Kriya Console 0.4.0
kriya Console v0.4.0 (universal: Intel + Apple Silicon) — free tier. Signed with our Apple Developer ID, notarized + stapled by Apple, so it opens with no Gatekeeper prompt. Verify with the .sha256 asset.
The v0.4.0 wave: govern the money, govern the night, start governed — and read your own reliability from your own verified receipts.
New
- Agent payment governance — the
paymentgate class is now a primary enforced dial (Allow / Receipt-only / Approve / Deny). A payment-shaped call on the governed Claude Code hook lane produces a signed, content-freekriya.pay.{intent,decision,outcome}chain: merchant host, a best-effort amount (an unreadable amount reads "unknown", never a guess), the decision against your per-txn cap and day spend, and the real outcome. A card number never enters a receipt — custody stays with credential brokering. New Spend › Purchases tab; payment approvals show the amount against your cap. - Shift reports — declare an unattended window (default 22:00–07:00) and get a signed, chain-linked roll-up of what the governed agent did across it, with a signed
kriya.attest.shift.gapreceipt for every heartbeat gap — visible by absence, never smoothed over. Arm the shift and a missed heartbeat fail-closes the policy tier (tighten-only; inert when disarmed). New Compliance › Shift reports view + the Today Overnight-shift card. - Governed run launcher — Start › New governed run composes an agent + policy pack + lanes into one
kriya-run …command; the open runtime's new bin signs a singlekriya.run.launchedattestation (content-free — never argv or cwd), then starts the agent. Copy-first: a launcher, not a second enforcement path. - Analytics — a new Monitor view over verified receipts: Reliability (actions, success rate, deny/hold split, denies/day + failures/day, top-failing tools, per-agent trends), SLOs (approval latency p50/p95 per gate class, verification pass rate, budget headroom, heartbeat gaps), and Posture — week-over-week threshold crossings, captioned verbatim: "Evidence posture — counts from verified receipts. Not a risk score."
- Charts — the Console's first chart layer (hand-rolled SVG, zero new dependencies): Spend gains a 30-day Trend; Local Models gain per-model p50/p95 latency.
Honest scope
- Payment enforcement runs where the pre-execution hook runs (the Claude Code lane); other lanes are observed. Never sold as PCI or DLP.
- The shift report is measurement of the governed record, not a promise nothing happened off-lane.
- Analytics failure counts render "did not complete", never "blocked" — deny wording stays reserved for explicit enforcement receipts.
- Every new vocabulary is additive + optional on the frozen envelope: old receipts verify byte-unchanged, TS↔Rust parity fixtures lock each format.
The Console is closed-source, built on the open MIT kriya runtime. Full changelog: CHANGELOG.md. Don't trust the cockpit — check its receipts.