Governance Engine
The authorize gate that runs the policy on every signed action, in cooperative or trustless mode, with human-in-the-loop escalation.
What it does
The Governance Engine is the authorize gate that runs the policy on every signed agent action. It can run cooperatively inside the agent or trustlessly at the service it calls, checks the action against the agent's mandate and the active Standards & SOPs, and routes anything that needs a human to the owner's escalation queue for approval before it proceeds.
Inside Governance Engine
The core functions this engine provides across the Trust Fabric.
Governance Engine composes with the Trust Fabric
Every engine is independently useful and interoperates through one API-first Trust Fabric — so identity, evidence, policy, risk and certification stay consistent across your AI estate.
Related engines
Action Passport
A signed, single-use proof that one exact action was authorized — bound to that authorization alone, carrying no raw payload content.
- Issued only on allow / observe
- Bound 1:1 to a single authorization
- No amount, merchant or payload data
- Paired Execution Receipt proves payloadMatch
Credential Vault
Encrypted-at-rest storage for the upstream credentials your agents need — released just-in-time, only to a gateway, only against a currently-active Action Passport.
- AES-256-GCM at rest
- One release path, gated on two factors
- Tenant derived from the passport, never the caller
- Every attempt audited, plaintext never logged
Evidence Engine
Signs every decision, batches them into a Merkle root, anchors it on Hedera, and lets anyone verify a record offline.
- Ed25519-signed receipts
- Merkle batching
- HCS anchoring
- Offline verification (magp-evidence)
See Governance Engine in action
Book a demo and see how the platform establishes trust across your AI systems.
