Which registries and local roots may provide skills?
A public directory, private team repository and local override should not automatically carry the same trust level.
Enterprise Edition is the governed control layer for large mixed-agent fleets where capability sources, versions and delivery state must be enforceable and auditable.
Constrain allowed capability sources
Sign the rules for managed instances
Audit or refuse disallowed delivery
Build fleet and compliance state
At fleet scale, an unreviewed instruction, stale version or wrong destination can become a security, compliance or change-management incident.
A public directory, private team repository and local override should not automatically carry the same trust level.
File presence does not prove that every managed instance received the intended release or retained it after an update.
Capability scope must follow organisational policy instead of spreading through copied folders and individual installs.
Security and compliance teams need durable state, exceptions and change history, not screenshots from each agent workstation.
Community Core stays MIT and local. Enterprise controls are opt-in for managed environments and do not turn the product into another agent platform.
Audit or refuse unmanaged registries, release channels, manifest keys, local roots, community actions, hub allowlists and remote fallback.
Local policy MVP availableFetch a signed policy assignment, verify both assignment and payload, support dry-run, and refuse unsafe removal of unmanaged local policy.
Client foundation availableKeep enterprise skill bodies, signing operations, entitlements and policy administration outside the public repository and public catalog.
Private foundation / deployment scopedRecord exceptional approval paths instead of bypassing policy invisibly, with explicit actor, reason, scope and change state.
Governance path evolvingBuild toward per-agent and per-pack acknowledgement, retry state, policy version and exception evidence across the managed fleet.
In developmentPackage local value and governance evidence with a verifier so reporting can be checked independently instead of accepted as an opaque dashboard number.
Evidence foundation availableThe design separates policy authority, signed delivery and local enforcement.
Choose approved registries, channels, signing keys, roots, community actions and fallback rules for each managed scope.
Bind the policy to the intended organisation, team or installation through a signed assignment contract.
The client verifies the assignment and policy before installing it. Dry-run performs verification without changing local state.
Managed instances log disallowed actions in audit mode or refuse them in enforce mode, while unmanaged Community Core remains unchanged.
Fleet dashboards and delivery receipts are being productised to expose policy, version, update, failure and exception state.
The final deployment is selected during design-partner scoping, not assumed from a generic SaaS architecture.
Use signed registry contracts and policy assignments while keeping local prompts, source code, skill bodies, local paths, tokens and device private keys outside policy-sync payloads.
Place the private registry and governance services inside a customer-controlled cloud boundary with contracted integration and operating responsibilities.
Planned deployment optionRun the registry and policy boundary inside enterprise infrastructure where network, identity and data-residency requirements demand it.
Planned deployment optionDesign partners enter with explicit boundaries, milestones and acceptance tests.
Unlimited Skills does not claim guaranteed fleet delivery until acknowledgement, retry and compliance-receipt workflows are completed and verified in the target environment.
No. It governs Unlimited Skills delivery paths and can constrain approved registries, channels, signing keys, roots and related actions. A user with direct filesystem and source-code access still requires normal OS and endpoint controls.
No. The managed sync contract excludes local skill bodies, prompts, source code, local paths, search queries, secrets, tokens and private device keys.
Not as a finished production integration. Both are planned Enterprise capabilities and must remain explicit roadmap items until implemented and verified.
No. Unlimited Skills is an independent capability and policy layer above supported runtimes. The design-partner process maps the existing fleet before proposing adapters or controls.
Tell us which registries, teams, runtimes, signing rules and deployment constraints define a safe rollout in your environment.