Only Institute / Knowledge

Follow your curiosity.

AI sends your question and public excerpts to PrimeSwarm.

Try agent memory, governance, or a project name.

All Projects
productioncore

DGV — Deterministic & Governance Verified

Enforcement gate + certification spec for deterministic AI systems


A live Rust enforcement gate that sits between an AI agent and the action it is about to take — plus the certification spec that makes its claims testable. The gate evaluates every proposed action at proposal time (T₀), re-checks continuing authority at execution time (T₁), and returns a signed Ed25519 receipt either way. Verified identity (JWT/OIDC), signed and versioned policies, human approvals, fail-closed partition handling, signed revocation gossip between disconnected nodes, sealed agent-to-agent transport, token delegation with monotonic authority decay, accumulated session context, a real deferred-decision state for pending quorum confirmations, and 240+ automated checks — including a live integration that governs 18 write tools in the Minuta CRM.

Overview

DGV (Deterministic & Governance Verified) is two things that reinforce each other: a live enforcement gate (an Axum/Rust HTTP service that intercepts agent tool calls) and a certification specification with 89 test cards across 9 governance layers (L1–L9) expressed in ONLY Lang.

The core thesis: permission to act is not continuing authority to act. An agent can be authorized at proposal time T₀ and lose that authority before execution time T₁. The gate checks both — and produces signed evidence for each decision, so nobody has to take our word for it.

The Enforcement Gate

dgv-gate is a running service, not a design document. Every governed tool call follows the same path:

  1. T₀ — Govern. The proposal arrives with verified identity, tool, action, params, justification, and a context hash binding the agent's full state. The gate checks identity, revocation, policy, budget, approvals policy, circuit breakers — then returns a signed decision and a one-use token bound to the exact action and payload hash.
  2. T₁ — Execute. Before the tool runs, the gate re-verifies: token signature, expiry, action match, params hash — and checks revocation again. Authority revoked between T₀ and T₁ means the token is refused. We proved this live: revoke the caller, and the governed write never executes.
  3. Evidence. ALLOW and DENY both produce a signed receipt (run_id, decision hash, Ed25519 signature) that anyone can re-derive and verify.

What the Gate Enforces

CapabilityWhat it meansWhy it matters
Verified identityJWT (HS256/RS256), JWKS key rotation, OIDC discovery — the sub claim is the agent, not a self-declared stringA revoked employee's agent cannot just rename itself
T₀/T₁ splitAuthorization checked at proposal AND re-checked at execution"I was allowed earlier" is not authority now
Signed, versioned policiesEvery governance policy is Ed25519-signed; tampered policies are rejected on load; full version history + one-call rollbackThe rules themselves are auditable and reversible
Human approvalsPolicies can require N verified approvals before a token executesHigh-risk writes get a human signature, not a vibe
Fail-closed partition policyIf the gate cannot reach its revocation store, it denies — unverifiable authority is not authorityA network partition cannot launder a revoked agent
Signed revocation gossipRevocations propagate between disconnected nodes as signed one-hop messages; forged, stale, or replayed gossip is rejectedKilling the database link does not resurrect revoked actors
Divergence digestGET /revocations/digest — count + max timestamp + SHA-256 of canonical entriesTwo nodes either agree byte-for-byte or you can see it
Circuit breakersTools that keep failing stop being authorized until they recover or a human resets themA broken tool cannot keep writing garbage
Session contextRecent actions for the same agent are accumulated and passed into the governance script — not evaluated stateless per-callPolicy can see what this agent already did this session, not just the one proposal in front of it
Deferred decisionsWhen multi-peer quorum can't confirm cleanly in time, the gate returns DEFER with a resolvable pending token instead of guessing; the window still fails closed to DENY on expiry"We don't know yet" is a real, auditable state — not silently rounded to allow or deny
Signed A2A envelopesAgent-to-agent messages verified by admin-provisioned keys, with replay protection and revocation of both partiesAgents cannot forge each other's authority
Sealed A2A transportX25519 encryption keys registered alongside signing keys; payloads sealed (ChaCha20-Poly1305) and carried by a zero-knowledge relay; payload_hash binds the exact authorized ciphertextThe gate authorizes delivery without ever seeing plaintext or ciphertext
Token delegationA token's grantee can mint a strictly narrower child token — same tool/action, parameter subset, shorter expiry, bounded depth; ancestors' revocation kills descendantsAuthority can only decay through a chain; one revocation is a kill switch
Quorum revocationCluster peers polled at T₁; execution requires confirmation from majority quorum; isolated nodes fail closedAn isolated or partitioned gate cannot assume authority
Merkle anti-entropy16-bucket prefix Merkle tree; /revocations/reconcile automatically exchanges missing records between nodesPartition divergence is automatically resolved without manual intervention
Sealed A2A v2Ephemeral X25519 ratchet for forward secrecy + hybrid post-quantum key combiner; static-key compromise cannot decrypt past ciphertext; dgv-sealed-v1 still opensPast messages stay sealed even if a static key leaks (experimental construction — independent crypto review pending)
Formal modelsT₀/T₁ quorum invariant checked in TLA+ (exhaustive, N=3) and Alloy (bounded); the residual partition boundary is documented, not hiddenThe safety argument is inspected by machines, not just asserted
ObservabilityPrometheus metrics, structured JSON logs, deep health checks, graceful shutdownThe gate itself is operable infrastructure

Framework Integrations

  • LangChain — GovernedTool wrapper + govern_all_tools middleware for full agent executors
  • CrewAI — adapter verified end-to-end against the real crewai package (v1.15.21)
  • PyO3 bindings + dgv-sdk — Python wheel builds verified installable
  • Minuta CRM (live) — 18 write and credit-spend tools wrapped; caller identity comes from the verified session (or the bearer token's verified sub under JWT auth), evidence lands in the CRM audit stream, and a revoked caller is denied at T₁ in the running system
  • PrimeSwarm memory admission — continuity-ledger writes are additionally governed through a real DGV /govern call before they persist; an ALLOW attaches the signed receipt to the record as evidence (bound into the record's own integrity hash, not just appended alongside it), and DGV being configured but unreachable fails the write closed rather than falling back silently

Measured, Not Asserted

  • 250+ automated checks across the Python integration suites (govern/execute/revoke, JWT modes, JWKS rotation, approvals, policy signing, circuit breakers, sealed A2A transport, delegation, gossip, quorum, Merkle anti-entropy, partition behavior)
  • ~60 ms signed-gossip revocation propagation node-to-node (measured)
  • ~4 ms shared-store revocation visibility between two live instances (same-host SQLite — a lower bound, published as such)
  • 89/89 test cards pass in the differential suite with real native implementations

Regulatory Mapping

DGV test cards map to existing frameworks: EU AI Act, NIST AI RMF, TRACE, ISO 42001, 21 CFR Part 11, GDPR. The OWASP Agentic Top 10 mapping is published in the repository with per-item coverage status.

What We Do Not Claim

  • No multi-leader Byzantine fault tolerance (BFT). Quorum revocation is crash-fault-tolerant (majority read quorum, R + W > N). True BFT consensus against arbitrary malicious nodes remains future work.
  • No third-party audit. The verifier source is open and the audit package documents what is computed — an independent audit is still required.
  • Gossip is fire-and-forget. A permanently unreachable peer reconciles via shared storage, not retries.
  • Sealed-v2 crypto is not independently reviewed — dgv-sealed-v2 adds ephemeral-ratchet forward secrecy and a hybrid post-quantum key combiner and passes 10/10 functional checks, but the construction has not undergone a formal cryptographic design review; dgv-sealed-v1 remains static-static X25519.
  • Model-checked ≠ code-proven — the TLA+/Alloy quorum models are checked abstractions with small bounds (N=3); no code-level verification of the Rust binary exists.
  • Partitioned-away revocations are undiscoverable — confirmed by both models: a revocation held only by nodes outside the assembled clean quorum does not block execution; quorum-write revocation is the documented mitigation, not yet implemented.
  • Delegation is attenuation, not scope composition — a delegated token can only narrow its parent's tool/action/params; cross-tool grants and parametric bounds ("amount ≤ X") are future work.
  • Semantic justification analysis is external — the gate calls a configured verifier webhook and enforces its verdict; it performs no LLM analysis itself.
  • Circuit-breaker state is per-instance in memory; distributed breaker state is future work.
  • Session context and DEFER are new — accumulated action history is available to policy scripts, but the gate does not yet score semantic drift against original intent, and neither feature has been exercised under real production load.

Current Status

  • Gate: live, v0.4.0 + dgv-sealed-v1/v2 + dgv-delegate-v1 + dgv-quorum-v1 + dgv-merkle-v1; OpenAPI-documented (31 endpoints), Docker + compose deployment files, and deploy-check.sh — a posture validator that has passed against a real Postgres + RS256-JWT instance
  • Catalogue: 89 test cards, 9 governance layers, all with real native implementations
  • Trust boundary: identity, policy integrity, revocation, partition behavior and evidence are implemented, tested, and (for the T₀/T₁ quorum invariant) model-checked; Byzantine fault tolerance, independent crypto review of sealed-v2, and independent audit remain open
  • Assurance: passing our own tests is evidence, not certification

Key Highlights

  • Live Axum enforcement gate: T₀ govern + T₁ execute re-check, signed Ed25519 receipts on every decision
  • Verified identity — JWT HS256/RS256, JWKS rotation, OIDC discovery; the sub claim is the agent
  • Signed + versioned policies with rollback, approval workflow, full context hashing
  • Fail-closed partition policy — unreachable revocation store means deny, not assume
  • Signed revocation gossip between disconnected nodes (~60ms measured) + divergence digest
  • 250+ automated checks; live integration governs 18 Minuta CRM write tools end-to-end
  • Session-context accumulation and a real DEFER state — pending quorum confirmations get a resolvable token, not a guess
  • Sealed A2A transport — X25519 ECDH + AEAD, payload hash binds the authorized ciphertext, zero-knowledge relay
  • Token delegation with monotonic decay — revoking the orchestrator cascades to every delegated descendant
  • Quorum revocation at T₁ with automated 16-bucket Merkle anti-entropy reconciliation
  • LangChain + CrewAI adapters, PyO3 bindings, Prometheus metrics, structured logs

Links

Watch test cards execute in 3D

See all 89 DGV test cards run live in your browser — gating planes, HITL escalation, cryptographic receipts, and deterministic replay — in an interactive 3D visualizer.