Ontario Protocol

Team-operated review workflows / Pilot

Private Agent Handoff

Give a reviewer agent the brief it needs, without handing it your entire client workspace.

Approved fields. One recipient. Short-lived access. Your keys and task payloads stay in your environment.

Review handoff

Policy simulation / synthetic data
Shared brief fields

Excluded: client contact, credentials, internal notes.

Action
Review brief
Spend permission
0 USDC
  1. 01Lead agentSelect fields
  2. 02Handoff gateCheck policy
  3. 03ReviewerAccept once
Ready to evaluate

Synthetic agency brief / reviewer-01

Recipient payload

No brief released.

Decision record

No decision yet.

Simulation only: no encryption, signature, delivery, execution, or payment occurs here. The local kit performs encryption and signature verification. It does not run an agent.

Private by placement, bounded by policy

Inside your environment

The Python kit signs a brief and encrypts it to a pinned recipient key using JWS and JWE. Transport stays with your existing authenticated queue or service.

Before the reviewer sees it

The receiver checks issuer, audience, allowed fields, scope, expiry, revocation and prior acceptance. Missing replay state blocks delivery.

Evidence without the brief

A recipient-signed receipt records acceptance and a ciphertext fingerprint. It omits task content and is not proof of completed work or service quality.

Recruiting three pilot teams

One real workflow. A measurable decision.

$299 / one 30-day pilot

For agencies and internal teams running a repeated lead-agent to reviewer-agent workflow. Start with synthetic briefs, then decide whether the integration is suitable for your data.

  • One Python handoff integrated in a team-controlled test environment.
  • A pinned-key and field policy, plus expiry, replay and revocation acceptance tests.
  • Payload-free signed acceptance receipts and an operator runbook.
  • Two scheduled implementation check-ins within the agreed 30 days.

Payment boundary: apply free. A manual invoice is issued only after written scope agreement and delivery of the agreed acceptance tests. No automatic renewal, production SLA, audit certification, or autonomous spending.

Pilot capacity is a recruitment target, not evidence of customers. This is not a hosted messaging product. If your workflow already has equivalent controls, keep them.

Request a fit review

Only business contact and the selected workflow metadata are sent to Ontario for qualification and follow-up. No task contents, private URLs, keys or client records. No public application listing. For deletion, email hello@ontarioprotocol.com.

Trust boundaries, not trust theatre

Not a secret language

The kit uses the established JWCrypto library with fixed algorithms. This is application-level policy around standard cryptography, not a new encryption protocol.

Not an escape from oversight

Your operator provisions keys and authorization. An authorized recipient can copy plaintext. Revocation cannot undo a completed handoff; encryption does not solve prompt injection.

Not an OAuth replacement

Keep existing transport authentication and authorization. There is no token passthrough, credential brokering, wallet custody, or claim of verified agent identity.

Inspect the implementation and threat model · Review the source and tests on GitHub · Need agent catalog distribution instead?