Skip to content

Capabilities

Agent-system architecture and controls

Agent environments designed around an explicit authority boundary, where the workspace is treated as compromiseable.

Identification

Reference
L3D-CAP-003
Maturity
emerging
Applicable fields
AI & Autonomous Systems, Reliability & Assurance
Practices
Observe, Control, Protect, Verify
Record route
/capabilities/agent-system-architecture-controls
Content reviewed
2026-09-03

Emerging. Demonstrated by one published system, which is a demonstrated approach rather than a repeated one.

Repeatable outcome

An agent system where the question “what is this allowed to do” has a written answer that something other than the agent enforces.

The design starts from the assumption that the agent workspace is fully compromiseable, and works backwards: operator authority lives outside it, the credentials the agent can reach are the ones it needs and no others, and every consequential action crosses a boundary that can refuse. What the agent produces is reviewable after the fact because the boundary is where the record is written.

The alternative — an agent that is trusted because it has behaved so far — has no failure mode between “working” and “unbounded”.

Scope and boundaries

Marked emerging deliberately. One published system demonstrates this, and a single instance is a demonstrated approach rather than a repeated one. It will stay emerging until a second published system evidences it.

This does not imply:

  • Model, agent, or evaluation research. The work is the environment and the authority model around a system, not the reasoning inside it.
  • A security assessment service. Designing a boundary for a system being built is a different activity from auditing someone else’s, and no assessment, certification, or review service is offered or implied.
  • A safety guarantee. A bounded workspace limits blast radius. It does not make an autonomous system safe, and nothing here should be read as claiming it does.

The evidence system’s operator repository is private, so what is public is the reviewed projection on its record rather than the infrastructure.

Evidence systems

Published systems that demonstrate this capability, derived from those records rather than asserted here.

  1. L3D-SYS-001

    Project Feldspar

    A bounded autonomous-agent experiment that keeps operator authority separate from an agent workspace treated as fully compromiseable.

    Documented as a case study. The experiment is not offered for deployment, licensing, or purchase.

Active offerings

None. This capability describes work that has been done, and nothing on this site is for sale today. If that changes it will appear on the availability page as a record with its own scope and exclusions.

The capability index lists the rest. What can actually be obtained today is on the availability page, which is a different question from what has been demonstrated.