Gate 01 Deterministic Agent Authorization

AUTONOMY, on the Record.

The control plane between an agent’s intent and its consequences. Every action is checked against frozen policy before it runs, and leaves a receipt you can verify without trusting us or the model.

  • 27.8 ms authorization p95
  • 16 / 16 security requirements
  • Fails closed unknown never allows
27.80 msauthorization p95, in-process path
16 of 16security acceptance requirements passed
107tests against real PostgreSQL, not mocks
0caches or shed paths added to flatter latency
1 chainreceipt history verifiable under sustained load
Fails closedunknown never resolves to allow

Four Gates Between Intent and Consequence.

An agent asking to move $47,800 is not an execution problem. It is an authorization problem that happens to end in execution. RobotID separates the two and puts four checks in the gap.

  1. 01

    Identify

    Every actor enters as an explicitly registered identity inside a tenant boundary. Nothing acts anonymously and nothing inherits trust from the process it runs in.

    Unregistered actor denied

  2. 02

    Authorize

    The requested action is evaluated against frozen policy, delegation scope, separation of duties, and expiry, in real time, with the exact context of the call.

    Policy version drift denied

  3. 03

    Approve

    When policy says a human owns the decision, the action stops and waits. Approval is bounded, single-use and attached to that exact action, not to the agent.

    Approval reused denied

  4. 04

    Prove

    The decision is written as a tamper-evident receipt and linked to the one before it. Anyone with the chain can confirm what was authorized.

    Broken link in the chain surfaced

Move the Amount. Watch the Policy Hold.

This is the real rule set from the day-one control loop — allow below $10,000, require CFO approval up to $100,000, deny above it. Drag the amount and the decision, the reason and the receipt all change with it.

FinanceAgent requests wire.create

$47,800

Vendor payout, tenant acme-prod

Allow to $10KApproval to $100KDeny above
Require Approval

Above the $10,000 autonomous ceiling. The action is held and routed to the CFO. The agent is not blocked, it is waiting.

Decision path

27.8 ms
Identity resolved inside tenant boundaryFinanceAgent
Policy evaluated against frozen rulesetfinance-prod@17
Deterministic decision returnedREQUIRE_APPROVAL
Human approval requested and boundedCFO
Downstream execution attemptedHELD
Decision receipt written and chainedSEALED
receipt
8f3c2a91d4e7b1
previous
c07de4128a5f36
chain height
4,182
verification
intact

It Fails Closed. By Design.

Most agent infrastructure gets fast by getting loose: cache the decision, pool the connection, drop the write under pressure. Every one of those trades correctness for a benchmark. RobotID holds five invariants instead, and publishes what they cost.

tenancy

Isolation is enforced by the database, not the query. FORCE row-level security is validated against real PostgreSQL, so an application bug cannot leak across a tenant boundary.

Verified in the M11 lane, 107 tests, no mocked driver
atomicity

The receipt and the outbox commit together or not at all. There is no window where an action was dispatched but its evidence was lost.

Single transaction, no deferred write path
fail-open

Permitted fail-open is an event, not a silence. When policy explicitly allows degraded operation, it writes a distinct durable enforcement record that is never mistaken for a normal decision.

Separate record type, separately auditable
semantics

UNKNOWN never becomes ALLOW. An evaluator that cannot reach a confident decision returns a denial, including when the failure is ours.

Enforced in the pure evaluator, not the caller
honesty

No shortcut was added to improve the published number. The 27.80 ms p95 is the existing in-process path under the M11 profile, with no cache, pool change or load shedding introduced to reach it.

The number moves when the system does

Six Layers, One Enforcement Boundary.

The agent never talks to the decision. It talks to a policy enforcement point, and the enforcement point talks to an evaluator that has no side effects. Hover a layer to lift it out of the stack.

Agent and SDKcarries request context
Gatewaythe enforcement boundary
Authorization servicepolicy, delegation, approval
Deterministic evaluatorpure decision, no side effects
Evidence and receiptstamper-evident history
PostgreSQLforced row-level security

Where Autonomy
Stops Being a Demo.

The moment an agent can spend, delete, grant or send, the interesting question is no longer whether it works. It is who authorized it, and whether you can still prove that next quarter.

Finance

Agents that Move Money

Bind transaction authority to amount, counterparty, approver and time window. The approval a CFO grants covers one payment, not a standing permission an agent can reuse tomorrow.

Security

Privileged Operations

Key rotation, access grants and production changes keep evidence by default.

Platform

Tool Execution

Let agents reach internal systems without handing them the service account.

Multi-agent operations

Delegation that Actually Narrows

A child agent receives strictly less authority than its parent, and the receipt chain shows the boundary held even when the orchestration was three agents deep and nobody was watching.

Let it Act. Then Prove it.

Every autonomous system eventually produces the same question in a room full of people who were not there: who authorized this? RobotID is the answer you can hand over.