Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Level 10: Going to production

You'll learn what changes between a laptop and a real deployment.

Everything from levels 1–9 works the same in production. What changes is where things run, who holds which key, and what you watch.

The checklist

On your laptopIn production
Guard servercargo run in a terminalsystemd or Docker, bound to 127.0.0.1, behind TLS (Deploying)
Admin tokenguard-data/keys/admin.tokenGUARD_ADMIN_TOKEN from a root-only env file or your secret manager
Signing keyguard-data/keys/audit.keySame file, backed up encrypted, readable only by the service
ApprovalsThe console on localhostThe console behind SSO or a VPN; automated reviewers for low-risk cases
Tool backendsThe agent calls tools itselfBackends check approvals themselves (level 9)
CheckpointsPrinted at the end of a runPublished on a schedule, to a system the guard host can’t modify
MonitoringReading the transcript/healthz, quarantined agents, and scar and termination alerts

Publish checkpoints

A few lines of cron make truncation and rewrites detectable forever:

#!/bin/sh
# /etc/cron.hourly/lineage-checkpoints: record every agent's head somewhere else
ADMIN="Authorization: Bearer $GUARD_ADMIN_TOKEN"
for id in $(curl -s -H "$ADMIN" https://guard.example.com/v1/agents | jq -r '.agents[].agent_id'); do
  curl -s -H "$ADMIN" "https://guard.example.com/v1/agents/$id/verify" \
    | jq -c --arg id "$id" '{agent: $id, ok, head, at: now|todate}'
done >> /mnt/audit-archive/checkpoints.jsonl     # a different machine, or append-only storage

Alert when ok is ever false, or when an agent shows up as quarantined.

Watch for

SignalWhereMeaning
Quarantined agentStartup output, GET /v1/agentsIts log failed verification. Treat it as an incident
Terminationterminated records, agent statusAn agent crossed its limits, or someone hit the kill switch
Rising scarsscar_score in the agent statusAn agent that’s struggling, or being attacked
Pending approvals piling upactions_pendingPeople are the bottleneck; consider an automated reviewer for low-risk cases

You’ve finished

You can now design a policy, guard any agent, put people in the loop, prove what happened, and run it for real. Next: