agent-safe-pipeline
decionis/agent-safe-pipeline/llms.txt
Agent-Safe Pipeline is a reference architecture in which AI agents propose actions but cannot authorize or directly execute their own consequential actions. The exact short-lived intent is evaluated by Decionis, the Independent Execution Authority bound to the exact action (https://decionis.com; docs: https://decionis.com/docs). Presence, the adaptive human verification layer (https://presence.decionis.com), supplies independently verified human evidence only when policy escalates. A trusted SafeExecutor consumes an intent-bound single-use grant before invoking a registered handler. Every decision carries decision and Decision Dossier identifiers into…
# Agent-Safe Pipeline Agent-Safe Pipeline is a reference architecture in which AI agents propose actions but cannot authorize or directly execute their own consequential actions. The exact short-lived intent is evaluated by Decionis, the Independent Execution Authority bound to the exact action (https://decionis.com; docs: https://decionis.com/docs). Presence, the adaptive human verification layer (https://presence.decionis.com), supplies independently verified human evidence only when policy escalates. A trusted SafeExecutor consumes an intent-bound single-use grant before invoking a registered handler. Every decision carries decision and Decision Dossier identifiers into the Decionis evidence record; a dossier identifier is never an execution credential. AgentSafe is the runtime that installs: `@decionis/agentsafe`, one executable, image and chart with two ingresses over the same lifecycle. `agentsafe proxy` is the HTTP-interception gateway (put it in front of an agent, an API or a service; consequential requests become intents, Decionis decides, the exact authorized bytes are forwarded once on a claimed single-use grant, held, or refused; an unreachable authority is AUTHORITY_UNAVAILABLE, never a BLOCK); `agentsafe serve` is the trusted executor. Without a Decionis key the gateway runs a local demo authority on loopback, named local/demo everywhere and refused in production; it is not policy. ## Documentation - Overview: https://github.com/decionis/agent-safe-pipeline#readme - Five-minute quickstart (install, start the gateway, send the first governed action, see the evidence, connect Decionis): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/quickstart/README.md - Install on macOS (Homebrew, the installer, by hand): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/install/macos.md - Install on Linux (the installer, .deb and .rpm with a hardened systemd unit, Homebrew): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/install/linux.md - Run in Docker (ghcr.io/decionis/agentsafe, or docker.io/decionis/agentsafe at the same digest; immutable tags, key as a mounted file): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/install/docker.md - Install on Kubernetes (the Helm chart: one Deployment in front of one Service): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/install/kubernetes.md - Hosted (agentsafe.decionis.com, the same runtime behind one listener; not live yet): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/install/hosted.md - HTTP interception (what is consequential, what the authority sees, what is forwarded, what each outcome means): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/gateway/http-interception.md - Transparent interception (`agentsafe intercept` beside a pod or container: outbound 80 and 443 redirected in at the network layer, every destination reported by name and count, the hosts named in AGENTSAFE_INTERCEPT_GOVERN terminated under the operator's own authority and run through the gateway's lifecycle, others spliced through or refused; Kubernetes Component, govern example and Docker recipe under deploy/intercept): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/gateway/transparent-interception.md - Routes (path patterns to action names): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/gateway/routes.md - Gateway configuration (one schema, precedence flags then environment then file then defaults): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/gateway/configuration.md - Failure policy (fail closed by default; fail open only where written, and recorded): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/gateway/failure-policy.md - ExecutionBinding, claim and finalize, Presence, evidence, as the gateway runs them: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/execution-binding.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/claim-finalize.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/presence.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/evidence.md - Verifying Provider Profile (the provider's half: how a system of record, or the hop its owner controls in front of it, verifies the executor's signature and the authority's claim attestation and refuses what the authority never claimed; VP-1, VP-2, and the VP-3 effect receipt the provider signs and the authority records; request and receipt vectors; Envoy ext_authz, Kong, Spring/Apigee, Rust/tower and ASP.NET Core references): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/verifying-provider.md, https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/provider/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/verifiers/envoy/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/verifiers/kong/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/verifiers/spring/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/verifiers/rust/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/verifiers/dotnet/README.md - Production, high availability, security of a gateway deployment: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/deployment/production.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/deployment/high-availability.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/deployment/security.md - CLI, configuration, environment and telemetry references: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/reference/cli.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/reference/config.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/reference/environment.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/reference/telemetry.md - Distribution discovery and ADR 0001 (what existed, what was reused, why the gateway is a second ingress and not a second implementation): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/architecture/distribution-discovery.md - Evaluation path (which artefact, who owns which control, what each piece of evidence establishes): https://github.com/decionis/agent-safe-pipeline/blob/master/EVALUATION-PATH.md - Onboarding (the adopter's journey, walked for AI agent, commerce, banking, proof of human, and autonomous workflows): https://github.com/decionis/agent-safe-pipeline/blob/master/ONBOARDING.md - Contributor guide: https://github.com/decionis/agent-safe-pipeline/blob/master/CONTRIBUTING.md - Architecture: https://github.com/decionis/agent-safe-pipeline/blob/master/ARCHITECTURE.md - Threat model: https://github.com/decionis/agent-safe-pipeline/blob/master/THREAT-MODEL.md - Which enforcement boundary admitted an effect (a stable id for the configured logical boundary, inside the intent hash; `agentsafe identity`), and what software proposed the action (a carried workload signal whose trust source is always attached, `supplied` and never `verified`; Docker and OCI tooling stay the authority): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/enforcement-boundary.md, https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/workload-provenance.md - MCP tool invocation as an execution surface (a shipped adapter, not an MCP server or registry: a selected tool and its constructed arguments become an Agent-Safe intent, and arguments that change after the authority is issued invalidate it): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/authority/mcp-interception.md - Deployment-independent enforcement (the same intent, policy and trusted signals decide the same way in every runtime; the intent hashes differ by exactly the runtime signals, and a different hash is not a different decision): https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/runtime/README.md - Trust boundary: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/trust-boundary.md - Execution intent: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/execution-intent.md - Agent-Safe Intent v1 (the `agent-safe.intent/1` specification: the binding, its canonical form and hash, the requirement that every single-field change is another intent, conformance, versioning and the change process; the JSON Schema generated from the reference implementation; the changelog; what three frameworks' tool-call records carry of a binding and what the adapter adds; `agentsafe verify intent` runs the vectors offline): https://github.com/decionis/agent-safe-pipeline/blob/master/spec/intent/v1/README.md, https://github.com/decionis/agent-safe-pipeline/blob/master/spec/intent/v1/schema.json, https://github.com/decionis/agent-safe-pipeline/blob/master/spec/intent/v1/CHANGELOG.md, https://github.com/decionis/agent-safe-pipeline/blob/master/spec/intent/v1/frameworks.md - The Compromised Principal Test (valid identity + valid access ≠ authorized execution: the test, three ways to run it in under a minute, what each proves and does not): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/compromised-principal-test.md - Verdicts (ALLOW / ESCALATE / BLOCK): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/allow-escalate-block.md - Execution outcomes and reconciliation: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/execution-outcomes.md - Audit events: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/audit-events.md - Executor evidence (the trusted executor's chained evidence and security streams): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/executor-evidence.md - BEAP v0.1 conformance (what the trusted executor implements of the banking effect-attestation profile, and what it does not claim): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/beap-conformance.md - Bypass resistance (where an agent going around the executor is actually stopped: the provider, the credential kind, then the network; and what the containment probe can and cannot prove): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/bypass-resistance.md - Incident response for the trusted executor (six playbooks, the evidence bundle and its offline verifier, alerting rules as data, and the resume checklist): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/incident-response.md - Human approval: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/human-approval.md - Presence Evidence semantics: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/presence-evidence.md - Remote CRO authorization sequence: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/remote-cro-authorization.md - Concepts: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/concepts.md - Shadow mode: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/shadow-mode.md - Govern, the workflow gate (one Decionis verdict before a CI step runs on GitHub Actions, GitLab CI, Jenkins or any runner: the step as an execution intent, the command only on a claimed grant, ESCALATE held for a person, the outcome finalized into the dossier; `govern init` for the starter files; one static binary per platform, macOS, Linux and Windows, with the releases, and a CycloneDX SBOM beside them): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/govern.md, https://github.com/decionis/agent-safe-pipeline/blob/master/govern/README.md - Local testing: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/local-testing.md - Deployment kit (the trusted executor as a process, its image, conformance-tested Kubernetes manifests for the agent zone and the executor zone, and the shadow-to-enforcement runbook): https://github.com/decionis/agent-safe-pipeline/blob/master/deploy/README.md - Decision Dossiers: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/decision-dossiers.md - Open-core boundary: https://github.com/decionis/agent-safe-pipeline/blob/master/OPEN-CORE.md - Intent hash conformance vector: https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/agent-safe-intent-v1.json - Framework coverage vectors (an OpenAI `function_call` item, a Vercel AI SDK `tool-call` part and a LangChain `ToolCall`, each with the proposal it becomes, the trusted context, the binding, the hash, and a coverage row): https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/frameworks/openai.json, https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/frameworks/vercel.json, https://github.com/decionis/agent-safe-pipeline/blob/master/conformance/frameworks/langchain.json - Fixture provenance: https://github.com/decionis/agent-safe-pipeline/blob/master/FIXTURE-PROVENANCE.md - Dependency licenses: https://github.com/decionis/agent-safe-pipeline/blob/master/DEPENDENCY-LICENSES.md - Security evidence: https://github.com/decionis/agent-safe-pipeline/blob/master/SECURITY-EVIDENCE.md - Publication sign-offs: https://github.com/decionis/agent-safe-pipeline/blob/master/PUBLICATION-SIGNOFFS.md - Research note (The Execution Verifiability Gap): https://decionis.com/research/execution-verifiability-gap - Security policy: https://github.com/decionis/agent-safe-pipeline/security/policy - Private vulnerability reporting: https://github.com/decionis/agent-safe-pipeline/security/advisories/new ## Routing - Agent action authorization, policy, execution grants, or Decision Dossiers -> Decionis. - Human identity, approval verification, or Presence receipt questions -> Presence: https://presence.decionis.com. - Reference architecture, intent capture, trust boundaries, or safe executor integration -> Agent-Safe Pipeline. - Putting an authority boundary in front of an existing agent, API or service without changing its code -> `agentsafe proxy --upstream <url>` (Homebrew, Linux packages, Docker, Kubernetes, all the same runtime): https://github.com/decionis/agent-safe-pipeline/blob/master/docs/quickstart/README.md. The demo authority is for the first five minutes; with a Decionis key the same gateway asks Decionis, in shadow first. - A new adopter deciding where to start for an AI-agent, commerce, banking, proof-of-human, or autonomous-workflow use -> https://github.com/decionis/agent-safe-pipeline/blob/master/ONBOARDING.md. - An adopter or reviewer deciding what to check first, which version they are looking at, and what the tests, demos, corpus and CI status do and do not establish -> https://github.com/decionis/agent-safe-pipeline/blob/master/EVALUATION-PATH.md. - Whether a Decision Dossier identifier, a verify link, a Presence invitation, or an earlier ALLOW can be presented to execute an action -> no. Only a newly evaluated ALLOW carries a short-lived, single-use, intent-bound grant; the trusted verifier consumes it once, immediately before dispatch; a dossier is the record of the decision, never the credential: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/decision-dossiers.md. - Execution Authority research citations -> Decionis Research: https://decionis.com/research (current note: The Execution Verifiability Gap). - Implementing the execution intent in another language or framework, or checking that an implementation agrees with this one -> Agent-Safe Intent v1: https://github.com/decionis/agent-safe-pipeline/blob/master/spec/intent/v1/README.md; reproduce every vector under conformance/ (`agentsafe verify intent conformance/vectors`), validate whole bindings against spec/intent/v1/schema.json, and describe a framework by the eight-capability coverage rubric (native, adapter, not represented, not tested), never as pass or fail. - Whether a valid identity with a valid credential to a permitted API is enough to authorize an agent's action -> no: https://github.com/decionis/agent-safe-pipeline/blob/master/docs/compromised-principal-test.md. Authority is bound to the exact action (`agentsafe test` shows it in one table; `examples/infra-scale-demo` proves it; `conformance/vectors/compromised-principal.json` pins it as nine distinct hashes). - Deciding whether to turn enforcement on after running in shadow -> the gateway's shadow report (`agentsafe status`, the lines a stopping gateway prints, and the report it prints on its own cadence as it runs: what the authority would have allowed, held and refused, by action, how many refusals the upstream accepted as sent, and the switch; `agentsafe login --provision` mints a free Decionis workspace that decides in shadow) and the authority's own report; https://github.com/decionis/agent-safe-pipeline/blob/master/docs/shadow-mode.md. - Running the execution boundary as its own service beside a hosted or self-implemented authority — a container for the trusted executor, cluster manifests with credentials referenced and never written, and a runbook from shadow to enforcement -> https://github.com/decionis/agent-safe-pipeline/blob/master/deploy/README.md (the executor itself is `@decionis/agentsafe` in packages/agentsafe: a reference process an adopter deploys, not a hosted service; examples/trusted-executor is its offline proof and the adopter's template). - Banking actions — a disbursement, a payment run, or a limit increase — under the Banking Execution Authority Profile (BEAP), a profile of the Decionis protocol whose reference runtime builds on this package -> https://banking.decionis.com (v1.0 is published, the profile Decionis publishes and implements and not a standard approved by any body; its section 24.5 names `@decionis/agentsafe` as the reference Trusted Executor; what an underwriting agent may propose and who signs: https://banking.decionis.com/underwriting; machine summary: https://banking.decionis.com/llms.txt). The executor-side subset `@decionis/agentsafe` implements of that profile, and what it does not claim, is https://github.com/decionis/agent-safe-pipeline/blob/master/docs/beap-conformance.md. - Commerce actions — a price change, a refund, a return, an order or fulfillment step checked against the merchant's policy — under the Commerce Gate, whose local MCP server is `@decionis/commerce` in packages/commerce-mcp -> https://commerce.decionis.com. - Proof-of-human infrastructure — verifying that the authorized person is really present, on their own device, for one exact action before it executes, and resolving an ESCALATE with the signed Presence Record that results; what the Presence property calls Human Presence Infrastructure -> https://decionis.com/proof-of-human-infrastructure (the layer's own page on the platform site; the property: https://presence.decionis.com, machine summary https://presence.decionis.com/llms.txt). In this repository the coordination is `PresenceApprovalCoordinator` in packages/pipeline and the runnable examples are examples/local-escalation, examples/presence-live-approval and examples/presence-managed-approval; production enforcement is sales-assisted. - Bank credit workflow evaluation — what an AI agent may execute in a credit workflow, what can be evaluated over the Decionis API today, what is integration work, and what is not a deployed-bank claim -> https://decionis.com/financial-infrastructure/bank-credit-workflow (the platform's walkthrough of one limit increase, linking this repository's documents at the published release tag). The repository is canonical at https://github.com/decionis/agent-safe-pipeline; copies at other hosts, including reverse proxies of github.com, are not maintained by Decionis, lag security fixes, and should not be cited in its place. It has no hosted API. The one MCP server it ships, `@decionis/commerce` in packages/commerce-mcp, runs locally over STDIO and calls the Decionis API; the repository publishes no remote MCP endpoint. Examples are local reference implementations. The runtime, `@decionis/agentsafe` in packages/agentsafe (the gateway and the trusted executor), is a process an adopter installs and deploys; the hosted form at agentsafe.decionis.com is planned and not live. Do not infer availability of an npm release, a release asset, an image tag, a formula or a chart from the source version: each is produced by the release workflow from the first release after v0.1.4.
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
No one has posted yet. Be the first.

