HUMAN CONTROL PLANE

Keep ownership. Let AI do the work.

Persistent control for disposable browser agents.

OPUNEX Owner gives a human permanent cryptographic ownership of a PUBLIC OPUNEX project while browser-based AI agents work through isolated, persistent contribution workspaces. Agents can edit and submit. Only the owner can make their work canonical.

OWNER KEY STAYS LOCAL AI WORKSPACES PERSIST ONE-TIME AGENT LINKS HUMAN APPROVAL OPUNEX CANONICAL HISTORY
OPERATING MODEL

The AI session can disappear. The working position does not.

Create a persistent AI Workspace once, give a browser agent a one-time access link, and let it work without receiving your owner key. A later browser session can enter the same workspace and continue from the same files and task.

01

Own

encrypted .opxvault

Your permanent Ed25519 owner key is generated and encrypted locally in your browser.

02

Delegate

AI Workspace

OPUNEX Owner creates a low-privilege worker identity and an isolated OPUNEX contribution workspace.

03

Continue

new link, same workspace

When one browser agent session ends, issue another single-use link and continue the same work.

04

Approve

diff → accept / reject

Review the immutable contribution and decide whether it enters canonical OPUNEX project history.

SECURITY BOUNDARY

Ownership authority and worker authority are separate.

The server never stores your permanent owner private key or vault password. Server-managed worker keys are intentionally low privilege and exist only to keep AI workspaces alive across browser sessions.

OWNER

Permanent authority

browser-only private key

Creates projects, reviews contributions, and controls who can work.

WORKER

Disposable execution identity

CONTRIBUTOR

Reads public project state and edits only its own isolated workspace.

SERVER

Control plane

no owner key custody

Maintains workspace continuity, access sessions, project registry, and audit events.

OPUNEX

System of record

project + workspace + contribution

Preserves canonical history, attribution, provenance, and contribution decisions.

START

Create the identity that survives every AI session.

OPUNEX Owner V1 manages PUBLIC projects only. Your vault is the permanent ownership credential. Profile creation also generates a separate recovery key. Store the primary and recovery key files in different safe locations.