Technical work on policy-gated agent execution, human authorization, provenance, attestation, and reconciliation. We publish working papers, experiments, architecture notes, and implementation reports — including limitations and negative results.
Gating every action produces approval fatigue, which is the same as gating nothing. Classification is the design problem — and a gate that classifies correctly can still be inert if nothing populates its rules.
Our attestation chain is signed, hash-linked, and re-verified on every read. It is tamper-evident. It is not independently verifiable, and the distinction is the first thing a security reviewer will test.