Governed agents

Let agents adapt without expanding their authority.

Your systems and authorized reviewers decide what's permitted. As agents change tools, plans, and routes, FieldHash keeps that authority connected to what they read, do, and reuse at the points you govern.

An external authority and evidence plane for adaptive agents.

Start with one consequential workflow. Production enforcement stays off during the evaluation.

The problem

Finding another route does not create permission.

An agent works toward an objective. A control denies one request. The agent can then try another tool, call a different API, submit a queued job, or delegate the work.

The route changes. The desired effect may not.

  1. Tool denied
  2. API reachable
  3. Queue reachable
  4. Delegate reachable
Illustrative routes to the same effect. Reachable does not mean authorized.

A check on one request does not, by itself, establish what remains authorized across the task. FieldHash keeps customer-defined authority connected to the decisions you govern as that task changes.

If an unauthorized refund goes through, the cost can extend beyond the payment to rework, approval disputes, and reconstructing what happened. Your team needs evidence of what executed and which authority it relied on.

How FieldHash works

Govern what agents read, do, and reuse.

Your policies, approvals, revocations, and authorized reviews establish the boundary. FieldHash keeps the relevant approvals, scope, status, and recorded dependencies in Authority State, a record held outside the model. Each connected handoff checks which authority applies. Your systems remain the source of authority.

What may shape the answer?

Governed Memory

Check which records may enter the governed context. Keep superseded material from being passed to the model as current authority.

What may the agent still do?

Governed Actions

Check proposed actions against current authority, task state, and configured related effects, beyond whether the next tool is reachable. A changed route does not inherit new permission.

Can a reviewed decision be used again?

Governed Precedent

Carry forward eligible human-reviewed decisions while their conditions remain valid. A review does not automatically become reusable precedent.

Current authority connects what agents use, do, and reuse.

Authority originates outside the agent

Customer systems and authorized reviewers

Governing records, approvals, scope, expiry and revocation.

Configured dependencies

Connected changes require dependent authority to be checked again.

FieldHash-governed handoffs

Agents can plan, delegate, or change routes. Each connected surface checks the authority that applies.

Memory / Influence

Which record may govern?

Actions / Effect

What may proceed?

Precedent / Reuse

Does the review still apply?

These are related surfaces; a workflow need not traverse them in this order.

Authority decision

Allow, withhold, or send to review

A decision governs the connected handoff. Review returns to an authorized person.

Separate evidence record

Source, decision and result

Inspectable evidence records what governed and what occurred; the record itself grants no authority.

Conceptual architecture, not an observed end-to-end result. Unmediated routes remain outside this control.
See how the product works

Make review count

Review compounds through bounded reuse.

Some decisions should remain one-off. Others can become bounded precedent for future work.

FieldHash lets eligible reviewed decisions carry forward without treating yesterday's approval as permanent permission. When a recorded change invalidates a required dependency, affected reuse is suspended. Unrelated workflows are not suspended by that dependency change.

Reuse the judgment. Recheck the authority.

Inspect the bounded-reuse study

FieldHash Ledger

Verified evidence before an inline allow.

FieldHash Ledger connects the governing authority, decision, reason, signer, and any available execution receipt in a verifiable evidence record.

On the controlled inline context path, FieldHash returns an allow only after recording the signed decision and verifying its integrity. The decision record establishes what was allowed; an execution receipt, when available, records the executor's reported result.

Inspect the evidence model

Evidence you can inspect

We left a gap. The agents found it.

In a synthetic, self-administered study, we tested eight simulated execution surfaces. One condition deliberately left a consequential route outside FieldHash. Another governed all eight tested surfaces.

Where it fits

Keep your models, tools, identity, and systems of record.

Expose the handoff; FieldHash governs it. Connect the authority sources and decision points before selected context reaches the model or a supported action is dispatched. That connected decision point is the governed handoff.

Scope deployment in your customer VPC or private environment. Scoped on-prem pilots are available where local custody is required. FieldHash complements IAM, sandboxing, and authentication. Your organization continues to own its policies.

FieldHash governs connected, configured paths. It does not claim to discover or contain every unknown route an agent could take.

Explore integration and deployment

Six-week shadow evaluation

Start with one workflow. Decide with evidence.

Six weeks. One approval-sensitive workflow.

Evaluate FieldHash in shadow mode, with production enforcement off and acceptance criteria agreed upfront. Bring a policy assistant handling live exceptions, or an approval-gated action reachable through more than one tool, credential, or runtime.

  1. 1. Map the authority.

    Identify the governing sources, the connected decision points, and who owns review.

  2. 2. Observe the differences.

    Compare current behavior with what FieldHash would allow, withhold, or send to review.

  3. 3. Measure the trade-offs.

    Evaluate false allows, over-blocking, review burden, latency, integration effort, and evidence usefulness.

  4. 4. Decide what belongs inline.

    Use the findings to decide whether selected paths are worth moving to enforcement.

Your closeoutShadow mode

Receive an evidence report and a recommendation to enforce, adjust, continue in shadow mode, or stop. Production enforcement requires separate testing and acceptance. The agreed scope identifies which gate, console, review queue, and Ledger components are included.

Explore the evaluation

Let the agent choose another route. Keep authority with your organization.