ENIMA OS

Secure agent operations

One command center.
Every agent accountable.

Plan, authorize, execute, and validate work across isolated tenant workspaces—with live evidence and bounded automation.

Tenant isolatedPolicy gatedFully audited

CONTROL PLANE ACCESS

Welcome back

Use your verified ENIMA account to continue.

Sessions use short-lived access and rotated refresh tokens. Privileged accounts require MFA.

  1. 1Choose
  2. 2Brief
  3. 3Launch
Budget and execution options

Policy, tenant scope, budget, and required approvals are checked before execution.

Hermes will return strict public proposal JSON through OmniRouter. This creates an immutable planning draft only; it cannot execute tools or fan out tasks.

This takes effect immediately

The Telegram account will need a new one-time code before it can use this project again.

The request passes through tenant policy and may enter the approval queue. Output is scanned, signed, and accepted only after every mandatory QA gate passes.

ENIMA cannot show this credential again.

The Extension Runtime tests it against the official provider, encrypts it and returns metadata only.

The stored credential stays server-side.

Only sanitized provider evidence is returned. Hostinger DNS update requires a second exact approval.

Only an owner or administrator with active MFA can save this setting. The ENIMA dashboard origin itself cannot be used as a deployment target.

The API key is accepted once.

It is written directly to OmniRouter's protected secret store. It is never returned, listed, logged, or sent to Hermes.

Routing and health options

New profiles are registered as active metadata, while real provider calls remain globally locked until a reviewed connection test and explicit owner activation.

Credential remains sealed.

This form changes routing metadata only. It cannot display, export, or replace the provider API key.

Preparing verified preview…

New and revised records stay provisional until an authorized reviewer verifies them.