Can an AI agent do anything without a person's approval?
Can an AI agent do anything without a person's approval?
PolicyValidator refuses to load or accept a proposal for a
policy that does not. The agent can set the approval signal to true, but
it counts only with a valid signed approval, checked before authorization
and again at the gateway, and used once. See Human
approval. The approval names the action and the
resource (and the amount for payments and refunds), not every parameter, and
a refused request is not held: the agent sends a new one with the approval.Is Parmana's signing key stored securely?
Is Parmana's signing key stored securely?
KEY_PROVIDER. With local it’s a PEM file on disk, read by
FileKeyProvider. With aws-kms the signing key lives in AWS KMS and is
never released, see AWS KMS signing. The
gateway attestation key is still a file in both modes. There’s a live
incident on record: an earlier committed key was publicly exposed and is
permanently compromised (rotated 2026-07-05). Azure Key Vault, Google Cloud
KMS and HSM custody are not built, see
Cryptography and Roadmap.Which SDK should I use?
Which SDK should I use?
npm install @parmana/sdk, pip install parmana. See Python SDK
and TypeScript SDK.Can I use Go / Java / .NET?
Can I use Go / Java / .NET?
Does Parmana support post-quantum signatures?
Does Parmana support post-quantum signatures?
PRIMARY_SIGNATURE_PROVIDER=dilithium3, real and tested. Requires Node ≥
24. Its signatures are randomized, not deterministic, don’t build tooling
that assumes otherwise. See Cryptography.What does 'replay' actually do?
What does 'replay' actually do?
Is there an 'Execution Permit'?
Is there an 'Execution Permit'?
SignedExecutionAuthorization +
Execution Gateway architecture, which is what actually ships. See
Glossary.Is this API authenticated?
Is this API authenticated?
/health, /ready, /openapi.yaml, and
/documentation requires a bearer key and fails closed with a 401 if it’s
missing or wrong (createCallerAuthenticator.ts). See
Authentication. This is a separate question
from whether the underlying business action was authorized, see
Security for that boundary.