Security and infrastructure
Prompt instructions and post-hoc monitoring cannot contain agentic execution. Put a deterministic authorization boundary around actions that change infrastructure, data, access, or operational state.
Constable is an AI control kernel that evaluates authority before an agent's proposed action reaches a governed execution surface.
Agentic AI systems are beginning to act through tools, workflows, APIs, infrastructure, and external systems. The issue is no longer only what the model says. It is what the system is authorized to cause.
Prompt instructions shape behavior. Output filters classify content. Monitoring records what happened. IAM defines access. These layers matter, but none of them prove that a specific AI-proposed action had authority before execution.
If an AI agent can operate tools, delegate work, move data, alter infrastructure, trigger financial activity, or generate external commitments, governance must precede execution. Post-hoc logs are not enough.
Preamblecontrol · nounThe authority to say “no” and be obeyed.
Constable, working definition
Familiar AI-governance terms are defined by their failure mode. Then paired with the boundary they are usually asked to substitute for.
Constable names the role the system performs: the part designed to stop an unauthorized action before it becomes an effect.
Constable sits between AI reasoning and governed execution surfaces. The model can reason and propose actions. Constable evaluates those proposals against declared policy before execution proceeds. Model output is treated as a proposal, not as permission. It is the reference implementation of the open Zero Trust Governance specification, and implements concepts derived from ZTG. No ZTG certification or conformance-mark program exists, and none is claimed.
Reasoning has no direct path to effect. A proposal crosses a deterministic gate; only an authorized verdict can reach a governed surface.
Produces an action proposal with validated parameters.
Proposal, not permissionNo effect is dispatched.
Hand the decision to the authority named by policy. No effect yet.
The action advances in order. Refusal stops the path; escalation waits for designated authority. An uncertain result is recorded as indeterminate.
State one action and its parameters.
Establish surface and consequence context.
Test the request against pinned governance state.
Emit authorize, refuse, or escalate.
Make authorizing evidence durable before dispatch.
Send only an authorized action to its registered surface.
Record dispatch and disposition.
Indeterminate effect: if dispatch disposition cannot be confirmed, the uncertainty is recorded and may trigger proportional Stasis.
The class describes whether harm can be restored, not whether the action looks reversible. Every class still requires authorization.
The prior state can be restored without material residual harm.
Standard gateRemediation exists, but some harm or cost persists.
Elevated gateThe effect cannot be undone within the governed boundary.
Strictest gateA refund, retraction, or settlement does not by itself make prior harm Restorable.
Loss of a guarantee closes authority in proportion to the uncertainty: surface first, then subsystem, then system only when required.
Prompt instructions and post-hoc monitoring cannot contain agentic execution. Put a deterministic authorization boundary around actions that change infrastructure, data, access, or operational state.
Evaluate whether an AI-driven action was authorized before it occurred. Tie the execution record to policy state, consequence class, and explicit authorization.
Constable produces action-level authorization evidence that can support analysis of governed AI exposure. Its use in underwriting remains a research and design-partner direction, not a validated insurance standard.
The model can change continuously. The authority boundary cannot drift with it. Constable separates reasoning from permission so model output does not become an institutional mandate.
Each row compares the same property before and after a surface is integrated with Constable. Unintegrated surfaces are outside this claim.
Constable is not a claim that AI becomes risk-free. It does not make institutional policy wise by itself, and it does not govern surfaces where it is not integrated.
Its claim is narrower: inside governed surfaces, execution authority becomes explicit, replayable, and deniable before consequence.