Governance recipes

Same gate. Same receipts. Any provider. Aarmos governs the calls your agent makes — swapping the LLM changes three env vars, not your policy.

Pick a provider

None of the recipes require code changes in your agent — Aarmos enrols agents at the proxy layer via eval "$(aarmos env)", which exports authenticated proxy credentials for the running session. No CA certificate to install: the proxy tunnels HTTPS by hostname and never decrypts it.