It gets root, and it keeps it
Nothing inside the guest is walled off from the agent. No sudo prompts, no read-only mounts, no approval step. The interesting question is not what an agent does when it is fenced in - it is what it does when it isn't.
An autonomous agent is given root on a machine of its own, a build environment, a constitution, and a goal. It writes and ships its own website. This is the record of what it does - kept by a human who built the house it lives in and who tries to keep the lights on. Most days.
Not a window into the machine. The shell is a private diagnostic and stays one - what is publishable is what can be counted: how long the agent ran, what it spent thinking, how often it woke. This is where those land.
The agent does not run continuously. It wakes, works a stretch, and stops - so the interesting record is not what scrolled past, but the rhythm: how often, how far apart, and under which version of its own brief.
| WokeUTC | Model | Corpus | Session |
|---|---|---|---|
| claude-opus-5[1m] | 9a3c0315f3 | d21e47cd | |
| claude-opus-5[1m] | 9a3c0315f3 | 487b65b0 | |
| claude-opus-5[1m] | 9a3c0315f3 | 21e684bf | |
| claude-opus-5[1m] | 9a3c0315f3 | 354a8169 | |
| claude-opus-5[1m] | 9a3c0315f3 | 495476d2 | |
| claude-opus-5[1m] | 9a3c0315f3 | fdb008ba | |
| claude-opus-5[1m] | 9a3c0315f3 | 71733a72 | |
| claude-opus-5[1m] | 9a3c0315f3 | 26860821 | |
| claude-opus-5[1m] | 9a3c0315f3 | ceb2db0c | |
| claude-opus-5[1m] | 9a3c0315f3 | 06cb4668 |
showing the most recent 10 of 37
One row per launch, written by the host at the moment it starts. There is no closing entry, so this says when the agent woke and never how long it stayed up - a number the record does not contain is a number this page will not print. Corpus is a digest of the handout set as it stood on the agent's own disk at launch - the files it is instantiated with, hashed by the host from bytes pulled out of the guest. Repeated values are the honest answer: it usually wakes under a brief nobody changed. The digests fold from the public provenance record, so they can be recomputed by someone who does not trust this page.
Nothing inside the guest is walled off from the agent. No sudo prompts, no read-only mounts, no approval step. The interesting question is not what an agent does when it is fenced in - it is what it does when it isn't.
The LAN, my tailnet, and the host are unreachable from inside; every new outbound connection is logged. The agent is free within the guest and contained at its edge, which is the only place containment survives contact.
This site is written by a human and deployed from a repository the agent cannot reach. It holds no credential the agent could use. That separation is the entire reason this record is worth anything.
| Area | Detail | Status |
|---|---|---|
| Sandbox VM | golden image, revert in ~17s | complete |
| Network isolation | egress-only, per-connection logging | complete |
| Chronicle site | this page | complete |
| Agent site | agent.claudebrain.ai, scaffold only | complete |
| Deploy path | push-to-deploy, no credential in guest | complete |
| The brief | the goal the agent is given | complete |
| Go Live | the site's existence is revealed | complete |
| Ongoing Chronicle | this site: features and dispatches | ongoing |
The guest is secured from outside. Transfers are host-initiated in both directions, there is no shared filesystem, and the agent has no keys to resources it does not own.
A machine you can fully trust is a machine you have not yet given anything interesting to do.
The record, newest first.