Make authority executable, and every effect reconstructable.
A deterministic execution-control layer for AI-enabled operations where permission cannot be inferred from model confidence, memory, consensus, intent, or a tool call.
Governance belongs in the execution path, not beside it.
CageOS is designed to make a verified authorization artifact a prerequisite of a bounded effect, then preserve a separately observed outcome. It does not ask an AI model to police itself: it binds a particular proposal, signed authority, exact permitted effect, expiry, replay defense, execution, and independently observed outcome into one action-specific record.
1BindAttach the subject, request, authority, target, payload digest, policy identity, and time bounds to one action.
2ConsumeRequire a durable one-use decision and reject malformed, stale, revoked, substituted, or replayed records.
3ObserveReopen the target through a separate path and record the outcome independently of the executor's success claim.
What runs today, and where the guarantee ends.
Both sides of the current state are part of the record: the measured fixture chain and the Phase I risks it does not yet close.
Current measured fixture
The bounded chain runs today
Peer-authenticated typed proposal intake
Signed authority and revocation verification
Durable single-use decision before execution
Time-limited capability for one scratch-file effect
Separate observation and committed reconciliation
Unresolved Phase I risk
The guarantee still ends at the host
A hostile administrator can act outside the CageOS path
Local state and local witness configuration can be rolled back together
No independently operated off-host witness is accepted yet
Post-reboot persistence remains unmeasured
Production emission remains locked
Keep the systems you already trust.
CageOS is intended to sit between AI proposals and consequential effects while integrating with existing agent frameworks, Git and CI/CD, IAM or PAM, ticketing, SIEM, and human approval workflows.
Action-specific
One approval cannot silently authorize a different target or payload.
Reconstructable
Follow the path from proposal and authority to observed outcome.
Fail-closed
Missing or invalid required evidence does not become permission.
Evidence-calibrated
Custody records prove process properties, not model or scientific truth.
A live fixture chain exists. Public proof remains narrower.
The development host has exercised one signed request through authorization, bounded execution, independent observation, and reconciliation, explicitly with ungoverned payload content. The downloadable Evidence Lab separately proves one fixture refusal-and-custody path. Neither establishes production, off-host, scientific, or general security validation.