// portfolio / routeros

RouterOS

The agent layer: one governed route from a prompt to an app, taken the same way by a person in chat or an agent over MCP. An A2A front door is planned.

Status: design draft with a tested v0 kernel. Not a product. Nothing here deploys anywhere or moves money.

Watch a request travel the route.

A short tour of the kernel: a request becomes an app only after a person signs off on that exact build, every step is logged, and anything that cannot prove itself stops the route. It runs with stand-in handlers, so nothing is really built.

Ready

Press play to watch it work.

Design draft. This ran the real RouterOS kernel with stand-in handlers: nothing is actually built or deployed, and no money moves. The refusals, the codes and the log checks are the kernel’s own results. Amounts are held as whole minor units (2500 means $25.00).

Read the steps as text
  1. A request for an app, signed by a trusted key.
  2. A person must approve that exact build.
  3. Every step goes into a signed, linked log.
  4. Edit one entry and the log refuses it.
  5. Anything that can’t prove itself stops the route.

Every stage can refuse.

The route is intent, plan, authorize, build, verify, ship, operate. Each stage produces a document, and any stage can refuse. A refusal stops the route.

Identity is a pinned key

Who is asking is a key the relying party pinned in advance, never one carried inside the request.

Authority only narrows

A grant can be passed on only with a smaller amount, audience, purpose or expiry. It is checked when it is used and can be spent once.

A human signs before anything ships

Shipping needs a signed approval from a pinned human key, tied to the exact request, expiring and single-use. A machine key can never approve.

A log that cannot be quietly edited

Every receipt and every refusal goes into a hash-chained, signed log. Edits, deletions, reordering and truncation are all refused.

A design draft. Here is exactly what exists.

Built
A kernel with 78 passing tests: signing against pinned keys, narrowing grants, human approval, a hash-chained log, a build-and-check pipeline tested against a mocked model, and an MCP front door.
Not built
No live model call has been made yet. It builds small static web apps only. The sandbox runs on macOS only and is not yet a security boundary. Deploying publishes to a local folder only. The MCP front door runs on demo stubs. There is no A2A front door, no durable store for spent grants, and no way yet for a person to sign an approval.
Money
Nothing here moves money. Money is held as whole minor units, never floats.
As of
2026-10-09, from the project’s own tests and notes