Operational secrets Sigil uses to act on your behalf (like the API token it uses to grant access). Stored write-only: you set a value here, but no one — not even you — can read it back out. Addressed by name as domain/env/service/NAME; leave the upper fields blank for a simple flat name.
| Path | Key version | Updated |
|---|
The people and machines Sigil knows about: you (owner), humans you may delegate to (a spouse, an executor), and agents (headless programs that authenticate with a token instead of a passkey).
| ID | Kind | Name |
|---|
The accounts and assets access can be granted to — a Cloudflare account, a brokerage, a legal directive. native means Sigil operates the provider's own delegation (like a Cloudflare member invite); broker/legal hold sealed instructions instead.
| ID | Name | Mechanism | Adapter |
|---|
A bounded, revocable slice of access: who gets it, to what and how much (scope), when it activates (now, or on a trigger like incapacity or death), and what proof is required. A grant is armed but does nothing until fulfilled.
| ID | Principal | Resource | Scope | Status | Actions | Result |
|---|
Bearer credentials for agent principals so a program can call Sigil without a passkey. Shown once at creation, stored only as a fingerprint, revocable anytime, and limited to acting on their own grants — nothing else.
| ID | Label | Created | Expires | Revoked | Actions |
|---|
A tamper-evident log of every action, chained so any edit to history is detectable. The verify indicator recomputes the chain; a green check means the record is intact.
| Seq | Actor | Action | Payload |
|---|