Skip to content

Core concepts

This section explains how TOVIO thinks — the mental model underneath the commands. It is for understanding, not for doing. If you want to make your first commit or protect your first secret, start with Get started; when you want to know why things work the way they do, come back here.

TOVIO is a version control system built to replace Git. It keeps everything good about Git — a content-addressed object graph, a commit history you can branch and merge — and changes the few things that have aged badly: the staging area, the fear of rewriting history, secrets you have to keep out of the repo, and the absence of any real model for AI agents. Those changes introduce new ideas, and this is the section that teaches them.

There are only seven concepts

TOVIO is built from seven ideas: an identity, a change, a commit, a conflict, a policy, a capability, and a forge. Understand those and everything else is detail. Start with The seven concepts.

Where to begin

  • The seven concepts


    The whole mental model on one page: identity, change, commit, conflict, policy, capability, forge.

    Read this first

  • Coming from Git


    A concept-by-concept mapping table, and the two mental flips that trip up every Git user.

    Translate your knowledge

  • The change model


    Why changes and commits are different things, and how a stable Change ID makes rewriting safe.

    Changes vs commits

  • Conflicts as data


    Conflicts are stored, not thrown. What "non-blocking" really means — and where its limits are.

    First-class conflicts

Going deeper

  • Permissions


    Clear files vs policy-protected files, the three crypto tiers, and what the Key Authority is — and is not.

    How permissions work

  • Offline & distributed


    Replicas work offline over one immutable object graph. A sync you run that finds your unprotected current lane diverged reconciles it on the lane into a merge-or-conflict commit, rather than leaving an off-lane orphan; a Hybrid Logical Clock propagates the pointer underneath. Sparse, partial, shallow, and lazy profiles need not hold equal object graphs.

    The distributed model

  • Agents & capabilities


    Agent identities, capability scoping, secret_clearance, and provenance on every agent commit.

    Bounded agents

  • Behavioral versioning


    Versioning an AI system's prompts, model, tools, and memory alongside the code it ships in.

    Versioning behavior

  • The Forge & trust


    What the collaboration server stores, why protected payloads do not give it recipient keys merely by being hosted, and which metadata, operational, and disclosure boundaries remain.

    The trust boundary

  • Fearlessness


    The feeling TOVIO optimizes for, and the architecture that earns it: supported local mutations are recorded, inspectable, and reversible.

    The philosophy

TOVIO is built in phases

Phases 0–4—the offline core, cryptographic permissions, agents, synchronization/Forge, and semantic and behavioral versioning—are implementation-complete under their documented supported profiles. Phase 5 productization, publication, hosted and Enterprise evidence, and broader hardening remain open. Each page distinguishes implemented behavior from an unaccepted release or evidence claim.

Last reviewed September 9, 2026

Suggest an improvement to this page Not for security reports — see disclosure