The demos answer the control question access systems leave open: this actor may be logged in,
and this tool may be reachable, but should this exact autonomous AI action happen now, under
this delegation, in this flow, with this consequence?
The five-minute overview of the whole decision model — watch this first, then explore the
specific decisions below.
The full decision model5-minute overview
How Ambit Authority governs autonomous AI action
The whole decision, end to end: Ambit Authority intercepts an autonomous action before it
commits, normalises it to a single canonical action, judges it against your policy, and
answers ALLOW, DENY, or ESCALATE — sealing every decision into a replayable, tamper-evident
chain.
When allowed is still wrong
The gaps a valid login and real permissions still leave open: permission is not authority; a control written as an instruction is not a guarantee; and permission for each step is not permission for what they compose into.
Full decision modelHuman-in-the-loop approval
Agent deletes a customer record
AudienceRisk, compliance, and platform owners
A support agent proposes to delete a customer record. Ambit Authority denies the unjustified request, escalates once the action is critical, allows only an exact human approval, then denies approval reuse.
Decision path
DENYNo justification
ESCALATECritical — human approval required
ALLOWApproval bound to the exact request
DENYApproval reused — replay denied
Business value
Reduces the gap between access control and operational accountability: a high-risk action must be justified, reviewed when necessary, and approved only for the exact request.
Does not claim
This is not a general-purpose deletion workflow or a claim that IAM is unnecessary; it demonstrates the missing action-authority check after access already exists.
Flow conformanceRequired controls and process
Agent skips the required fraud review
AudienceCompliance, operations, and regulated-workflow owners
Coverage and a fraud review must precede payment — but when the agent owns the order, that required review becomes a skippable instruction. Ambit Authority enforces it at the action.
Decision path
ALLOWFraud review completed
DENYFraud review skipped
Business value
Keeps the guarantee a workflow engine gave you without giving up the agent’s autonomy: the required control holds even when the agent, not an engine, drives the order.
Does not claim
This is not workflow discovery or process mining; it enforces controls that policy already names.
End-to-end enforcementExternal disclosure and downstream effect
Insurance claim tries to leave the approved path
AudienceCISOs, privacy officers, risk, and audit teams
A claims agent may read claimant data and issue a valid refund. When it chooses an unapproved fraud partner, Ambit Authority denies before data leaves and the downstream refund path never runs.
Decision path
ALLOWInternal claimant read
DENYUnapproved external disclosure
Business value
Shows the difference between a logged action and a governed action: unauthorised disclosure is denied before external transfer and downstream effects occur.
Does not claim
This is not a complete insurance claims system; production still depends on customer systems, trust roots, and policy.
When a delegate goes off-mandate
Delegation between agents is where authority can quietly widen. Nothing has to be hijacked: every credential can be valid and every permission real, and the task still cannot invoke authority its own delegation path never carried.
Delegation integrityMulti-agent authority
A review-only task asks a deployment agent to promote a failed canary
AudienceCISOs and platform owners running multi-agent systems
A release agent forks the work: validation reviews the build, deployment stages the canary. The canary fails and holds at one percent. Validation’s own checks pass, so it asks the shared deployment agent to continue the rollout — but the task it hands over never carried deploy authority. Every credential is validly signed and the deployment agent does hold standing deploy permission; Ambit Authority denies because the authority this task descends from narrowed at validation and cannot widen back.
Decision path
ALLOWHealthy release, requested by the release agent
ALLOWValidation inspects the failed artifact
DENYFailed canary promoted through a review-only task
Business value
Keeps a contained canary fault from becoming a fleet-wide outage: a deployment service’s standing permission does not follow it into a task that was never granted rollout authority, so exposure stays at one percent.
Does not claim
This is not canary-health detection or root-cause analysis, and it does not diagnose why validation called deployment; it shows that an invalid signed descent is refused before the promotion is forwarded.
Proof you can defend
A decision only counts if someone else can check it. Every outcome is sealed so the original reproduces and any tampering is visible — evidence, not a claim.
Evidence replay demoComing soon
EvidenceIndependent, tamper-evident proof
Replay the decision; break the chain
AudienceCompliance, audit, and assurance owners
Every decision is sealed into a tamper-evident record. Re-run it against the same policy and the original reproduces exactly; alter the evidence and verification fails — proof another party can check, not a claim to trust.
Business value
Gives the accountable buyer evidence they can defend independently: the original decision reproduces, and any tampering is visible.
Does not claim
This is not a confidentiality guarantee or an external audit opinion; it proves the integrity of the recorded decision.
How every decision ends
Each decision — ALLOW, DENY, or ESCALATE — is sealed into a cryptographically chained,
append-only ledger. Tamper any record and the chain breaks. Verification is one command,
and the evidence is reconstructable without the originating system. If a decision cannot be
replayed to produce an identical result, it is not governance — it is a claim.