Execution authority

The consequential-action layer behind your gateway.

Keep your gateway, orchestrator, and provider. BoundRunner binds the exact side effect to deterministic policy, independent approval, narrow authority, safe execution, and a signed result.

The bound execution record

Treat every side effect like a transaction.

Authorization does not end at allow or deny. The same immutable context follows the action through approval, credential issuance, execution, retry handling, and evidence settlement.

01Exact actionProvider-normalized operation, target, environment, and hash
02Exact authorityPolicy revision, reviewer eligibility, constraints, and one-time grant
03Safe executionReduced credential, idempotency ownership, and uncertain-outcome quarantine
04Portable receiptRedacted provider result in an Ed25519-signed evidence chain

The runtime path

Six boundaries. One immutable context.

01

Bind the actor

Resolve the authenticated human or workload, registered agent, deployment, artifact digest, and tenant before policy.

02

Normalize the action

Connector-owned parsing turns provider-specific calls into a stable ActionRequest with server-owned risk and side-effect class.

03

Decide deterministically

Versioned OPA policy returns allow, deny, approval-required, or constrained allow under a strict deadline.

04

Pause the exact action

Approvals cover an immutable action hash, expire automatically, enforce separation of duties, and cannot be replayed.

05

Broker narrow authority

The agent never receives standing provider credentials. BoundRunner issues reduced, short-lived scope for the approved request.

06

Seal the evidence

Each event is canonicalized, chained, signed, tenant-isolated, exportable, and independently verifiable.

Control plane

Humans define authority.

Security and platform teams register agents, publish policies, define approval roles, connect credential providers, inspect decisions, and verify evidence.

Data plane

Agents stay inside it.

The gateway and Envoy adapter intercept actions, enforce bounds, fail closed, and forward only normalized requests that survive the complete control chain.

Built for adoption

Start with one consequential workflow.

Protect a production deployment, repository merge, Terraform apply, internal API mutation, or MCP tool call first. Expand the same identity, policy, approval, credential, and evidence model as the agent surface grows.

  • Deploy in your environment
  • Use your identity and credential providers
  • Keep deterministic policy in source control
  • Export evidence for independent verification

Bring a workflow

We’ll map the control path with you.

Map one action