Skip to request
PUBLIC UI DEMOSYNTHETIC DATA · NO API · NO REAL DECISION OR EXECUTIONVESOS.AI ↗
VESOSVerifiable Engineering Stewardship & Oversight System
VESOS Owner ConsoleSYNTHETIC OWNER VIEW
Upstream APIDisconnected · public demo
Demo conditionCompare the safe fail-closed states.

Try it: inspect each stage and the exact fixture bytes, then record a simulated decision.

Release the school director calendar

dreq_demo_school_calendar · rev 3 · T3_PRODUCTION · PENDING · Expires 2026-09-05T17:43:04.114Z

AWAITING_OWNER

WHERE THIS ILLUSTRATED TASK IS NOW

Calculating the displayed fixture hash…SHA-256

WHAT THIS SYNTHETIC REQUEST CONTAINS

T3 · T3_PRODUCTION

High-impact production action · T3

Requested action: deploy.release → demo://school-calendar/production

“Synthetic release of the calendar application to a non-real target.”
May touch
app/calendar/**
Synthetic fixture
Must not touch
credentials/** · infra/**
Synthetic fixture
Action
deploy.release
Synthetic fixture
Tool
demo-deployer
Synthetic fixture
Stops if
the target or revision changes
Synthetic fixture
Task
task_demo_school_calendar · AWAITING_OWNER
Illustrated field — not API data

Synthetic proposer synthetic_coordinator · 2026-09-04T17:43:04.114Z

Expires 2026-09-05T17:43:04.114Z

This summary is illustrative. The exact DEMO-JSON-1 bytes below are the fixture used by the browser calculation.

CONTEXT OF THIS ILLUSTRATED DECISION

Overall goal
Synthetic release of the calendar application to a non-real target.
Synthetic fixture
Why a human is required
The illustrated risk tier requires an authorized owner decision.
Illustrated field — not API data
What came before
A synthetic proposal and request fixture are displayed.
Synthetic fixture
What follows a simulated approval
Only browser state changes. No VESOS record or execution starts.
Derived in this browser
Who could execute in a real integration
A connected adapter and external executor would be responsible in a real integration.
Illustrated field — not API data
Expected reported evidence
A real integration would report evidence bound to its attempt; this demo creates none.
Illustrated field — not API data

ILLUSTRATED CONSEQUENCES

If approved in a real system

A matching next step could become eligible under a scoped lease. This demo only records browser state.

If rejected

The illustrated request remains blocked. A new request or revision would be needed.

If it expires

The request remains blocked. Expiry never becomes automatic approval.

EXACT SYNTHETIC FIXTURE BYTES

UTF-8 · LF · no BOM · no trailing newline

bytes
316
Format
DEMO-JSON-1

Expected SHA-256sha256:922193aca529a904bc0a61e1ba23786c1e61fdc629a8127adc213284bc1aba6a

Computed SHA-256—

{
  "action": "deploy.release",
  "allow": ["app/calendar/**"],
  "deny": ["credentials/**", "infra/**"],
  "request_id": "dreq_demo_school_calendar",
  "revision": 3,
  "target": "demo://school-calendar/production",
  "task_id": "task_demo_school_calendar",
  "tier": "T3_PRODUCTION",
  "tools": ["demo-deployer"]
}

Decision controls remain locked until the displayed fixture hash matches.

PUBLIC DEMO BOUNDARY

This interface changes browser memory only. It does not send a request, create a VESOS record or start an executor. Running and receipt panels are separate synthetic read-only examples.

In a real integration, VESOS governs only actions routed through the connected enforcement point. The adapter and executor validate and enforce the actual command; the kernel never runs it.