The baseline, not the ceiling
The org-approved harness is the default. Engineers still add their own on top, and the baseline updates when the central library does.
Skills, sub-agents, rules and hooks decide how an agent behaves, and today every engineer assembles their own. The control plane shows what is actually running, pushes the approved setup from one place, and denies what should not run at all.
A control plane engineers route around is worse than none at all. Three properties keep this one from becoming that.
The org-approved harness is the default. Engineers still add their own on top, and the baseline updates when the central library does.
Skills, plugins or rule packs flagged as risky are denied at org level, and the deny list is enforced when someone tries to install one.
Admins publish from the same recommendation engine that powers the improvement loop, rather than triaging the public catalogue cold.
This is the one surface in Tetriz that writes anything, and what it writes is harness configuration an admin published — never code, never commits. Access is role-based, and the org baseline is a default engineers build on, not a ceiling.
The approved baseline arrives on one machine already working; the same signal rolls up to what the org is actually running, without anyone reading a line of code.
Or explore the rest of the platform
Everything wrapped around the AI agent that shapes how it behaves: skills, sub-agents, plugins, hooks, and the CLAUDE.md, AGENTS.md or Cursor rules file the engineer has installed. It is why the same tool produces different output in different hands.
Yes, and it is the one place in Tetriz that writes anything. What it pushes is harness configuration an admin has published: skills, sub-agents and rules. It cannot modify code and it cannot push commits.
Yes. The org-approved harness is the default baseline, not a ceiling. Engineers add their own on top, and the baseline refreshes when the central library is updated. A control plane that froze everyone's setup would just get worked around.
Packs flagged as risky during evaluation are denied at org level, and that denial is enforced at install time. It means a vulnerable sub-agent gets blocked everywhere at once instead of being chased repo by repo.
Admins publish from a vetted base fed by the same recommendation engine behind the improvement loop, pre-filtered against the org's security posture. The alternative is triaging the public catalogue cold, which is why most orgs never start.
Drivers is the visibility layer: what is installed, what gets used, and where it conflicts. The control plane is the action on top of it: publish, push, deny. Same data, different verb.