Verify
The script validates the embedded shadow manifest and refuses to apply if write scopes, executable permits, credentials, or forbidden consequence effects appear.
SIO24 · One-Command Bootstrap
Turn the read-only Shadow Setup Manifest into a customer-controlled bootstrap artifact. The generated package verifies its own invariants before creating a local observation boundary. It contains no secret, no write scope, no execution credential, and no path for the website to control your environment.
01 / Runtime target
02 / Evidence custody
03 / One command
Complete SIO23 Shadow Mode Quickstart first.The script validates the embedded shadow manifest and refuses to apply if write scopes, executable permits, credentials, or forbidden consequence effects appear.
Customer-local runtime, configuration, inbox, evidence, and teardown directories are created with restrictive defaults.
Local replay can begin immediately. Connected transports remain customer-supplied and read-only; the website never receives their secrets.
The package records a deterministic removal path. Teardown removes the shadow runtime boundary; it does not claim rollback of any consequential action because SIO24 executes none.
write_scopes=0 · permit=PROHIBITED · credential=PROHIBITED · execution=PROHIBITED · proof=NOT_CREATED