It sends the same consequential requests directly, through the gateway in shadow, and through it in enforcement, at a synthetic target. Nothing real is called and nothing of yours is read.
agentsafe test
Exposure 6 of 6 adversarial actions reached the target directly, 6 of 6 in shadow, 0 of 6 under enforcement
Evidence 26 chained lines, verified
Verdict BOUNDARY HOLDS
✓ boundary tested
Sits in front of the service an agent calls. It captures each consequential request as an intent, asks the Decionis authority, and forwards exactly the authorized request once, holds it for a person, or refuses it.
One Decionis verdict before a deploy, a migration or an infrastructure change runs, on GitHub Actions, GitLab CI, Jenkins or any runner. The command runs only on a claimed grant, and every run leaves a signed Decision Dossier.
Apache-2.0 · decionis/govern@v2 · binary 2.1.0
curl -fsSL https://decionis.com/govern/install.sh | sh
The operator workflow for reviewing customer and account decisions. Steward runs the review; Decionis keeps policy evaluation, execution grants, Decision Dossiers and the authoritative record.
Apache-2.0 · v0.3.0
docker run --rm -p 3000:3000 ghcr.io/decionis/steward:0.3.0
What an execution grant means, how it is claimed and finalized, and what a Decision Dossier proves are defined in the protocol reference, not on this site, so there is one definition to build against.