Project brief

Anthesis

Governed execution for agentic systems

Anthesis is the governance boundary between an agent's intent and its externally observable effects.

It evaluates consequential actions against explicit policy, authority, approvals, capabilities, and evidence requirements. A surrounding tool surface, gateway, credential boundary, downstream validator, capability system, or runtime must then make that decision authoritative.

The problem

Agentic systems gain practical authority through tool registries, credentials, network access, delegated specialists, filesystem access, and automated loops. Without a deliberate governance boundary, that authority can be implicit, bypassable, and difficult to reconstruct after an incident.

Anthesis turns a proposed consequential effect into a structured decision with explicit policy, authority, approval, capability, and evidence requirements. It does not become an enforcement guarantee merely because an application calls it; the integration must remove or constrain direct effect paths.

Public proof model

Governance Lab keeps three proof surfaces separate so each claim stays precise. The 24 inference-integrity cases are separate from the 27 general demo scenarios.

Runnable now

7 canonical governance scenarios

Stable public conformance fixtures for deterministic governance decisions and controlled expectation-drift testing.

Runnable now

9 packs / 27 scenarios

Broader synthetic governed-action coverage spanning SDLC and operational declarations without executing the effects.

Runnable now

24 inference-integrity scenarios

Recorded provider-neutral evidence for identity, seed/token integrity, verifier trust, routing, topology, re-verification, operating modes, and recovery.

Full reproduction path: signed evaluator acquisition, all three proof surfaces, controlled mismatch checks, evidence generation, and checksums are documented in the Governance Lab full-verification runbook.

The dedicated inference-integrity runbook explains the 24-case verification classes and limitations.

Responsibility boundaries

Anthesis ecosystem responsibilities
ComponentOwnsDoes not own
AnthesisPolicy authority, deterministic evaluator semantics, approval requirements, capabilities, evidence semantics, and provenance.General-purpose orchestration or universal runtime enforcement.
Governance LabIndependent conformance, scenario packs, inference-integrity fixtures, reports, and walkthroughs.Runtime execution, durable production approvals, or universal non-bypassability.
DubniumReference runtime, gateway, bounded tools, execution, and runtime evidence.Anthesis policy authority or universal deployment guarantees.

Six integration modes

Each mode must identify its enforcement location, bypass prevention, evidence return path, and residual trust assumptions.

Anthesis integration modes and assurance
ModeEnforcement locationRequired bypass controlTypical assurance
Tool wrapper / invokeTool surfaceRaw effectful tools are not available to the agent.Moderate to strong
MCP mediationTool surfaceRaw downstream MCP servers, credentials, and direct service paths are unavailable or constrained.Moderate to strong
Gateway / sidecarInfrastructureDownstream services are unreachable except through the governed gateway.Strong
Capability tokensInfrastructure / downstream toolEffects reject missing, expired, altered, replayed, or out-of-scope grants.Strong
SDK wrapperApplicationDirect clients and raw credentials do not remain an uncontrolled path.Advisory to moderate
Sandboxed runtimeRuntimeFilesystem, network, process, credentials, and tools are unavailable outside governed paths.Runtime-enforced when complete

Enforcement location and assurance are separate dimensions. An MCP, SDK, or tool-wrapper integration may be cooperative or strong depending on credential ownership, network controls, registry restriction, downstream validation, and remaining bypass paths.

Trial criteria

A useful trial evaluates the target workflow rather than only the evaluator.

  1. Enforceability: governed effects must cross the selected boundary.
  2. Attribution: actor, runtime, tool, decision, approval/capability, and evidence are identifiable.
  3. Least privilege: out-of-scope variants are denied.
  4. Human approval: approval-required effects remain blocked until exact scope is granted.
  5. Auditability: decisions, approvals, effects, and outcomes can be reconstructed at the claimed verification level.
  6. Bypass resistance: direct effect paths and residual trust assumptions are explicitly tested or documented.

Read the full trial criteria →

Current maturity

Runnable now

Signed public evaluator, 7 canonical scenarios, 9 packs / 27 scenarios, 24 inference-integrity scenarios, deterministic reports, and reproducible evidence.

Reference integration

Dubnium bounded execution with authorization binding, approval-gated constrained tools, and runtime evidence.

In development

Broader production enforcement profiles and stronger live inference-integrity capture, replay, verification, containment, and recovery.

Trust boundary

Governance Lab demonstrates deterministic contract behavior over synthetic declarations and recorded evidence, not effect execution. Dubnium demonstrates one bounded reference integration, not universal production enforcement. Anthesis does not guarantee deterministic model output, universal replay, complete compliance, or non-bypassability without an enforcing environment.