Governed execution for agentic systems

Let agents act without giving them invisible authority.

Anthesis evaluates consequential agent actions against explicit policy, authority, approvals, capabilities, and evidence requirements.

The decision becomes meaningful when the surrounding tool surface, gateway, credential boundary, downstream validator, capability system, or runtime prevents the agent from bypassing it.

Runnable public proof

Three proof surfaces. Three different questions.

The counts are intentionally separate. The 24 inference-integrity cases are not part of the 27 general demonstration scenarios.

Runnable now

7 canonical governance scenarios

Stable public conformance fixtures for deterministic allow, approval-required, policy-deny, and engine-guard outcomes.

Open the operator runbook →

Runnable now

9 packs / 27 scenarios

Broader synthetic governed-action coverage across documentation, source, CI/release, dependencies, secrets, tools, runtimes, administration, and adversarial declarations.

Inspect the demo packs →

Runnable now

24 inference-integrity scenarios

Recorded provider-neutral evidence for identity, seed/token integrity, verifier trust, routing, supervisor/specialist localization, re-verification, operating modes, and recovery.

Open the inference-integrity runbook →

Reproduce everything: use the Governance Lab full-verification runbook for signed evaluator acquisition, expected counts, controlled mismatch checks, evidence generation, and checksums.

Responsibility boundaries

Policy, validation, and execution have distinct owners.

Keeping them separate prevents the demonstration harness or runtime from becoming a self-certifying policy authority.

Anthesis ecosystem responsibilities
ComponentResponsibility
AnthesisPolicy authority, deterministic evaluator semantics, approval requirements, capabilities, evidence semantics, and provenance.
Governance LabIndependent conformance, synthetic scenario packs, inference-integrity fixtures, reports, and walkthroughs. It does not execute production effects.
DubniumReference runtime, gateway, bounded tools, execution, and runtime evidence. It consumes decisions and does not define policy authority.

Integration assurance

Where enforcement lives is not the same as how strong it is.

The same integration style may be advisory, moderate, strong, or runtime-enforced depending on which bypass paths remain.

Anthesis integration enforcement locations and assurance conditions
ModeEnforcement locationRequired bypass controlTypical assurance
Tool wrapper / invokeTool surfaceRaw effectful tools are unavailable to the agent.Moderate to strong
MCP mediationTool surfaceRaw downstream MCP servers, credentials, and direct service paths are unavailable or constrained.Moderate to strong
Gateway / sidecarInfrastructureDownstream effects are unreachable except through the governed gateway.Strong
Capability tokensInfrastructure / downstream toolEffects reject missing, expired, altered, replayed, or out-of-scope grants.Strong
SDK wrapperApplicationDirect clients and raw credentials are blocked or the mode is explicitly advisory.Advisory to moderate
Sandboxed runtimeRuntimeFilesystem, network, process, credentials, and tools are unavailable outside governed paths.Runtime-enforced when complete

What prevents the agent from producing this effect without crossing Anthesis?

Read the integration modes →

Current maturity

Use precise claims for each layer.

Public materials distinguish deterministic evaluation, bounded reference execution, and broader production assurance.

Runnable now

Deterministic public validation

Signed evaluator acquisition, 7 canonical scenarios, 9 packs / 27 scenarios, 24 inference-integrity scenarios, reports, controlled mismatch exercises, and reproducible evidence.

Reference integration

Bounded governed-agent execution

Dubnium demonstrates one composition with exact authorization binding, approval-gated constrained tools, and runtime evidence.

In development

Broader production assurance

Additional enforcement profiles and stronger live inference-integrity capture, replay, independent verification, containment, and recovery.

Trust boundary: Governance Lab demonstrates deterministic contract behavior over synthetic declarations and recorded evidence. It does not prove universal effect enforcement or live non-bypassability. Those guarantees depend on the actual integration environment.

Learn more

Choose the depth that matches your question.

Run Governance Lab

Use the short stakeholder walkthrough or reproduce every current public proof surface.

Stakeholder walkthrough →
Full verification →

Inspect bounded execution

Follow the reference decision, approval, execution, and evidence path.

Dubnium governed-agent runbook →

Read the project brief

See the problem, proof model, integration modes, maturity, and adoption path in one concise document.

Project brief →

Read the whitepaper

Longer-form architecture and governance material.

Whitepaper →

Read the engineering notes

Long-form context on the problem, architecture, and public governance proof. This project site remains authoritative for current product status.

24 Scenarios That Prove Your AI Agent Follows Rules →
Anthesis Update: Memory, Governance, and Beyond the SDLC →
AI SDLC: automating the grind →
All Anthesis posts →