ExecBound
Sign in Request Community access

Integration evidence

Know what each path proves.

Connect an agent, an existing executor or an observation feed. Each entry records its placement, enforcement mode, tested versions and known limits.

A platform trial covers the recorded path and version. It does not establish vendor partnership, commercial support or coverage of every action on that platform.

How to read this register
research-only
A candidate or recipe exists; no tested compatibility is claimed.
fixture-tested
The path is exercised against synthetic fixtures at the recorded versions.
platform-validated
A bounded trial against the real host is recorded. Read its limits; a real host may still call a mock provider.

Placement describes where ExecBound connects. Mode describes the boundary: Native, Integrated and Embedded require proof for the protected routes; Advisory can be bypassed; Observed provides visibility; Unknown has insufficient evidence. These are separate from the evidence states above.

Read the enforcement modes and evidence rules

Expand an entry to read its tested versions and every recorded limitation. A row advances only when new evidence is recorded.

Execute

An agent asks ExecBound to act. The mode below states whether its path is protected or advisory.

Claude Agent SDK tool examplefixture-testedMode: Native

Tested versions

execbound
0.1.0
sdk
0.2.153
protocol
HTTP v1

Recorded limitations

  • A scripted caller stands in for Claude Code and reaches the tool over the SDK's in-process MCP server; the Claude Code CLI itself is not run
  • The boundary beat is the bypass test: the agent holds the gateway credential and nothing else; a host that gives the model another path to the provider is outside this row
Claude Coderesearch-onlyMode: Unknown

Tested versions

No tested versions claimed.

Recorded limitations

  • Promoted by its trial record under docs/trials/ (the named host trial, #26)
Claude Desktop and claude.ai connectorsresearch-onlyMode: Unknown

Tested versions

No tested versions claimed.

Recorded limitations

  • Waits for the MCP authorization server; these hosts accept OAuth only, not a static bearer credential
Cursorresearch-onlyMode: Unknown

Tested versions

No tested versions claimed.

Recorded limitations

  • Promoted by its trial record under docs/trials/, after the Claude Code trial
execbound-client over HTTP (Python)fixture-testedMode: Native

Tested versions

execbound
0.1.0
sdk
0.1.0
protocol
HTTP v1

Recorded limitations

  • The boundary beat is the bypass test: the agent holds the gateway credential and nothing else; a host that can reach the upstream credential is outside this row
MCP with the maintained 1.30 clientfixture-testedMode: Native

Tested versions

execbound
0.1.0
sdk
1.30.0
protocol
2025-11-25

Recorded limitations

  • Hash-locked legacy client environment (tests/mcp-legacy.txt); static bearer only
MCP with the official Python SDKfixture-testedMode: Native

Tested versions

execbound
0.1.0
sdk
2.2.0
protocol
2026-07-28

Recorded limitations

  • Static bearer credential per host; there is no MCP authorization server yet
OpenAI Agents SDK tool examplefixture-testedMode: Native

Tested versions

execbound
0.1.0
sdk
0.22.2
protocol
HTTP v1

Recorded limitations

  • A scripted model stands in for the OpenAI model; the Runner, the function tool and the tool's result are the SDK's own
  • The boundary beat is the bypass test: the agent holds the gateway credential and nothing else; a host that gives the model another path to the provider is outside this row
Tines governed-action storyplatform-validatedMode: Advisory

Tested versions

execbound
0.1.0
host
Tines schema 30, lib 96, runtime 88

Recorded limitations

  • Founder trial at c1818de: allow, deny, approval/refusal, same-reference retry, pending polling and wait-boundary resume ran in Tines; the AI caller returned allow, deny and pending; independent protected-mock journals corroborated outcomes
  • Shared-impact follow-up: ten Tines and ten second-agent HTTP actions filled one tenant limit; both overflows were denied and retries retained twenty charges and one mock mutation per successful operation
  • Expiry and malformed-target rejection passed on the hosted pilot; controlled Tines 503, 429-exhaustion and DNS faults exercised bounded retries and the explicit-uncertainty correction
  • Recovery at a513c8f: dropped response after mock effect, corrected 502 uncertainty and same-reference recovery retained one mutation and charge; alternate-story provider calls returned 401 and its gateway call remained denied
  • Signed-in Android approval passed; cold signed-out return and gateway-to-provider loss remain separate; the endpoint provider is a protected mock, and the pilot has no declared dispatch precondition
  • Advisory rather than Native: the story calls ExecBound voluntarily and nothing forces the call, so a story that skips it is not governed by anything

Gate

An existing gateway or workflow keeps its connector and credentials. Its blocking control point determines enforcement.

Arcade Logic Extensionplatform-validatedMode: Advisory

Tested versions

execbound
0.1.0
host
arcade-cloud-2026-09-18
sdk
Github 5.0.0

Recorded limitations

  • Advisory, not the Integrated the design targets: failing closed is a customer setting the extension cannot read, and a post hook is a runtime report not a receipt, so no settlement rises above tier ASSERTED
  • One live playground call on 18 September ran the whole chain, so the grant, the report window, the asserted settlement and an administrator's attested correction are measured rather than claimed
  • A settlement from a vendor success ran only against the hook process on loopback: a claimed incident must occupy one of the tool's declared inputs and SetStarred has no spare one
  • Mode is kept per action path, so an ungoverned toolkit stays Unknown
External execution checkpointfixture-testedMode: Integrated

Tested versions

execbound
0.1.0
protocol
checkpoint v1

Recorded limitations

  • Enforced only for the tested profile: the executor's own control point must block execution, bind the exact request and report; an unreported grant is swept to uncertainty and never refunded
Read the published setup guide
Tines Gate storyplatform-validatedMode: Advisory

Tested versions

execbound
0.1.0
host
Tines schema 30, lib 95, runtime 88

Recorded limitations

  • Cooperative: any Tines story holding execbound_gate_vendor can call the vendor directly, without asking ExecBound; the trial proved this bypass, which is the reason Gate is Advisory rather than Integrated
  • The signing credential cannot be host-restricted; any story in the team holding execbound_gate_signing can produce a valid attestation for any grant it can read
  • Principal separation is owner provisioning, not a control the seed ships with: the trial found the Gate credential reaching the Execute mapping until two Cedar forbids were activated by hand
  • Mock vendor only: the protected mock signs journals with an HMAC key in the gateway's own configuration; no real vendor was exercised

Monitor

Connected feeds and collectors supply observations or authority evidence. They do not prevent execution.

Coding-agent MCP proxyresearch-onlyMode: Unknown

Tested versions

No tested versions claimed.

Recorded limitations

  • Spike on #230: a local MCP proxy that turns a coding agent's tool calls into observations; not started
Entra Agent ID via Graph (Scout)fixture-testedMode: Observed

Tested versions

execbound
0.1.0

Recorded limitations

  • The collector and Agents page are implemented; docs/SCOUT.md records a September 18 founder-lab probe, but no complete versioned trial record promotes this row
  • Inherited allAllowed permissions, real-agent activity attribution and populated customer directories were not exercised by the lab probe; Azure RBAC and role-bearing group paths remain gaps
  • Directory reach is evidence of possible authority, not execution prevention; a principal binding governs only its path through ExecBound
CrowdStrike Falcon feed (Edge)research-onlyMode: Unknown

Tested versions

No tested versions claimed.

Recorded limitations

  • Brief written September 17, 2026 (#229); built after the raise with a design partner
Tines discovery and collectionfixture-testedMode: Observed

Tested versions

execbound
0.1.0
protocol
monitor events v1

Recorded limitations

  • Allowlisted story, action and credential metadata; a September 16 live inventory probe is recorded in docs/TINES_MONITORING.md, while audit and AI-audit collection lack the required account plan and remain fixture-tested
Tines instrumented stories (intake)fixture-testedMode: Observed

Tested versions

execbound
0.1.0
protocol
monitor events v1

Recorded limitations

  • A live Tines story delivered synthetic events on September 14, 2026; the row stays fixture-tested until a trial record in the interview format is written
  • Telemetry only: observations and findings never authorize, settle or consume limits