Standard_00 // Reference Architecture
One invariant, and everything else follows from it. Authorization, policy validation, and scope enforcement are preconditions for action. Not runtime suggestions. Not retrospective checks. If an agent cannot satisfy the permit, it does not run.
Completed November 2025. Filed under two USPTO provisional applications. Published as a reference architecture and unchanged since.
A model is probabilistic by design and that is exactly what makes it useful. Execution cannot be. The architecture puts a deterministic boundary between the two, so that inference proposes and a governed layer disposes. That boundary is not advisory and it is not circumventable by the model that sits behind it.
Before an action reaches anything real, the layer resolves who issued the authority, what scope it covers, and whether it is still valid. A failed check is a refusal, not a warning written to a log somebody reads next quarter.
Reproducibility is not a performance target here. It is the precondition for holding anyone accountable, because a decision you cannot reproduce is a decision nobody can be held to.
Every material action produces a cryptographically verifiable, replayable record, written ahead of execution rather than reconstructed after it. The artifact does not depend on model internals or on any vendor's infrastructure to be read.
Execution is local-first with no cloud dependency. A record held by somebody else is a record somebody else can edit, delay, or lose. For regulated industry and anything with a sovereignty requirement, that is the whole procurement conversation.
No agent acts without an issued permit naming an owner, a scope, and an expiry. Permissions are granted rather than inherited, and they do not accumulate quietly over time.
Same inputs, same decision, every time. Nondeterminism is confined to inference and never reaches the execution path.
Every material action leaves a durable, timestamped record that outlives the session that produced it. If it was not recorded, it did not happen.
Authority granted has to be authority withdrawable, immediately, without a redeploy. A permission you cannot pull back is not a permission. It is a transfer of control.
The output is the point. When an incident happens, the difference between an afternoon and a week is whether the authorization record already exists or has to be assembled backward out of whatever logs happened to survive.
Over the next ninety days nearly every vendor in this category will announce a governance layer and some will describe theirs as the first. Authorship is settled by dates and records. It is not settled by announcements.
A governance layer announced after the failure it would have prevented is a marketing decision. One specified before it is an invention. The entire difference sits in the dates, and dates are the one artifact that cannot be back-filled.
Technical review, licensing, procurement, and partnership. Every conversation starts with the question the framework asks before it lets anything run. Who authorized this, and how is it proved.
stephen.zeitvogel@roguemgmtgroup.com