Skip to content

TOVIO Documentation

TOVIO is a next-generation version control system built to replace Git for teams of humans and AI agents, with first-class AI-agent authorization, change-centric identity that survives history rewriting, and cryptographically-enforced per-file permissions.

This is everything you need to learn and use TOVIO.

New to TOVIO? Start here

Make your first repository, then see an AI agent work through TOVIO under a capability token. Supported TOVIO edges reject out-of-scope operations before policy evaluation; process and host sandboxing remain a separate deployment responsibility.

Get started

Choose your path

  • Get started


    Install TOVIO, make your first commit, and protect your first secret - the 10-minute tour.

    Tutorials

  • AI agents & automation


    Give coding agents scoped, audited, cryptographically-bounded access. The TOVIO differentiator.

    For agents

  • Core concepts


    The seven ideas TOVIO is built from, mapped to the Git concepts you already know.

    Understand TOVIO

  • Guides


    Task-focused how-tos: commit, branch, land, protect files, resolve conflicts, collaborate.

    How-to guides

  • Plugins


    Sandboxed lifecycle extensions: required checks, resolvers, transforms — no shell hooks.

    Plugin system

  • CLI reference


    Every tovio command, flag, configuration key, and error code.

    Reference

  • Run the Forge yourself


    Run your own TOVIO Forge: deploy, federate identity, govern, scale, harden.

    Operate

Why TOVIO

  • AI agents are first-class, bounded participants. Capability tokens scope what an agent may touch; every agent change carries signed, task-level provenance; a whole fleet works one repo in parallel.
  • History is safe to rewrite. A stable Change ID survives amend, rebase, squash, and reorder - so the audit trail survives an agent rewriting history.
  • Keep some files private inside a shared repo. Protected files are ciphertext to anyone without clearance - human or agent - enforced by mathematics, not a server.
  • Recorded local mutations are reversible. The local operation log can restore supported commits, lands, rewrites, lane changes, and sync state; irreversible maintenance and already-observed remote side effects remain outside that guarantee.

TOVIO is in active development

Phases 0–4 are implementation-complete under their supported profiles. Phase 5 is in progress: M5.0 contracts/gates are complete and M5.1-M5.8 remain open. TOVIO is not generally available, its packages are unpublished, and independent assurance is incomplete. See the roadmap.

Last reviewed September 9, 2026

Suggest an improvement to this page Not for security reports — see disclosure