Custody is architecture, not policy

If a secret can reach a place, assume it will. Design so that it cannot. The tool holds the token; the model never sees it.

Every member of a Nexus household gets a private, sandboxed agent. The question that shaped the design was not “what should the agent be allowed to do with credentials?” but “how do we make it impossible for a credential to enter the agent’s context at all?” The answer is a sidecar — Valet — that exposes platform providers to the agent as tools and holds every token itself. The agent calls a tool; custody never moves.

Policy is what you write when the architecture has already leaked.