Mandatory disclosure
Every agent identifies itself as an AI in any external communication. You are never talking to one of our agents believing it is a person, and there is no setting that turns this off.
Governance & control
A system that executes without a person in the loop must be bounded before it runs, not corrected after. These constraints live in the runtime. No axiom, agent or operator can relax them.
Hard constraints
Every agent identifies itself as an AI in any external communication. You are never talking to one of our agents believing it is a person, and there is no setting that turns this off.
Decisions that are hard to reverse, that risk the whole entity, or that touch a declared ethical boundary halt and escalate to a human. Cheap, local and recoverable actions never do — a gate on everything is a gate nobody reads.
Spend tiers, change-rate ceilings on customer-facing systems, portfolio caps and stop criteria live in deterministic server-side code. The agent may only ask; the runtime decides. Model compliance is never the control.
Every action, output and cent of inference is logged against the agent that caused it, with the reason it was permitted. Nothing in the operating record is reconstructed after the fact, and nothing is editable once written.
Delegation
An agent is not "trusted" or "untrusted". Each responsibility it holds resolves to one of three modes, and the resolution is computed in one place so no screen can show a different answer from the runtime.
Every change to that grant carries a reason, is attributed to the person who made it, and is appended to a ledger that cannot be edited afterwards — including the changes that reduce oversight.
Direct answers
Deterministic guardrails, not model goodwill. Spend tiers, change-rate ceilings, portfolio caps and registered stop criteria are enforced by the server. An agent that attempts an action outside its grant does not get a warning — it gets a refusal.
No. Disclosure is enforced in code rather than stated in a policy. Every agent identifies itself as an AI in external communication, and there is no configuration that disables it.
Writes and revises the axioms, allocates capital, and decides anything irreversible or company-risking. Everything cheap, local and recoverable executes autonomously. In a normal week that is a handful of decisions rather than a calendar of meetings.
The parameters that produced it are revised, and the constraint that should have caught it is added or tightened. Execution is never asked to try harder — that is a management move, and there is nobody to manage.
The people who declared the axioms. Autonomy is delegated execution, not delegated responsibility, and the ledger makes the delegation explicit rather than implied.
Model access runs through credentials you control, per provider, and the runtime records which model served which turn. Specifics — residency, retention, the provider set you are willing to use — are a conversation for the demo, and we would rather answer them precisely than publish a paragraph that reads well.
The governance layer is the part worth interrogating, and the demo is where it holds up or does not.