The Governance Operating Model
How organisations organise people, process and technology to govern AI continuously — the roles and workflows that the protocol makes real.
Roles & accountability
A verified legal Owner authorises each agent and is the default approver for escalations; a compliance team authors Standards & SOPs; developers integrate the guard. Accountability is cryptographic — the mandate names the authorising principal, and every decision is attributable.
The core workflows
- Onboarding & issuance — verify the owner (KYC/KYB) or start on the free tier, issue identity + mandate in one call
- Policy authoring — compose Standards & SOPs from deterministic atoms; edit live
- The authorize gate — allow / observe / block / escalate on every governed action
- Human-in-the-loop — escalations park for the owner to approve or deny
- Evidence & audit — signed, anchored, offline-verifiable decision records
- Delegated issuance — a developer requests, the owner approves in the dashboard
The technology underneath
The operating model runs on the Trust Fabric: an identity service (DIDs + VCs), a deterministic policy engine (atoms → molecules → Standards/SOPs), the signed authorize gate, an evidence pipeline (Merkle-batched, HCS-anchored), and the Trust Index. Each is an open, verifiable component — enforcement never depends on trusting a black box.
Cooperative and trustless enforcement
The gate is a checkpoint. In cooperative mode the agent's own guard calls it and refuses on block/escalate; in trustless mode the counterparty (e.g. an MCP) re-verifies the agent's signed request against its policy bundle — so a rogue agent that skips the check can't get anyone to act on it.
