Runnable now
7 canonical governance scenarios
Stable public conformance fixtures for deterministic governance decisions and controlled expectation-drift testing.
Project brief
Governed execution for agentic systems
Anthesis is the governance boundary between an agent's intent and its externally observable effects.
It evaluates consequential actions against explicit policy, authority, approvals, capabilities, and evidence requirements. A surrounding tool surface, gateway, credential boundary, downstream validator, capability system, or runtime must then make that decision authoritative.
Agentic systems gain practical authority through tool registries, credentials, network access, delegated specialists, filesystem access, and automated loops. Without a deliberate governance boundary, that authority can be implicit, bypassable, and difficult to reconstruct after an incident.
Anthesis turns a proposed consequential effect into a structured decision with explicit policy, authority, approval, capability, and evidence requirements. It does not become an enforcement guarantee merely because an application calls it; the integration must remove or constrain direct effect paths.
Governance Lab keeps three proof surfaces separate so each claim stays precise. The 24 inference-integrity cases are separate from the 27 general demo scenarios.
Runnable now
Stable public conformance fixtures for deterministic governance decisions and controlled expectation-drift testing.
Runnable now
Broader synthetic governed-action coverage spanning SDLC and operational declarations without executing the effects.
Runnable now
Recorded provider-neutral evidence for identity, seed/token integrity, verifier trust, routing, topology, re-verification, operating modes, and recovery.
Full reproduction path: signed evaluator acquisition, all three proof surfaces, controlled mismatch checks, evidence generation, and checksums are documented in the Governance Lab full-verification runbook.
The dedicated inference-integrity runbook explains the 24-case verification classes and limitations.
| Component | Owns | Does not own |
|---|---|---|
| Anthesis | Policy authority, deterministic evaluator semantics, approval requirements, capabilities, evidence semantics, and provenance. | General-purpose orchestration or universal runtime enforcement. |
| Governance Lab | Independent conformance, scenario packs, inference-integrity fixtures, reports, and walkthroughs. | Runtime execution, durable production approvals, or universal non-bypassability. |
| Dubnium | Reference runtime, gateway, bounded tools, execution, and runtime evidence. | Anthesis policy authority or universal deployment guarantees. |
Each mode must identify its enforcement location, bypass prevention, evidence return path, and residual trust assumptions.
| Mode | Enforcement location | Required bypass control | Typical assurance |
|---|---|---|---|
| Tool wrapper / invoke | Tool surface | Raw effectful tools are not available to the agent. | Moderate to strong |
| MCP mediation | Tool surface | Raw downstream MCP servers, credentials, and direct service paths are unavailable or constrained. | Moderate to strong |
| Gateway / sidecar | Infrastructure | Downstream services are unreachable except through the governed gateway. | Strong |
| Capability tokens | Infrastructure / downstream tool | Effects reject missing, expired, altered, replayed, or out-of-scope grants. | Strong |
| SDK wrapper | Application | Direct clients and raw credentials do not remain an uncontrolled path. | Advisory to moderate |
| Sandboxed runtime | Runtime | Filesystem, network, process, credentials, and tools are unavailable outside governed paths. | Runtime-enforced when complete |
Enforcement location and assurance are separate dimensions. An MCP, SDK, or tool-wrapper integration may be cooperative or strong depending on credential ownership, network controls, registry restriction, downstream validation, and remaining bypass paths.
A useful trial evaluates the target workflow rather than only the evaluator.
Runnable now
Signed public evaluator, 7 canonical scenarios, 9 packs / 27 scenarios, 24 inference-integrity scenarios, deterministic reports, and reproducible evidence.
Reference integration
Dubnium bounded execution with authorization binding, approval-gated constrained tools, and runtime evidence.
In development
Broader production enforcement profiles and stronger live inference-integrity capture, replay, verification, containment, and recovery.
Governance Lab demonstrates deterministic contract behavior over synthetic declarations and recorded evidence, not effect execution. Dubnium demonstrates one bounded reference integration, not universal production enforcement. Anthesis does not guarantee deterministic model output, universal replay, complete compliance, or non-bypassability without an enforcing environment.