ForkLab Workbench
Enterprise agent workflow (Preview)
Prompt → generate patch → BrowserPod run → proof report
Agent task
Secure run request
Agent activity
Timeline
Built-in repo context is staged.
BrowserPod boots and receives source files.
The tenant access-control test fails first.
A provider returns a constrained full-file patch.
ForkLab waits before writing AI output.
The approved patch is executed and tested.
The result is ready for handoff.
Verification policy
Trust gate
Patch proposal
Waiting for secure run
The proof report completes only after the approved patch passes inside BrowserPod.
What is real vs preview?
Honest demo boundary
SEC-101 writes files and runs Node tests in BrowserPod.
/api/agent/plan-patch keeps Gemini and Groq keys server-side.
Fallback mode is deterministic and still requires approval.
GitHub import, queued UI-204, and PR creation are not live yet.