Decision Authorization for Agentic AI
Authorize AI actions before they become enterprise consequences.
OntoGuard evaluates the exact action an AI agent is attempting to take and determines whether it is authorized to proceed. It returns ALLOW, BLOCK, or ESCALATE and produces portable evidence showing what was authorized, withheld, or routed for human authority.
Adapter tests passed
Historical proof and live local harness independently reproduced by an AgenTrust maintainer prior to merge.$250K COMMIT 1 · $260K COMMIT 0
Authorized $250K path: PENDING → RELEASED, TRACE emitted. Mutated $260K action refused: state remained PENDING, commit_count=0, no TRACE.Controlled software-only executor. No hardware-attestation, production non-bypassability, or L5 claim. Patent record: U.S. Patent Application 19/444,521 — Track I prioritized examination granted May 2026.
The problem
AI governance changes when AI can act.
Once an agent can move money, update records, communicate decisions, invoke tools, or trigger workflows, evaluating model output is no longer enough. The enterprise must determine whether the exact proposed action has standing and authority to become a consequence.
01
Understand the movement
What is the agent actually attempting to change—payment, record, message, tool call, or workflow state?
02
Authorize the action
Does the action have the required intent continuity, evidence, governing basis, and authority?
03
Prove the consequence
What was allowed, blocked, or escalated—and did the protected effect actually occur?
Other systems may observe, score, detect, log, enforce, attest, orchestrate, or execute. OntoGuard determines whether the exact proposed transition has sufficient standing and authority to proceed.
Product demonstration
The same authorization does not survive a material change.
An authorized $250,000 release is not an open-ended permission. If the proposed amount changes, the prior decision no longer binds. Illustrative controlled proof.
ALLOW ✓
$250,000 → $260,000
Prior authorization: NO LONGER BINDS
BLOCK ⊘
A mutated payload is a new proposed action. OntoGuard evaluates that action; it does not reuse a stale ALLOW.
Where OntoGuard fits
The semantic decision point between proposal and consequence.
OntoGuard is designed to compose with identity, policy, enforcement, confidential computing, audit, orchestration, agent infrastructure, and evidence systems rather than replace them.
OntoGuard produces the semantic authorization decision. Independently evidenced execution can then be represented in TRACE. TRACE is not OntoGuard’s native audit format, and AgenTrust does not perform OntoGuard’s semantic decision.
Category claim
Decision Authorization is not another name for monitoring.
Observation, scoring, detection, logging, policy documents, orchestration, and execution are all useful. None of them answer the question OntoGuard is built to answer: may this exact proposed action become an enterprise consequence?
OntoGuard evaluates the proposed transition against intent continuity, governing basis, evidence, and authority. It returns ALLOW, BLOCK, or ESCALATE. It records whether release occurred and whether a protected effect formed. Portable packets—PDF, JSON, receipt, manifest—let a reviewer inspect that chain without rerunning the system.
Ontology remains in the mechanism. It helps the system interpret what the agent is attempting to change. It is not the homepage category. The product sold here is Decision Authorization infrastructure for agentic AI.
Deploy where the action happens
Headless Decision Authorization Runtime
OntoGuard can run as a self-contained authorization service inside a customer-controlled or partner execution environment. The runtime carries exact-action authorization, authenticated governance inputs, and durable decision evidence without requiring the OntoGuard web application.
OntoGuard Headless Decision Authorization Runtime 1.0.19 · OntoGuard Governance Pack v1.2.0 — different version namespaces.
Who it is for
Three paths into Decision Authorization.
Enterprises
Govern consequential AI actions before execution—financial workflows, claims, regulated communications, customer-impacting decisions, and protected record movement.
AI / Agent Vendors
Add Decision Authorization to the product you already sell, so enterprise buyers can inspect what the agent is permitted to do before it acts.
Infrastructure / Implementation Partners
Combine semantic authorization with enforcement, identity, audit, and deployment infrastructure. OntoGuard supplies the decision boundary; partners supply the execution route.
Proof
Don’t take our word for it. Inspect the decision evidence.
Public artifacts are sanitized. They show Decision Authorization, release state, and consequence custody without implying customer-production enforcement.
Research: Decision Authorization for Trustworthy AI
Interactive Proof Explorer
Inspect a governed decision in-browser, including ALLOW / BLOCK / ESCALATE and no-bind state.
AGENTRUST COMMUNITYAgenTrust Integration
Inspect the public TRACE adapter and maintainer-reviewed merge.
PUBLIC SANITIZEDFinancial Services Proof Case
A sanitized end-to-end example from proposed movement to withheld consequence.
Detailed proof pack
Sanitized deep-pack artifacts are available under technical diligence, not as anonymous downloads.
Production maturity boundary
What is demonstrated, what integration establishes, and what is not implied.
Demonstrated
- Decision API
- ALLOW / BLOCK / ESCALATE
- No-bind proof
- Controlled release path
- Receipt / manifest
- Controlled full seam
- TRACE community integration
Customer integration establishes
- Protected endpoint connection
- Route inventory
- Production fail-closed behavior
- Bypass testing
- Production replay
- Real reviewer closure
- Downstream outcome evidence
Not implied
- Universal production L5
- Automatic regulatory compliance
- Hardware attestation by default
- Production enforcement in unintegrated environments
- AgenTrust Verified status
- Replacement of human legal, medical, or financial authority
Human review
ESCALATE is not a soft failure.
It is an explicit authorization state that routes the action to qualified human authority. Closure is part of the governed event: reviewer, authority, evidence considered, disposition, approved or revised action, release state, and resulting consequence.
ALLOW ✓
The exact proposed transition may proceed under the frozen authorization basis. A later mutation is a new action.
BLOCK ⊘
The transition may not proceed. No authorization token is issued. Protected commit remains 0 in the evidenced environment.
ESCALATE ↗
Release is withheld pending qualified review. The case is not closed merely because it entered a queue.
How to start
Begin with representative actions. No proprietary upload required.
Start without integration. Use representative actions to identify where Decision Authorization would allow, block, or escalate movement. The Risk Scan is a commercial entry point, not the category definition.
A Controlled Decision Authorization Pilot then progresses from representative cases to a decision contract, a controlled route, execution evidence, and production-readiness findings. Elapsed calendar time does not itself prove production completeness.
Representative cases
10–25 prompts, outputs, logs, or workflow samples. No production deployment and no model retraining required to start.
Decision contract
ALLOW / BLOCK / ESCALATE against intent continuity, evidence, governing basis, and authority—not against fluency.
Controlled route
Then connect a protected execution path and collect release, replay, and outcome evidence. Remaining customer responsibilities stay explicit.
Product video
See Decision Authorization in action
See how OntoGuard evaluates an exact proposed action, returns ALLOW, BLOCK, or ESCALATE, and prevents a prior authorization from silently carrying over after material change.
Poster first. The file loads when you press play. Controlled demonstration — not a production bank transaction.
Show us one consequential AI workflow.
Start with representative agent actions and the evidence, policies, authority, and review path surrounding them. OntoGuard can first evaluate the decision boundary and then progress toward a controlled production corridor.