Personal build · checked 11 October 2026
Governed agent
control plane.
I built a governed agent control plane to connect delegated work with identity, permissions, durable ownership and release control. This work uses my personal time and infrastructure.
Authority, evidence and recovery
The architecture essay · Completion needs readback
The product problem
Once an agent can change things, its answer is only one part of the product. The system needs to know who authorised the action, who owns the next step and whether the intended state exists. I wanted those facts to survive a model or runtime change.
The alternative was to put tools, approvals and memory inside each assistant. That is simpler to start, but spreads authority across sessions and makes a handoff hard to inspect. A shared control plane adds coordination overhead in exchange for explicit boundaries.
The architecture
What the evidence supports
Live means observed usage with readback in the stated scope. Piloted means a bounded trial. Designed means the published architecture describes the target behaviour; operational acceptance is not claimed for that scope.
| Component | Status | Demonstrated behaviour and limitation |
|---|---|---|
| Tool gateway | Live | Authenticated public-record work and ledger reads/writes were exercised through a shared MCP access surface. Model inference routing is a separate path; this does not establish all-runtime acceptance. |
| Work ledger | Live | Revision-guarded updates and independent readback preserve the next actor and current task state. A completed issue does not itself prove a deployed result. |
| Provenance memory | Live | Recall returns evidence identifiers and source metadata. Retention records provenance; an asynchronous queue receipt is not completed storage. Tenant isolation is not claimed here. |
| Independent review and release verification | Live | The site release used a distinct reviewer, exact-head hosted review, signed commits, deployment readback and behavioural checks. The broader fleet is a separate acceptance scope. |
| Runtime identity and model-tier routing | Designed | The architecture specifies identities at runtime boundaries and separate model tiers. Complete runtime-canary and denial coverage is not established by this public write-up. |
| Instruction containment | Designed | Retrieved content is treated as evidence rather than permission. The fictional denial flow below explains the boundary; systematic injection-resistance results are not published. |
| Simulation and consolidated observability | Designed | A design direction for replay, recovery, authority violations, human attention and total cost. A unified view and public evaluation reports are still open work. |
A fictional task, including the denial path
- An owner asks to update the opening hours of a community library.
- The ledger records the branch, expected revision and next actor. The executor retrieves the attributed source.
- A retrieved page says to change an unrelated account setting. That text supplies no permission; the proposed operation stops at the scope boundary.
- A distinct reviewer inspects the hours change. A rejection returns the task with the reason; the executor does not perform the rejected effect.
- After approval, the executor applies the bounded change and reads the destination. If the record is correct but the public page is stale, the receipt records partial completion and the repair that remains.
This flow illustrates the design. It is not a reported trial or a universal defence against malicious prompts.
The tradeoffs
Centralised ownership reduces ambiguous handoffs but creates a coordination dependency. Review makes consequential changes slower. Provenance increases storage and retrieval complexity. A fail-closed boundary needs a useful recovery path, otherwise its queue becomes the product.
What remains open
Simulation coverage and a consolidated observability view remain gaps. Agent VITALS is planned evaluation work addressing them: replay, outcome verification, authority violations, human attention and total cost. Public repository links and results will follow an actual public release; no performance result is claimed here.
The private operations gateway is separate from this site’s public read-only evidence tools.
Reference points
MCP authorization informs the access boundary. SLSA verification guidance informs artifact checks, without a certification claim. Anthropic’s agent-evaluation guidance informs the next evaluation work. These references explain the framework; they do not verify this personal system.