Governance & trust

Autonomy withoutgovernance is chaos.

Every decision carries its evidence. Every action has a route. Every outcome is proven or it is not claimed. Auctorian is advisory and dry-run only — and says so in the product, on every surface. The refusal is the feature.

The autonomy ladder

Six rungs built.We stand on the fourth.

Autonomy is not a switch, and it is not a slider anyone should be able to drag. It is a ladder where each rung has to be earned by evidence the rung below it produced. Two of these are designed and deliberately not stood on — and it will stay that way until the measurements that would justify them exist.

01ObserveRead operating data across transactions, inventory and supply signals. Nothing is triggered by looking.Reached
02RecommendCompile a recommendation carrying its evidence, its alternatives and what it could not resolve.Reached
03ReviewRoute it to the person whose decision it is. The engine names who may sign; it never signs.Your signature
04BoundEnforce the policy below the model — margin floors, exposure caps, approval paths — so drift is impossible rather than discouraged.Auctorian operates here
05ExecuteAct inside an approved envelope, with idempotency and a reversal window. The envelope is built; no connector is certified, so nothing dispatches.Designed · gated
06LearnProve the decision against actuals once the measurement window closes. The mechanism exists; the loop cannot close on real outcomes until the rung below it opens.Designed · gated
The invariants

Six things itwill not do.

Written as refusals on purpose. A promise is a sentence; a refusal is something you can test, and every one of these is enforced in the runtime rather than requested of a model.

No dispatch

Advisory and dry-run only. It prepares action packets and previews; nothing reaches a live system, on any rung.

No fabricated evidence

No invented ROI, confidence, forecast or measured outcome. Every figure resolves to a signal, a model or a policy — or it is marked absent, out loud.

Guardrails prune before intelligence

Price floors, exposure caps, approval thresholds — the limits remove unsafe candidates before anything is scored, not after. Most of what could be suggested never survives this stage.

Modeled is never measured

A prediction is never rendered as a result. An outcome is claimed only once the window has closed on actuals.

The ledger is append-only

Every decision, approval and reversal is a hash-chained record. Past entries are never rewritten, and a missing link breaks the chain after it.

Authority stays human

The engine compiles the decision and names who is allowed to sign it. The signature is never the engine's.

Security posture

Built for the reviewyour security team runs.

Evidence lineage and freshness

Every load-bearing number carries its grain, its source and its as-of date, inspectable in place.

Role-scoped, fail-closed permissions

Who may see, decide and approve is scoped per tenant and per surface. The default answer is no.

Signed audit trail

Every recommendation, override and authorization is signed to the append-only ledger.

Your grammar stays yours

Decisions run over your evidence. Your operating vocabulary is not pooled and not trained on.

Reversible by design

Anything authorized carries an explicit reversal window. Nothing is one-way.

Ceilings enforced below the model

Risk limits and approval paths bound what any agent can prepare — in the runtime, not in a prompt.

Full posture and isolation boundaries available under NDA · Security review

Why it refuses

The refusalis the feature.

Anything can be made to act. The hard part is a system that declines — that stops at the guardrail, says which evidence it could not resolve, and hands you the decision with the reasoning attached. Authority is earned from measured results, and until those exist it stays exactly where it is.