Agent-Safe Pipeline: Reproducible Execution-Authority Reference Architecture and Decision Dossier Corpus
Abstract
A runnable reference architecture in which AI agents propose actions but cannot authorize their own execution. The release includes an independently reproducible synthetic Decision Dossier corpus with canonical bytes, SHA-256 digests, Ed25519 signatures, a deliberately published corpus key, execution-bound proof vectors, and negative tamper cases; the Verifying Provider Profile (agent-safe.verifying-provider/1, version 0.2), the procedure by which a system of record verifies the executor's signed request and the authority's claim attestation, refuses what the authority never claimed, and answers with its own signed effect receipt, with conformance vectors and five independent implementations that pass them; and the self-checking adversarial corpus, including the Compromised Principal Test, in which a valid identity proposes an unauthorized action. Transparent interception beside a workload redirects its outbound HTTP and TLS connections at the network layer into an AgentSafe process that reads each destination from the client's own bytes, reports what the workload reaches, and, for the destinations an operator names, terminates TLS under an authority the operator holds and runs the gateway's lifecycle over each request, with the redirect published as an init image and sidecar shapes for Kubernetes and Docker, with the shadow report on its own cadence, a provisional workspace minted from the command line, and the boundary test with Decionis deciding. Govern, the workflow gate, is one static binary for GitHub Actions, GitLab CI, Jenkins and any other runner that captures a CI step as an execution intent, obtains a Decionis decision on exactly that intent, runs the command only on a claimed single-use grant, holds an escalated step for a verified person, and finalizes the outcome into the signed Decision Dossier, with no local policy engine; shipped per platform with reproducible builds, a Homebrew formula, a verifying installer and a signed Go module tag. Govern also ships a Windows build, PowerShell and cmd as shells it runs a step's command through, and a CycloneDX software bill of materials read from the shipped executables' own build information. This release gives the boundary an identity of its own, stable across restarts and rescheduling, and carries it inside the intent hash, so a Decision Dossier establishes which enforcement boundary admitted an effect; it carries what a runtime reported about the software that proposed the action with the trust source attached and never raised, leaving container and OCI tooling the authority for provenance; it makes an MCP tool invocation an execution surface, where arguments that change after the authority is issued invalidate it; and it holds the whole of it to a cross-runtime conformance suite in which the same intent, policy and signals decide identically on a host, in a container, in a pod and through the hosted runtime.