When an agent does something wrong, who gets blamed, and can you prove what happened?
The Operator
You get blamed for a machine you cannot explain. The action already happened. The record is whatever the system chose to keep.
The Insurer
You cannot underwrite what you cannot reconstruct. Without a fixed record, every claim is a dispute about what the agent actually did.
The Auditor
A log that can be edited is not evidence. If an attacker can rewrite the history, the history proves nothing.
RogueOS converts every agent action into a signed, time-ordered, replayable fact.
Eight governance primitives
Three foundational primitives carry the guarantees. Five composed primitives build on them. The composed tier depends on the foundation beneath it.
Write-Ahead Log
Every action is recorded before it can happen. History cannot be back-dated.
Immutable Permission Lattice
Only enumerated actions can execute. Nothing outside the tree runs.
Zero-Non-Determinism Sandbox
The same inputs always produce the same run, so any run can be reproduced.
Builder's Permit Authorization Kernel
Every capability is granted by an explicit permit, checked before use.
Governance Engine
Policy is enforced at runtime, not suggested after the fact.
Evidence Ledger
Each decision becomes a signed, time-ordered, replayable fact.
Trust Fabric
Identity and authority are verified for every action, not assumed.
Persistent Runtime Identity
Execution is bound to a verifiable identity across the agent's lifetime.
Two guarantees that hold when the machine is under attack
Most frameworks govern what an agent may do on a healthy host. The harder problem is what happens when the host is compromised. RogueOS is built for that case.
The agent cannot be turned against its owner.
A governed agent has no ambient authority. It can only perform actions a permit granted, and no permit can exceed the lattice it derives from. An attacker who reaches the host still cannot make the agent act outside its permit.
The record cannot be silently erased.
The log is append-only and sealed. An attacker cannot rewrite history, only break the chain, and a broken chain is detected in seconds. The absence of evidence becomes evidence of tampering.
What determinism means here
The governance path is deterministic and replayable. Model inference is not, and RogueOS does not pretend otherwise. Model inference is captured as a recorded input and output pair. The prompt hash, model hash, parameters, and seed are written to the log before any side effect. Replay verifies the decision chain, not the model's regenerated text.
This scope is stated plainly because honest boundaries are what make the strong guarantees believable. RogueOS is a governance and evidence framework, not an endpoint detection product. It does not prevent host compromise. It guarantees that a compromise cannot silently rewrite the record of what the governed agent did.
Your claim file writes itself
RogueOS is designed to satisfy Federal Rules of Evidence 901 and 902 for self-authenticating digital records. The record is a sealed, append-only log, an open verifier, and a notarized verifier hash. Reconstruction cost after an incident drops to near zero, because the evidence package existed before the incident did. The first billable hour starts at analysis, not collection.
Built to map cleanly onto emerging agent-governance work
The framework is designed to map cleanly onto the agent-governance direction taking shape at NIST and in the broader standards community. RogueOS makes no certification claim it has not earned. It offers a concrete, testable substrate that governance and audit tooling can build on.
The deep material is gated
Trust math, policy DSL internals, and permit-derivation logic are available under NDA to qualified integrators, insurers, and standards bodies. Tell us what you are evaluating and we will follow up.
This opens your email client addressed to stephen.zeitvogel@roguemgmtgroup.com with your details filled in. No data is stored on this page.