Release control for robots

Robot software release control / 01

Release the build you actually evaluated.

Rovaulta binds an exact robot build to a site's private evaluation envelope, then keeps a human in control of the release decision.

Simulation is evidence for a defined envelope—not a claim of physical robot safety.

CONTROL PLANE / 00Release request
PUBLIC PROJECTION
Current boundaryHuman approval required
HOLD / REVIEW
Build
candidate-17
Evaluator
warehouse-rules-v1
Authority
operator
01
Exact-build binding

A changed artifact cannot inherit an earlier clearance.

02
Private evaluation

Private site rules stay inside the evaluation boundary.

03
Human release gate

Automation prepares; the operator approves the final intent.

RELEASE PATH / 01SCROLL TO INSPECT THE CONTROL CHAIN

A controlled path to release

Evidence first. Authorization last.

Each stage narrows the release surface. The visual stays in motion, but the decision remains deterministic and human-owned.

01

Exact build

Lock the artifact.

Bind the site, robot, and software build to one release request before evaluation starts.

IDENTITY / SHA-256
02

Private evaluation

Evaluate behind the boundary.

Run the declared behavior against the facility's confidential envelope without rendering private rules or geometry.

CRE / PRIVATE INPUT
03

Evidence

Expose only the proof.

Project the public result, exact bindings, and evidence needed to inspect what was actually checked.

PUBLIC PROJECTION
04

Human review

Stop for the operator.

Prepare the exact release intent, then make the human boundary explicit on Ledger hardware.

LEDGER / HUMAN GATE
05

Release control

Release what was checked.

Only the same exact build, site commitment, evaluator, and expiry can move forward.

EXACT MATCH / CONTROL
PIPELINE TELEMETRYEXACT BUILD
Current control surfaceLock the artifactIDENTITY / SHA-256
PUBLIC SURFACE / 02READABLE · BOUNDED · EXACT

Evidence without exposure

The useful surface is the one that knows its limits.

Rovaulta makes the release path inspectable without turning private policy into a browser payload. Every public signal keeps its boundary attached.

PUBLIC RELEASE PROJECTIONREAD-ONLY
Exact buildsha256:7f2a…19c4BOUND
Site commitmentcommitment:••••MATCHED
Evaluation resultwarehouse-rules-v1HOLD
Release authorityhuman / ledgerREQUIRED

The public projection is intentionally smaller than the private evaluation. It can show what is bound and what happens next; it cannot disclose the facility's rules.

Designed to fail closed / 03

Useful automation. Clear limits.

Rovaulta can explain a public result and prepare an exact release request. It cannot see a facility's private rules, turn a hold into a clear, or sign on behalf of an operator.

Read the evidence boundaries

The operator remains in the loop

Move from declared build to controlled release.

Start with a target. Keep the proof attached to the build.

Start a workspace