Permission comes from outside.
An agent’s explanation of why it should act is evidence to consider. The resource owner decides the authority.
AUTHORITY INFRASTRUCTURE FOR AI
Start with your agent
INTELLIGENCE IS NOT AUTHORITY
A capable model still needs a boundary. Sekos keeps permission outside the model and checks it before a protected action can begin.
Externally issued permission. Inspectable decisions.
A proposal is a request for permission.
The decision and observed result can be inspected.
The model can reason, plan, and ask. A separately issued grant defines which operation may touch which resource, under which conditions. The enforcement point checks that grant before the protected consequence.
An agent’s explanation of why it should act is evidence to consider. The resource owner decides the authority.
A grant can bind the operation, target, arguments, state, expiry, and use. Changing the request requires a fresh check.
Inspect the decision and read back the effect. Keep confirmed results, refused requests, and unknown outcomes distinct.
02 / USE THE TECHNOLOGY
Connect Customer Orders, approve an agent’s limits, and submit a refund. The live service compiles the request, checks signed authority with Substrate, and enforces it through the Resource Deputy.
Northstar Online Store
Read · search · refund up to $50
3 refund tokens · 10 minutes
Fictional customers. A real isolated database, signed grants, admission decisions, and resource effects. No money moves. This Site connects to the service at demo.sekos.ai.
Open the full governed-actions workspaceEach browser gets its own resettable records.
The Deputy presents its identity and Customer Orders capabilities for your approval.
Read and search orders; refund up to $50, 3 times, for 10 minutes.
Signature checked here with the origin key returned by the service. Database readback is the demo owner’s view.
In one week, we test one agent workflow. You see what passed, what failed, and what we couldn’t test, with evidence your team can inspect and tests it can repeat.
For teams preparing to launch an agent, connect a sensitive resource, or expand what an agent may do.
Describe your agentBegin with a brief. Scope, access, and terms are agreed together.
$12,500fixed fee
One agent workflow · one week
Passed, failed, and untested cases with supporting evidence.
Check the same boundaries again after a change.
Synthetic data, expected and observed cases, and a copy your team retains.
Prioritized changes and criteria for retesting.
Explore the demonstrations and public implementation behind Sekos. Each has its own construction, assumptions, and limits.
Connect a resource, approve bounded access, and inspect a refund against invented customer data.
Explore governed actions 02 / MODEL COMPUTATIONGrant or revoke a digit recognizer and see which parts of the MNIST model execute.
Explore the CDP demo 03 / PUBLIC IMPLEMENTATIONInspect the open-source authority and enforcement primitives in Schemen Gate.
Read Schemen Gate05 / THE EVIDENCE BOUNDARY
Authority checks apply at declared enforcement points. Their value depends on the issuer, key custody, trusted host, and whether alternate routes to the resource remain open.
A hash can reveal changed content. A signature can identify a signer. Replay can check consistency with declared inputs. These checks do not establish that a source is truthful, a policy is wise, or the whole system is safe.
Read the published evidence and limitsSTART WITH THE ACTION THAT MATTERS
Tell us what it does, where it acts, and what worries you.
Start with your agent