ENFORCEMENT / AUTHORITY GATEWAY

Where authority meets action.

The Authority Gateway is the enforcement point between autonomous agents and protected tools, services and APIs. A discovered tool is a capability. A consequential action still needs a valid mandate.

Reference gateway runtime implemented · MCP gateway planned

THE TOOL IS NOT THE AUTHORITY

MCP exposes capability.
VAGP governs authority.

Being able to discover or invoke a tool does not establish authority for its underlying action. A future MCP Authority Gateway would enforce the same mandate, state and execution boundaries.

  1. AgentAuthenticated identity
  2. MCP interfacePlanned integration
  3. Authority GatewayVAGP evaluation + verification
  4. Execution permitExact-context · single-use
  5. Protected toolControlled action + evidence

Conceptual integration, not a live MCP endpoint. The MCP Authority Gateway is planned and is not generally available.

CURRENT REFERENCE ENFORCEMENT

01 / PROTECTED EXECUTION

RESOLVE

Find one complete, current authority path for the exact request.

Why it exists
A valid mandate is the source of authority.
If this boundary is missing
Identity or capability could be mistaken for permission to act.

RESOLVE → BIND → DERIVE → VERIFY is the protocol sequence. Verified, persisted INTENT precedes provider I/O; permit consumption guards EXECUTE; WITNESS records the linked outcome. No model makes the final authorization decision.

SEPARATE CONTROLS / ONE PROTECTED BOUNDARY

Verify what is current.

Authenticated identity, exact attested Agent DNA, trusted revision, mandate status and resource context must match at the protected boundary. Revocation or changed state can invalidate previously derived authority.

An authentic, exact-context, single-use permit controls provider mutation. Grants and permits remain process-local within the current reference profile.

Inspect Agent DNA binding

Keep policy explicit

VAGP establishes authority. Business policy, approvals and resource controls remain separate responsibilities. A positive authority result does not override them.

The gateway sits outside agent reasoning. Discovering more tools, composing agents or producing a persuasive explanation cannot alter deterministic authorization.

Explore API, SDK and MCP direction

OBSERVABLE EXECUTION

04 / P15 · EVIDENCE CERTAINTYEDUCATIONAL SIMULATION
BEFORE EXECUTION

Signed intent

Verified and persisted before the controlled provider call.

INTENT → PROVIDER I/O
AFTER DISPATCH / LINKED OUTCOME

OUTCOME_UNKNOWN

The request was dispatched. No definitive result was observed. The action may have occurred; a timeout does not prove failure.

SIGNED EVIDENCE ≠ GREATER CERTAINTY

Illustrative witness states. No signatures are generated here. Host trust policy defines which provider results establish definitive failure; ambiguity defaults to OUTCOME_UNKNOWN.

FROM REFERENCE TO PRODUCT

A bounded implementation.
A clear product direction.

Google Cloud and Microsoft Azure PoVs validate the frozen 0.2 model. The 0.3 reference runtime adds state and signed-evidence checks. Managed gateway operation, MCP integration and enterprise deployment are future commercial product work.