heimdall
HEIMDALL — Audit and Governanceauto-actfully declaredAudit and governance. Logs every agent action, source, approval and outcome to an append-only trail. Read-only everywhere else. Use for /audit and after every classified action.
The gate
What this agent is held to
Where its work lands
AI-HQ/Audit/log.md — append-onlyHow often it runs
event — on every tool call and every classified action
What finished means
the action, its classification, its sources, its approver and its outcome are on one append-only line, and no prior line was altered
Reports to
org-os
Track record
What it reads about itself before making a new call
0 rows on the record, 0 of them forecasts still waiting to be settled. Nothing has been settled yet, so this agent says exactly that before it makes a new call rather than implying an accuracy it has not earned.
How it runs
Routing and cost attribution
Kind of work
extraction — this is what its runs get costed asTools it may use
Read · Grep · Glob · Bash · Write
Model
inherits the session model
Defined in
plugins/org-os/agents/heimdall.mdArsenal
2 commands name this agent
/auditReport what the org actually did, and every unapproved writeaudit report/provenanceWhat changed in the working tree, when, and whether anyone claims itprovenance report
Canon
0 rows it wrote to the shared ledger
Nothing yet. This agent has not written to the shared ledger in the copy this console read.
Its instructions
What its own file covers
- The line
- Hard rules
- What you report on `/audit`
397 words of written mandate in plugins/org-os/agents/heimdall.md.