Verified in source
Security & governance
Vira's control plane uses scoped behavior authority, permission-checked mutations, versioned revisions, runtime evidence, and explicit fallback/fail-closed paths.
- Behavior authority is resolved through explicit scope and revision identity.
- Governed mutations use project-scoped authorization and distinct capabilities.
- Runtime explanation uses server-owned receipt evidence where that evidence exists.
- Stale or mismatched optimized artifacts are not treated as new authority.