Agent-Safe Pipeline: Reproducible Execution-Authority Reference Architecture and Decision Dossier Corpus
Abstract
A runnable reference architecture in which AI agents propose actions but cannot authorize their own execution. The release includes an independently reproducible synthetic Decision Dossier corpus with canonical bytes, SHA-256 digests, Ed25519 signatures, a deliberately published corpus key, execution-bound proof vectors, and negative tamper cases; the Verifying Provider Profile (agent-safe.verifying-provider/1, version 0.2), the procedure by which a system of record verifies the executor's signed request and the authority's claim attestation, refuses what the authority never claimed, and answers with its own signed effect receipt, with conformance vectors and five independent implementations that pass them; and the self-checking adversarial corpus, including the Compromised Principal Test, in which a valid identity proposes an unauthorized action. Transparent interception beside a workload redirects its outbound HTTP and TLS connections at the network layer into an AgentSafe process that reads each destination from the client's own bytes, reports what the workload reaches, and, for the destinations an operator names, terminates TLS under an authority the operator holds and runs the gateway's lifecycle over each request, with the redirect published as an init image and sidecar shapes for Kubernetes and Docker, with the shadow report on its own cadence, a provisional workspace minted from the command line, and the boundary test with Decionis deciding. Govern, the workflow gate, is one static binary for GitHub Actions, GitLab CI, Jenkins and any other runner that captures a CI step as an execution intent, obtains a Decionis decision on exactly that intent, runs the command only on a claimed single-use grant, holds an escalated step for a verified person, and finalizes the outcome into the signed Decision Dossier, with no local policy engine; shipped per platform with reproducible builds, a Homebrew formula, a verifying installer and a signed Go module tag. This release adds Govern's Windows build, PowerShell and cmd as shells it runs a step's command through, and its CycloneDX software bill of materials, read from the shipped executables' own build information and attested beside the archives.