Multi-step AI work with human checkpoints.
Stores bounded plans using exact capability references, stops at approval-gated stages and records execution digests while the normal permissioned dispatcher remains the only executor.
The AI never receives direct operating-system privileges. Tool calls are resolved against the exact Idovio binding and pass through permissions and sandboxing.
Agentic workflows without handing autonomous execution authority to the model.