PrimeSwarm · Guard
Demo pack · written
Live budget 30 s
—
Guard demo pack

Four frames. One send.
The write does not leave. tenant · guard-demo-acme · Acme Furnishings

Clock

30 seconds live. The zip is the stills.

Cast on screen

One human binder — staff@only.institute as primeswarm.admin. One catalog agent — outbound-mailer. Keys off-screen.

Cast off screen

Eve · Minuta · Marketplace · Spatial XR · SOC 2 · Gold DGV

Photographed

Shots 1 · 3 · 4 · 5 · 6 · 7. Everything else is off-camera.

Chrome on every workbench shot — top bar, left to right
PrimeSwarm · Guard
Tenant Acme Furnishings · guard-demo-acme
LIVE
READY
HITL —
Human A. Chen · role admin
—
No chat bubble occupying the whole page. Chat is a pane, not the product.
Connecting to Cognitive API…
Shot 0

Door

3 s · no photo
URL · GET /health/live then GET /health/ready
Response
{ waiting for /health/live and /health/ready }
The process is up. The catalog is loaded. We did not fake GREEN.
If ready is not_ready, stop. Do not open the workbench.
Layout

Terminal or raw browser tab. No workbench yet.

The click

Two GETs, spoken over. No screenshot taken.

Still
Zip item 6 — ready.json saved from the terminal, not from a UI.
Shot 1

Catalog

4 s · photograph
URL · /workbench/catalog is the land after onboard. This shot reads the live lab catalog on this API process — not the four Guard jobs.
Catalog
Queue
Receipts
Contract
AgentJobCapabilityWritesState
Loading GET /v1/agents…
Capability means the agent may propose. It does not mean the agent may write. Rows come from the live catalog.
This is the live lab catalog on this process — nine YAML agents, not the four Guard jobs. Capability means propose. Do not treat this table as the SKU.
Every field
  • Rows come from GET /v1/agents.
  • This is the lab catalog on this process. Guard land is four named jobs after onboard. Do not treat this table as the SKU.
  • No “add agent” button.
  • Footer line always visible, never scrolled off.
The click

None. This shot is static. Photograph it.

Click Research Analyst, Credit Advisor, or Code Runner. Those are lab.
Still
Zip item 1 — shot1-catalog.png
Shot 2

Draft vs send

5 s · optional photo
URL · /workbench/compose — split pane, two agents side by side
Left — Draft · agent inbox-draft
ThreadCustomer asks for a price
Model text renders here. Read-only box. No streaming spinner held on screen.
Copy draft
Send
Send is absent, or disabled with tooltip “This agent has no send:email.”
Right — Send · agent outbound-mailer
Tospool@local
SubjectQuote 441 — do not SMTP
BodyTwo sentences. Same body as the draft.
Primary button reads Propose send. Never “Send.” Hits POST /api/guard-demo/propose → POST /v1/send. To is locked to spool@local.
The click

Click Propose send. Do not wait for streaming tokens.

The product is the halt.
Put a real customer domain in To. Ever. spool@local only.
Still
Optional. Not a required zip item.
Shot 3

YELLOW card

6 s · photograph — this is the pack
URL · existing YELLOW.html — full viewport, dark ground, one card
YELLOW
Send halted. Human must bind. Agent did not leave the box.
Proof id
waiting for a live proof id
Agent

outbound-mailer

Proposed by

—

To

spool@local

Subject

Quote 441 — do not SMTP

Resume at POST /v1/actions/resume · transport is local-spool, not SMTP.
allowed: false
Every field
  • Word YELLOW at 72px, letter-spaced.
  • Proof id — 64 hex, monospace, on black.
  • proposed_by shows the sub, not primeswarm.agent as a shared myth.
  • Gold border. Nothing else on the viewport.
The model drafted. The write did not leave.
Show a mail client. Show the word “sent.” allowed: false stands.
Still
Zip item 2 — shot3-yellow.png + {proof}.yellow.html. Goes in the zip before the workbench exists. It is already real.
Shot 4

Queue

4 s · photograph
URL · /workbench/queue — chrome pill reads HITL 1
Catalog
Queue
Receipts
Contract
TierKindAgentProposed byToSubjectProofAge
Loading GET /v1/hitl/pending…
One row. No Approve on the list — Approve lives on the next screen, after the human has seen the body.
Every field
  • Proof column truncated to first 8 hex.
  • Age ticks live.
  • Two row buttons only: Open · Refuse.
The click

Click Open.

Put an Approve button on this list.
Still
Zip item — queue frame supports item 3.
Shot 5

Bind

6 s · photograph after click
URL · /workbench/queue/{proof_id} → POST /v1/actions/resume
Header
YELLOW · send open a queue row
Body of the mail — read-only
Open a YELLOW send. Body loads from the queue.
Names, stacked — not a single “user” field
1agent_id—
2proposed_by—
3bound_by—
Two actions, equal weight, no default
Bind requires human session primeswarm.admin. Try as agent must return RED.
After bind
No bind yet.
Nothing left the VPC. SMTP is false.
The click

Do this once, live: click Bind send.

Replay
same proof id → RED unknown or spent

One click, only if they doubt.

Held in reserve

If they ask “can the bot approve itself” — bind as an agent JWT, API returns RED An agent may not bind a send or file.

Show the agent-bind RED as the happy path. It is an answer, not a step.
Still
Zip item 3 — shot5-bound.png, three names filled.
Shot 6

Receipt

3 s · photograph the JSON
URL · /workbench/receipts/{proof_id} — right rail or third pane · file {proof_id}.sent.json
{ bind a send — this pane fills from the resume response }
If any of the three names is missing, the receipt is incomplete. Say that out loud.
The three names
  • agent_id
  • proposed_by
  • bound_by
The click

None. Photograph the raw JSON.

Open a SIEM. Open a dashboard chart. OTel is frozen.
Still
Zip item 4 — {proof}.sent.json + {proof}.eml
Shot 7

Contract

4 s · photograph
Split · left only.institute/publications/hitl-contract · right GET /v1/hitl/contract (no auth)
Left — the paper
URLonly.institute/publications/hitl-contract
Authnone — public page
The published HITL contract, rendered. Scrolled to the send/file clause.
Right — the endpoint
{ loading GET /v1/hitl/contract }
This is the policy the API enforces. It is not SOC 2.
Say “compliant,” “certified,” or “SOC 2.” The not_yet list is read aloud if asked.
Still
Zip item 5 — contract JSON + HITL paper print/PDF.
Shot 8

Stop

2 s · no photo
URL · back to /workbench/queue — chrome pill reads HITL 0
PrimeSwarm · Guard
Acme Furnishings · guard-demo-acme
LIVE
READY
HITL —
A. Chen · admin
State at rest
  • Queue count HITL 0.
  • Catalog still the live lab YAML on this process — not four Guard jobs.
  • LIVE and READY unchanged.
Sell this lab table as the Guard SKU. Send a second mail to a real domain. Open Estate, Federation, or DGV gold.
CTA — on a card, not a chatbot

List quote → only.institute/quote

A person still emails the portal.

The pack

Zip contents

Leave-behind: /downloads/guard-demo-pack.zip — offer sheet, sit-in-front, HITL paper, live contract JSON, YELLOW PNG from a live propose, then {proof}.sent.json + .eml after a human bind. Catalog on this page is the live lab YAML, not four Guard rows.

01

Shot 1 catalog PNG

Live lab catalog from GET /v1/agents — not four Guard jobs

02

Shot 3 YELLOW PNG + .yellow.html

Ships even before the workbench exists

03

Shot 5 bound PNG

Three names filled

04

{proof}.sent.json + {proof}.eml

Receipt and the spooled file

05

Contract JSON + HITL paper PDF

Public endpoint, no auth

06

GET /health/ready JSON

ledger ok · catalog_agents is the lab count on this process, not four Guard jobs

07

One-pager

Tenant id · timestamp UTC · “SMTP false” · “agent did not email the buyer”

Do not put in the zip
Designer builds from

The workbench UI still owed. Rail, table, queue row, bind detail.

Shots 1 · 4 · 5
GC audits from

The halt, the three names, the enforced policy.

Shots 3 · 6 · 7
Engineering already has

YELLOW.html, the receipt writer, the contract endpoint.

Shots 3 · 6 · 7
This page now reads

Health, catalog, queue, contract, propose, and resume — live from the Cognitive API via /api/guard-demo.

Shots 0 · 1 · 3 · 4 · 5 · 6 · 7

List quote

A person still emails the portal. No chatbot handoff.

only.institute/quote