prims.sh · applets · stub · exploratory

Prims Applets

Soft framing for compositions that agents hit all the time: need a password or an approval. Lean: these are applets that compose an encrypted Prim with unlock / approve engines — also usable as platform capabilities. Lives with Prims Desktop.

Applets, not a third line Not a separate product. Not “just a connector.” Compositions you open like a Prim.
You own unlock / approve Agents ask. Humans (or policy) unlock and approve. Engines stay under the hood.
No registry cement Names and lean are exploratory. Soft copy only — don’t mint types from this page.

Two faces

Working nouns: Prim Secrets and Prim Approvals. Engines stay branded where they already live.

applet · secrets

Prim Secrets

Store secret values in an encrypted Prim. The applet operates that pack — unlock / policy under the hood (Knox).

  • Encrypted Prim is the vault file — not a second vault product
  • Connector / agent calls the applet for unlock · sign · grant
  • User owns unlock; agent never holds the clear secret as product
applet · approvals

Prim Approvals

Signing / approve inbox as an applet face. Engine under the hood (Hancock). Same “agent asks, you approve” gate as Secrets.

  • Mac dogfood path: Approve Inbox watches local signing surface
  • Later absorbed as Prim Approvals connector / applet — not a competing store
  • Used anywhere an agent needs a human go / no-go

What an AI hits

  1. Agent needs a password, token, or approval to continue.
  2. It routes through Prim Secrets or Prim Approvals — not a parallel vault.
  3. You unlock or approve on Prims Desktop (or the inbox). Policy can constrain.
  4. Grant returns to the agent for that act. Pack stays the store.

Stub only. Soft copy · mockups later. Do not treat this page as a registry row for secrets / approvals types. Composition vs connector vs surface still soft. Sibling stubs: /drive/, /desktop/, /together/.