TillarTechnologies

Make authority executable, and every effect reconstructable.

A deterministic execution-control layer for AI-enabled operations where permission cannot be inferred from model confidence, memory, consensus, intent, or a tool call.

Operating boundary
Authority
Signed, explicit, and scoped
Use
Durable and single-use
Outcome
Independently observed
Current effect
One bounded scratch-file write

Governance belongs in the execution path, not beside it.

CageOS is designed to make a verified authorization artifact a prerequisite of a bounded effect, then preserve a separately observed outcome. It does not ask an AI model to police itself: it binds a particular proposal, signed authority, exact permitted effect, expiry, replay defense, execution, and independently observed outcome into one action-specific record.

  1. 1BindAttach the subject, request, authority, target, payload digest, policy identity, and time bounds to one action.
  2. 2ConsumeRequire a durable one-use decision and reject malformed, stale, revoked, substituted, or replayed records.
  3. 3ObserveReopen the target through a separate path and record the outcome independently of the executor's success claim.

What runs today, and where the guarantee ends.

Both sides of the current state are part of the record: the measured fixture chain and the Phase I risks it does not yet close.

Current measured fixture

The bounded chain runs today

  • Peer-authenticated typed proposal intake
  • Signed authority and revocation verification
  • Durable single-use decision before execution
  • Time-limited capability for one scratch-file effect
  • Separate observation and committed reconciliation

Unresolved Phase I risk

The guarantee still ends at the host

  • A hostile administrator can act outside the CageOS path
  • Local state and local witness configuration can be rolled back together
  • No independently operated off-host witness is accepted yet
  • Post-reboot persistence remains unmeasured
  • Production emission remains locked

Keep the systems you already trust.

CageOS is intended to sit between AI proposals and consequential effects while integrating with existing agent frameworks, Git and CI/CD, IAM or PAM, ticketing, SIEM, and human approval workflows.

Action-specific
One approval cannot silently authorize a different target or payload.
Reconstructable
Follow the path from proposal and authority to observed outcome.
Fail-closed
Missing or invalid required evidence does not become permission.
Evidence-calibrated
Custody records prove process properties, not model or scientific truth.

A live fixture chain exists. Public proof remains narrower.

The development host has exercised one signed request through authorization, bounded execution, independent observation, and reconciliation, explicitly with ungoverned payload content. The downloadable Evidence Lab separately proves one fixture refusal-and-custody path. Neither establishes production, off-host, scientific, or general security validation.