Trust boundaries and data flow
The command lifecycle crosses three trust zones: the authenticated dashboard, the command gateway, and the paired device. Each zone enforces policy independently.1
Dashboard proposes action
The authenticated dashboard proposes a typed action. Retrieved content is data, never policy.
2
Gateway validates and gates
The command gateway validates identity, current session, ownership, capability, risk, consent, and rate limits.
3
Preview and confirmation
Medium actions show a preview. High actions require confirmation plus AAL2 step-up. Critical actions add a second confirmation.
4
Gateway signs device-bound command
The gateway signs a device-bound command with a unique nonce and a lifetime of at most five minutes.
5
Device verifies independently
The paired device independently verifies signature, nonce, expiry, device ID, current local grant, and local approval.
6
Device executes least-privileged action
The device uses the least-privileged OS API, keeps sensitive access visible, and returns a bounded result.
7
Audit event is appended
The gateway appends an audit event. Models and ordinary clients cannot modify audit rows.
Primary threats and controls
Capability and risk matrix
Terminal access never means a generic shell. A separately configured command policy must bind executable, arguments, working directory, duration, and output limits.
Platform capability matrix
Residual risks
The following risks require specialist review:- Native-agent sandbox escapes
- OS accessibility abuse
- Signing-key compromise
- TURN/WebRTC metadata exposure
- Organization consent validity
Monorepo target
The current repository remains operational while migration proceeds toward:apps/webapps/desktopapps/androidapps/iosservices/gatewayservices/notificationspackages/control-sdk