Denials are first-class
A blocked action is evidence too — it protects you later. Fail-closed decisions are preserved, not discarded.
Approvals bound to the exact action
A human approval applies to one specific action, is used once, and expires — it cannot be reused or transferred to a different invocation.
Built for audit
Open a decision and see its authority trail in one place. Evidence is designed to be tamper-evident and replayable.
Sample decision — what evidence captures
Illustrative readout. Every field binds to the decision at execution time.
Three proofs every consequential action should leave
No schema knowledge required — just three questions, always answerable.
Actor proof
Who or what acted?
Identity continuity confirms the actor and whether its behavior is consistent with the past — not just a valid credential.
Authority proof
What policy and approval applied?
The rules in force and any human approval bound to the exact action — single-use and expiring.
Outcome proof
What happened, and what evidence exists?
The decision — allow, deny, or hold — and a replayable evidence bundle that explains it later.
What each evidence anchor means
Plain language — not internal schema names. These are names for exact meanings.
Action fingerprint
A fingerprint of the exact action that was proposed.
Proves: This approval was for this action — not a swapped one.
Policy fingerprint
A fingerprint of the rules in force at decision time.
Proves: These exact rules applied when we decided.
Actor recognition record
Who the system believed was acting, and continuity status.
Proves: We recognized this actor under this grant at this moment.
Risk context record
The risk context that triggered escalation, if any.
Proves: Elevated risk at time T — preserved even if it later cools.
Human approval record
A sealed record of a human decision bound to the action.
Proves: A specific person approved this exact action before it ran.
What becomes easier to assess
Autonomous workflows become easier to underwrite, audit, and approve when identity, authorization, approval, and evidence exist before execution. We don't claim to make workflows insurable — we make them legible to the people who decide.
