Project brief

Anthesis

Governed execution for agentic systems

Anthesis is the governance boundary between an agent's intent and its externally observable effects.

It evaluates consequential actions against explicit policy, authority, approvals, capabilities, and evidence requirements. A surrounding tool, gateway, credential boundary, downstream validator, or runtime must then enforce the decision.

The problem

Agents gain practical authority through tool registries, credentials, network access, delegated specialists, filesystem access, and automated loops. Without a deliberate governance boundary, that authority can be implicit, bypassable, and difficult to reconstruct after an incident.

Anthesis turns a proposed consequential effect into a structured decision with explicit policy, authority, approval, capability, and evidence requirements. It does not become an enforcement guarantee merely because an application calls it; the integration must remove or constrain direct effect paths.

Public proof paths

Validation and execution are separate so their claims remain precise.

Runnable now

Anthesis Governance Lab

An independently runnable deterministic proof surface using the public Rust evaluator, immutable acquisition, reconciled scenario catalogs, and aggregate reports.

  • Reconciled themed packs spanning representative governed actions
  • Stable allow, approval-required, deny, guard, and drift outcomes
  • No declared filesystem, network, merge, deployment, or release effect is executed

Reference integration

Dubnium governed-agent demo

A bounded execution path that normalizes actions, invokes Anthesis, binds exact approvals, runs only constrained tools, and produces sanitized tamper-evident evidence.

This demonstrates one enforceable composition. It is not a claim that every Anthesis deployment has equivalent runtime controls.

Responsibility boundaries

Anthesis ecosystem responsibilities
Component Owns Does not own
Anthesis Policy authority, deterministic decision contracts, approvals, capabilities, evidence semantics, and provenance General-purpose agent orchestration or universal effect enforcement
Governance Lab Independent conformance, scenario packs, reports, and walkthroughs Runtime execution, durable approvals, or production non-bypassability
Dubnium Reference runtime, gateway, bounded tools, execution, and runtime evidence Anthesis policy authority or universal deployment guarantees

Six integration modes

Each mode must identify its enforcement location, bypass prevention, evidence return path, and residual trust assumptions.

Anthesis integration modes, enforcement locations, bypass controls, and typical assurance
Mode Enforcement location Required bypass control Typical assurance
Tool wrapper / invoke Tool surface Raw tools are not available to the agent. Moderate to strong
MCP mediation Tool surface Raw downstream MCP servers, credentials, and direct service paths are unavailable or constrained. Moderate to strong
Gateway / sidecar Infrastructure Downstream services are unreachable except through the gateway. Strong
Capability tokens Infrastructure or downstream tool Effects reject missing, expired, altered, replayed, or out-of-scope grants. Strong
SDK wrapper Application Direct clients and raw credentials do not remain an uncontrolled path. Advisory to moderate
Sandboxed runtime Runtime Filesystem, network, process, credentials, and tools are unavailable outside governed paths. Runtime-enforced when complete

Enforcement location and assurance are separate dimensions. An MCP or SDK integration may be cooperative or strong depending on credential ownership, network controls, registry restriction, downstream validation, and other bypass controls.

Current maturity

Runnable now

Public evaluator, Governance Lab packs, deterministic reports, and stakeholder walkthroughs.

Reference integration

Dubnium approval-gated bounded execution with authorization binding and verified evidence.

In development

Broader production enforcement profiles and stronger live inference-integrity evidence, replay, verification, containment, and recovery.

Adoption path

  1. Validate the contract. Run Governance Lab and inspect deterministic decisions, reasons, rules, and reports.
  2. Integrate one bounded effect. Identify the action, credentials, executor, direct bypass paths, and required evidence.
  3. Strengthen enforcement. Add registry restriction, credential isolation, gateway controls, capability validation, egress controls, or sandboxing according to risk.

A trial is successful when reviewers can explain what Anthesis decided, what prevented bypass, who executed the action, which approval or capability authorized it, what evidence proves the outcome, and which residual assumptions remain.

Trust boundary

Governance Lab demonstrates deterministic contract behavior, not effect execution. Dubnium demonstrates one bounded reference integration, not universal production enforcement. Anthesis does not guarantee deterministic model output, universal replay, complete compliance, or non-bypassability without an enforcing environment.