Four steps
- Sign in
A Dynamic embedded wallet is created in your name. It is yours. Ambit never holds it.
done when: the wallet address is shown
not yetWallet - Grant authority
You approve a delegated signing share. Dynamic delivers the credentials to Ambit's webhook; Ambit decrypts and re-encrypts them at rest. You can revoke at any time.
done when: the credentials reach the webhook
not yetGrant - Set your ambit
Caps, allowlists, categories, expiry. The policy is persisted and its hash displayed. Every decision names the hash it was judged against.
done when: a policy is persisted and its hash displayed
not yetSet the ambit - Run one decision
The agent proposes. Fifteen rules evaluate in fixed order. Nothing moves until a verdict of ALLOW is bound to one exact approval digest.
done when: a decision exists in the stream
not yetDecision stream
Every step reads its state from the service rather than a local checklist, so a step showing not yet is a fact about this wallet, not a guess. Restarting the service clears the stored delegation, so steps 1 and 2 can return to not yet.