Technical Diligence

OntoGuard Technical Diligence

Architecture, evidence boundaries, authorization semantics, maturity levels, and production-route requirements. Last updated September 20, 2026.

The homepage sells the category. This page is the technical record. Claims below are bounded to current implementation, controlled proof, public sanitized artifacts, the AgenTrust Verified TRACE integration, or explicit customer-integration requirements.

1. Architecture

OntoGuard sits between a proposed action and protected consequence. It is a semantic decision point, not a replacement for identity, policy engines, enforcement gateways, confidential computing, or audit ledgers.

Agent / Application
        │
        ▼
 Proposed Action
        │
        ▼
 ┌───────────────────┐
 │     ONTOGUARD     │
 │ Decision Authorize│
 └───────────────────┘
   │       │       │
 ALLOW   BLOCK  ESCALATE
   │               │
   ▼               ▼
Enforcement     Human
/ Execution     Authority
   │
   ▼
Evidence / TRACE / Audit

AgenTrust / TRACE placement: OntoGuard produces the semantic authorization decision. Independently evidenced execution can then be represented in TRACE. TRACE is not OntoGuard’s native audit format. AgenTrust does not perform the semantic decision.

Structured semantic context is used to interpret what the agent is attempting to change and how that movement relates to evidence, authority, policy, and institutional state. Ontology is mechanism, not category.

2. Governable state transitions

A governable event is a proposed movement from a source state toward a target state that would bind the enterprise if released. Representative classes include payments, record mutations, customer communications, tool invocations, workflow triggers, memory writes, and multi-agent handoffs.

The public site does not enumerate every internal transition type. If a movement can become a consequence, it is a candidate for Decision Authorization.

3. Decision Authorization contract

The Decision API is the sole ALLOW / BLOCK / ESCALATE authority. Semantic scores, trust signals, retrieval ranks, and curvature metrics are explanatory. They do not grant release.

  • ALLOW — the exact proposed transition may proceed under the frozen basis.
  • BLOCK — the transition may not proceed. Prior authorization does not survive a material mutation.
  • ESCALATE — explicit authorization state routing to qualified human authority.

A material change to amount, destination, text, tool arguments, or target state is a new proposed action.

4. Pre-Transition Standing

Standing asks whether the proposed movement has enough intent continuity, evidence, governing basis, and authority to be decided. Coherence of language is not standing. A high reliability score is not standing.

5. Semantic projection

Semantic interpretation determines what action is being attempted and how it relates to people, accounts, records, policies, and authority. Retrieval may inform standing. It does not authorize release. Missing evidence remains visible and may drive ESCALATE rather than fabricated certainty.

6. Governing basis

Standing determines whether the proposed action is sufficiently grounded to enter authorization. A prior standing result is not a reusable approval. Every protected movement receives a fresh Decision API decision.

7. Intent Horizon

Intent alignment checks whether a later proposed action is still the same movement the enterprise authorized. Distance or similarity scores do not themselves authorize or refuse release.

8. Authority

Retrievable is not authorized. Callable is not delegated. Source authority and capability authority are evaluated separately from evidence sufficiency. Positive authority is a prerequisite, not an independent ALLOW engine.

9. Evidence

Provenance, integrity, and custody remain separate fields. Missing or customer-asserted custody is preserved as such. The proof harness exports valid artifacts or an explicit failure / pending state. It does not emit silent blanks.

10. Release / consequence custody

Release control records whether the movement is authorized, withheld, refused, replaced, or routed. Consequence custody binds proposed movement → governing basis → Decision API result → release / no-bind state → receipt → manifest → whether the protected effect formed. A no-bind receipt records that no protected downstream effect formed in the evidenced environment.

Proposed movement
        │
 Frozen basis + Decision API
        │
 Release control (authorize / withhold)
        │
 Consequence custody
   effect formed  |  no-bind receipt
        │
 Receipt + manifest hashes

11. Human review

ESCALATE is not a queue token. Closure records reviewer, authority, evidence considered, disposition, approved or revised action, release state, and resulting consequence. Unresolved states remain explicit. Review-gated learning signals may be exported. Live model-weight mutation is not part of the authorization path.

12. Proof packaging

Portable Decision Authorization evidence can include a buyer-facing report, machine-readable decision receipt, integrity manifest, and controlled-batch summary. More detailed audit-pack schemas are provided through technical diligence.

Public filenames on this site are the sanitized variants. Batch / Controlled Corridor Mode can aggregate multiple cases while retaining per-case hashes and full-audit pointers. Aggregate rule: any BLOCK controls; else any ESCALATE controls; ALLOW requires all-clear cases.

13. Controlled full seam

The controlled full seam demonstrates L4 behavior on a bounded controlled route, including a reproducible executor harness used in the AgenTrust integration review. In that controlled proof, an authorized $250,000 action can proceed (commit_count=1, TRACE emitted) while a $260,000 mutation is refused (state remains PENDING, commit_count=0, no TRACE). This is controlled proof, not a customer bank transaction.

Controlled proof
        │
Customer-connected route
        │
Production completeness
  (inventory, fail-closed,
   bypass, replay, closure)

14. Production route evidence

Customer integration establishes protected endpoint connection, route inventory, production fail-closed behavior, bypass testing, production replay, real reviewer closure, and downstream outcome evidence. Universal production non-bypassability is not claimed from public artifacts alone.

15. Longitudinal governance

Longitudinal governance uses decision and outcome history for bounded review and diagnostics. History is not a second Decision API. Insufficient history is reported rather than invented.

Decision history
 Governing-basis epochs
 Outcome evidence
        │
 Review-gated learning candidate
        │
 No live weight mutation

16. Capability boundaries

Not claimed: universal production L5; automatic regulatory compliance; hardware-backed attestation unless supplied by the deployment; OPAQUE certification; hardware-backed AgenTrust appraisal; replacement of human legal, medical, or financial authority; autonomous protected action merely because a semantic score is high.

External ecosystem integration validation: the Decision Authorization → execution-evidence → TRACE path was independently exercised by an AgenTrust maintainer before acceptance into the integrations repository. Status: Verified tier.

Procurement and security review materials can be discussed under NDA. Do not send confidential customer data through the public site.

Open Proof Explorer Request diligence conversation