Watch Ambit Authority decide before action

The demos answer the control question access systems leave open: this actor may be logged in, and this tool may be reachable, but should this exact autonomous AI action happen now, under this delegation, in this flow, with this consequence?

Start here

The five-minute overview of the whole decision model — watch this first, then explore the specific decisions below.

When allowed is still wrong

The gaps a valid login and real permissions still leave open: permission is not authority; a control written as an instruction is not a guarantee; and permission for each step is not permission for what they compose into.

When a delegate goes off-mandate

Delegation between agents is where authority can quietly widen. Nothing has to be hijacked: every credential can be valid and every permission real, and the task still cannot invoke authority its own delegation path never carried.

Delegation integrity Multi-agent authority

A review-only task asks a deployment agent to promote a failed canary

Audience CISOs and platform owners running multi-agent systems

A release agent forks the work: validation reviews the build, deployment stages the canary. The canary fails and holds at one percent. Validation’s own checks pass, so it asks the shared deployment agent to continue the rollout — but the task it hands over never carried deploy authority. Every credential is validly signed and the deployment agent does hold standing deploy permission; Ambit Authority denies because the authority this task descends from narrowed at validation and cannot widen back.

Decision path

  1. ALLOW Healthy release, requested by the release agent
  2. ALLOW Validation inspects the failed artifact
  3. DENY Failed canary promoted through a review-only task
Business value
Keeps a contained canary fault from becoming a fleet-wide outage: a deployment service’s standing permission does not follow it into a task that was never granted rollout authority, so exposure stays at one percent.
Does not claim
This is not canary-health detection or root-cause analysis, and it does not diagnose why validation called deployment; it shows that an invalid signed descent is refused before the promotion is forwarded.

Proof you can defend

A decision only counts if someone else can check it. Every outcome is sealed so the original reproduces and any tampering is visible — evidence, not a claim.

Evidence replay demo Coming soon
Evidence Independent, tamper-evident proof

Replay the decision; break the chain

Audience Compliance, audit, and assurance owners

Every decision is sealed into a tamper-evident record. Re-run it against the same policy and the original reproduces exactly; alter the evidence and verification fails — proof another party can check, not a claim to trust.

Business value
Gives the accountable buyer evidence they can defend independently: the original decision reproduces, and any tampering is visible.
Does not claim
This is not a confidentiality guarantee or an external audit opinion; it proves the integrity of the recorded decision.

How every decision ends

Each decision — ALLOW, DENY, or ESCALATE — is sealed into a cryptographically chained, append-only ledger. Tamper any record and the chain breaks. Verification is one command, and the evidence is reconstructable without the originating system. If a decision cannot be replayed to produce an identical result, it is not governance — it is a claim.