The model below is conceptual and uses fictional data. It does not represent a live customer deployment.
Control
Decide what the AI is allowed to cause.
Give AI a mandate. Not a blank cheque.
A mandate sets the ceiling, the scope and the expiry before the agent acts. The intended Control runtime checks every action routed through the governed workflow against it in the moment rather than reviewing it afterwards. In the model, an action above the boundary is escalated or refused, and the architecture is designed to pair the decision with evidence.
Proposed €250,000 · Nova Industries
Decision required€50,000 over available
Worked example. No customer data.
What a mandate is
A ceiling, a scope and an expiry. Set by a person, before the agent speaks.
A mandate is not a setting and not an instruction to the model. It is a bounded authority with three terms: how much the agent may commit in total, which actions it may take at all, and the moment the authority ends.
The ceiling is an aggregate, not a limit per call: everything the agents under this mandate hold or commit counts against the same number. The scope is a named list: an action that is not on it is not a smaller version of an allowed action, it is outside the mandate. The expiry is a moment, not a warning: after it the authority is gone rather than reduced.
All three are set by a named person before the first call. Changing any of them is itself an action, and it leaves a record of who changed what.
Commercial mandate
M-204 · v3- Ceiling
- €500,000
- Aggregate across every agent under this mandate.
- Scope
- EMEA renewals
- Anything not named is outside the mandate.
- Expiry
- 31 Dec 2026
- After this moment the authority is gone, not reduced.
Issued by a named person for Acme GmbH, valid 1 Jun 2026 – 31 Dec 2026, held by Renewal Agent 7 · AGT-7F31. Worked example. Acme GmbH and Nova Industries are fictional; no customer data appears here.
The check
Every request that reaches the boundary is designed to meet the mandate in the moment. Three outcomes, no fourth.
Control is being designed to sit in front of the governed action, not behind it. Before the agent says the sentence that would commit you, the request is measured against the ceiling that is left, the named scope and the expiry.
There are three outcomes and there is no fourth. Allow: the action goes ahead and the amount is held against the ceiling. Escalate: the action stops and waits for a person. Refuse: the action does not happen, and the reason is kept with the request that asked for it.
A refusal is the mandate doing the job it was set up for. It is measured against the same three terms as an approval, and in the design it leaves the same kind of record.
- Request
- Confirm a renewal at list price
- Amount
- €1,240
- Measured against
- Ceiling, scope and expiry
- Outcome
- Request
- Commit the Nova Industries renewal
- Amount
- €250,000
- Measured against
- Above available authority by €50,000
- Outcome
- Escalate
- Request
- Change the payment terms to 90 days
- Amount
- —
- Measured against
- Not a named action
- Outcome
- Refuse
- Request
- Confirm a renewal at list price
- Amount
- €2,780
- Measured against
- After the expiry moment
- Outcome
- Refuse
The action goes ahead.
The request fits inside the remaining ceiling, the named scope and the expiry — all three set by your organisation, not by us.
The request, the terms it was measured against, the amount held, and the link to the receipt before it.
The action stops and waits.
The request is inside the scope but above what is left, or it needs terms the agent was never given.
The request, the term it exceeded, who it went to, and how long it waited before a person answered.
The action does not happen.
The request falls outside the named scope, or the mandate has expired. Nothing is committed and the caller is told.
The request, the term that ruled it out, and the sentence the agent said instead.
Escalation
The action stops, a person decides, and both branches leave a receipt.
In the model, escalation is not a notification that arrives after the fact. The action is held: the agent does not say the sentence, the commitment is not made, and the request sits in a queue with the term it exceeded written next to it.
A person then answers. If they approve, the action goes ahead under a one-off authority for that request and the amount moves from requested to held. If they decline, the action does not happen and the agent says so in words that were approved beforehand.
Both branches end in the same artefact. An approval and a refusal are recorded alike, because the question a year from now is not only what was allowed but what was asked for and turned down.
- Completed: Request
The agent asks before it acts.
- Completed: Check
Ceiling, scope and expiry.
- Needs a person: Clearance
Above the ceiling. Held for a person.
- Not started: Decision
A person approves or declines.
- Not started: Effect
What the agent may then cause.
- Not started: Receipt
One on either branch.
- The action goes ahead under a one-off authority that covers this request and nothing else.
- €200,000 comes out of the mandate and the remaining €50,000 out of that one-off authority; available authority goes to zero.
- The call continues in the same session; the caller hears the wait and nothing else.
Who approved, at what time, against which mandate, and the link to the receipt before it.
- The action does not happen and nothing is held against the ceiling.
- The agent says the sentence that was approved for a refusal, not one it wrote itself.
- The request stays visible as something that was asked for and turned down.
Who declined, at what time, the term the request exceeded, and the link to the receipt before it.
Three things anyone can recompute today
Anyone holding a receipt can recompute three things today: the input hash, the output hash and the link to the receipt before it. A fourth, that the receipt sits in the Merkle root, follows once we publish the roots. No key from us, no account, no login: the three recompute from the receipt itself. Publication of the root, and the open endpoint that serves it, is in development.
The authentication code on the receipt works the other way round: an HMAC under a symmetric key we issue to your tenant. It is not a digital signature: whoever can check it can also produce it. So the check from outside is carried by the three above, and those three need nothing from us at all.
At the same time
No two requests can jointly commit more than the mandate allows.
A ceiling that each request checks against its own copy is not a ceiling. Two agents that both see €200,000 left will each commit €200,000. Together that is €400,000 against the €200,000 that was actually there.
So the check is designed to run against one number, held once. A request that is granted moves its amount out of what is available before the agent speaks, and a request that arrives in the same second measures itself against what is left after that move — not against what was there when it started.
That is why the second request below escalates. On its own there is nothing unusual about it: it is inside the scope, inside the expiry, and smaller than the ceiling. It is only too large for what is left.
How the ceiling is divided right now
- Reserved€300,00060%
- Available€200,00040%
- Time
- 14:02:11.118
- Agent
- Renewal Agent 7 · AGT-7F31
- Request
- Reserve €300,000
- Outcome
- Time
- 14:02:11.402
- Agent
- Renewal Agent 7 · AGT-7F31
- Request
- Commit €250,000
- Outcome
- Escalate
€300,000 reserved against a ceiling of €500,000 leaves €200,000. The second request asks for €250,000 and is €50,000 too large for what is left, so it goes to a person. That is what escalation is for.
Five readers, one product
One product. Five questions.
The organisation defines the mandate; Audact enforces it. We do not advise how much authority an agent should get: you set the principal, the ceilings, the scope, the approvers and the risk appetite.
CFO and finance
How much authority may a machine use, and when must a person decide?A ceiling, a scope and an expiry. Set by a person, before the agent speaks.
There are three outcomes and there is no fourth. Allow: the action goes ahead and the amount is held against the ceiling. Escalate: the action stops and waits for a person. Refuse: the action does not happen, and the reason is kept with the request that asked for it.
No two requests can jointly commit more than the mandate allows.
Where to check itWhat a mandate isAt the same time
General Counsel
What was the machine authorised to do, and which record supports that decision?The input hash, the output hash, the link to the receipt before it. Inclusion in the Merkle root is the fourth check, and it follows once we publish the roots; that publication and the open endpoint for it are in development.
A receipt is a faithful record of what the system received, decided and sent. That is what it establishes, not whether the world matched it.
If a caller gave a wrong name, the receipt records the wrong name faithfully. Proof of process is not proof of fact, and no cryptography closes that gap.
What this status establishes
- AuthorityDid the AI stay inside the configured authority and rules?Established by Audact.
- QualityWas the answer correct, understandable and usable?Not assessed by AudactEstablished by the customer, not by Audact.
- OutcomeDid the promised appointment, payment or call-back actually take place?No closing source connectedEstablished by a source competent to state it: the payment rail, the scheduling system, the counterparty.
Why this status
- Claim
- Allowed · Not assessed by Audact · No closing source connected
- Scope
- One governed turn or action. Not the call as a whole, not the deployment, and not the customer relationship.
- Ground
- In an internal test a turn passed all seven configured checks, scored 100% and was recorded as allowed, while the answer it gave was not usable. The authority verdict and the quality of the answer are separate measurements.
- What it does not establish
- That the answer was correct, that the task succeeded, or that anything is compliant beyond the rules configured for this workflow.
- Last checked
- 27 August 2026
Where to check itSee a receipt
CISO
What can this identity still cause after access has been revoked?At 09:14 an agent promises an engineer on site before 18:00. At 11:30 every agent is switched off. The promise is the company's, so it does not switch off with them.
Switching the model off removes the thing that makes promises. It does not remove the promises already made. That is the difference between an agent's task and your company's obligation, and it is why the obligation is held somewhere the model cannot reach.
An agent session is over in seconds. What it committed to stays open until something proves it was met, and the something is not the agent.
Where to check itSeven screens, one question each
Head of AI
How can more actions run on their own, without unbounded authority?A mandate is not a setting and not an instruction to the model. It is a bounded authority with three terms: how much the agent may commit in total, which actions it may take at all, and the moment the authority ends.
Enforced when it acts, not reviewed afterwards.
The action stops, a person decides, and both branches leave a receipt.
Where to check itWhat a mandate isEscalation
Agent builder
How do I add a consequence boundary without rebuilding enterprise controls for every client?The gate is a call your system makes, at a point in your own code that you choose. If your system does not call it, nothing is evaluated, and nothing is recorded either. Coverage is a property of where you place the call, not something the network grants you.
It records what was decided and what followed from it. Where money moves, it moves in your own systems; the receipt says what was permitted and what was recorded, and it stays out of the accounting.
A sub-account per end-client, isolated, so each client's agents, policies and receipts stay apart.
Where to check itSee the architectureSee the offer
Next
Control what AI can cause. Prove what follows.
Authority before action. Proof through finality.
Control is being designed to decide what may happen. Proof is the other half: the artefact each of those decisions leaves behind, and the part of it a third party can recompute without a key from us.
Voice is the application built on this model, and the one that carries a price today.
What a receipt carries
The first three need no key and no account; the fourth follows once we publish the roots. The fifth is a keyed code under a symmetric key we issue to your tenant.
