Governance & control

What the axioms are not permitted to override.

A system that executes without a person in the loop must be bounded before it runs, not corrected after. These constraints live in the runtime. No axiom, agent or operator can relax them.

Hard constraints

Four rules with no configuration flag.

01

Mandatory disclosure

Every agent identifies itself as an AI in any external communication. You are never talking to one of our agents believing it is a person, and there is no setting that turns this off.

02

The irreversibility gate

Decisions that are hard to reverse, that risk the whole entity, or that touch a declared ethical boundary halt and escalate to a human. Cheap, local and recoverable actions never do — a gate on everything is a gate nobody reads.

03

Enforced, not requested

Spend tiers, change-rate ceilings on customer-facing systems, portfolio caps and stop criteria live in deterministic server-side code. The agent may only ask; the runtime decides. Model compliance is never the control.

04

Complete attribution

Every action, output and cent of inference is logged against the agent that caused it, with the reason it was permitted. Nothing in the operating record is reconstructed after the fact, and nothing is editable once written.

Delegation

Autonomy is granted per job, not per agent.

An agent is not "trusted" or "untrusted". Each responsibility it holds resolves to one of three modes, and the resolution is computed in one place so no screen can show a different answer from the runtime.

Automatic
The agent acts. Used where the action is cheap, local and reversible.
Drafting
The agent prepares the action and parks it. A person releases it.
Human
The agent may not act at all. The job belongs to a person and stays there.

Every change to that grant carries a reason, is attributed to the person who made it, and is appended to a ledger that cannot be edited afterwards — including the changes that reduce oversight.

Direct answers

The questions that actually get asked.

What stops an agent from doing something catastrophic?

Deterministic guardrails, not model goodwill. Spend tiers, change-rate ceilings, portfolio caps and registered stop criteria are enforced by the server. An agent that attempts an action outside its grant does not get a warning — it gets a refusal.

Will I ever talk to an agent without knowing?

No. Disclosure is enforced in code rather than stated in a policy. Every agent identifies itself as an AI in external communication, and there is no configuration that disables it.

What does a human actually do here?

Writes and revises the axioms, allocates capital, and decides anything irreversible or company-risking. Everything cheap, local and recoverable executes autonomously. In a normal week that is a handful of decisions rather than a calendar of meetings.

What happens when the system gets something wrong?

The parameters that produced it are revised, and the constraint that should have caught it is added or tightened. Execution is never asked to try harder — that is a management move, and there is nobody to manage.

Who is accountable?

The people who declared the axioms. Autonomy is delegated execution, not delegated responsibility, and the ledger makes the delegation explicit rather than implied.

Where does our data go?

Model access runs through credentials you control, per provider, and the runtime records which model served which turn. Specifics — residency, retention, the provider set you are willing to use — are a conversation for the demo, and we would rather answer them precisely than publish a paragraph that reads well.

Bring the hard questions.

The governance layer is the part worth interrogating, and the demo is where it holds up or does not.