From an agent's request to an authorised, evidenced action
From an AI system in the inventory to an authorised, evidenced action.
Two layers, one record
| Layer | What it does | Where you see it |
|---|---|---|
| Governance record | Inventory, classification, risk, controls and evidence for every AI system | Console: Inventory, Risk, Controls, Assurance |
| Runtime authority | Governed state, conflict detection and a decision before each consequential action | Console: Authorisation; API and MCP |
Both layers share the same AI systems, controls and evidence. A control mapped to CPS 230 in the registry is the same control a gate policy enforces at runtime, and the decision receipt it produces becomes evidence for that control.
Step by step
- 1The AI system is known and governed
It is in the inventory with an owner, a risk tier and the controls that apply.
- 2Context becomes governed state
Facts the agent relies on are recorded as typed, versioned state items with their source.
- 3Conflicts are detected
When sources disagree, a conflict is recorded instead of one value silently replacing the other.
- 4Policies are evaluated
The proposed action is checked against gate policies derived from your controls: required state, open conflicts, thresholds and approvals.
- 5A decision is made before the action
The gate returns allow, warn or block. The decision does not depend on a model judgement, so it can be replayed.
- 6A receipt becomes evidence
Every decision is written to the append-only trail with what was asked, what was known and which rule applied.
See a decision being made
- Unresolved conflict on claim.amount ($48,200 vs $41,750)
{
"verdict": "BLOCK",
"action": "release_payment",
"decision_id": "gd_7Q2K9F",
"reasons": [
"Unresolved conflict on claim.amount ($48,200 vs $41,750)"
]
}