Governance

Governance built into every decision.

Not governance claims. Governance artifacts. Open Policy Agent enforcement, structured decision traces, runtime sandboxing, and semantic data protection, verifiable, auditable, and built into every decision.

Coverage and evidence

Connect the execution path. Make the boundary explicit.

Discovery identifies agents. Enforcement applies to actions that pass through Operon's runtime or a configured interception point.

Imported agents. Agents admitted into the Operon runtime use its policy checks and decision traces. Review the imported tools and bound policies before promotion to production.

Existing executors. The governance wrapper intercepts configured outbound model calls. Tool calls and other execution paths need their own governed routing; wrapping a model call does not establish control over every action the agent can take.

Your wider governance program. Operon's execution records can support control reviews and audit evidence alongside your existing GRC tools. Agree evidence mappings and transfer requirements during the architecture review; a packaged connector is not implied.

Review the wrapper and credential path →

Inspect the enforcement path

Don't take our word for it. Read the traces.

Three illustrative artifacts show the intended enforcement path: a policy, an approved action trace, and a denied action trace. Use them to frame an architecture review against your own workflow.

Constraint enforcement with OPA.

Policies are declared in OPA/Rego. The runtime evaluates each agent action against the bound policy before dispatch. The same policy runs at compile time (binding to artifacts) and at runtime (verifying current context). One source of truth.

# policy.rego: Clinical agent: PHI write controls
package operon.clinical.phi

default allow = false

# Allow PHI writes only when:
#   - Agent is on the approved list AND
#   - Action is escalated to a clinician on the care team AND
#   - The classification of the data matches the agent's clearance
allow {
  input.agent.id == data.approved_clinical_agents[_]
  input.action.kind == "phi_write"
  input.escalation.reviewer.role == "clinician"
  input.escalation.reviewer.member_of == input.patient.care_team
  input.data.classification <= input.agent.clearance
}

# Always escalate when the agent is uncertain
escalate {
  input.confidence < 0.85
}

What an EDT trace actually looks like.

The Evidence Data Trace is the immutable record of every governed action: the agent, the input, the policies fired, the model version, the human reviewer if any. Open-schema, queryable in SQL, exportable to OpenTelemetry.

// EDT record: single agent action
{
  "trace_id": "edt_01HXY8ZMQF3K...",
  "agent": { "id": "clinical-summarizer-v3", "sha": "4b2..." },
  "input": { "data_class": "PHI", "redactions": 12 },
  "policy_evals": [
    { "policy": "phi_write", "result": "escalate", "latency_ms": 4 },
    { "policy": "residency", "result": "allow", "latency_ms": 1 }
  ],
  "model": { "provider": "anthropic", "name": "claude-opus-4-6" },
  "human_review": { "reviewer": "dr_chen@hospital.org", "decision": "approve" },
  "signature": "sha256:e9c..."
}

What happens when an agent goes wrong.

An agent attempts to write outside its clearance. Policy denies. The action never reaches the model. The denial is logged. The reviewer is notified. The agent's authority ceiling is reduced for review. No surprise outputs reach production. No partial state in the system of record.

// Denied action: full incident trace
{
  "event": "action_denied",
  "trace_id": "edt_01J2...",
  "reason": "data_classification > agent_clearance",
  "agent": "finance-summarizer-v1",
  "data": { "class": "MNPI", "clearance": "INTERNAL" },
  "action": "never_dispatched",
  "escalation": { "workspace": "sec-incidents", "sev": "S2" },
  "agent_state": { "authority_ceiling": "reduced_pending_review" }
}
Fails-safe, not kill-switch

Stop the problem, not the platform.

A literal kill switch in a regulated workflow is an anti-feature: it leaves records mid-write and financial transactions with orphaned compensating actions. Regulated operations require predictable transactional boundaries, not abrupt termination.

Abort vs. Operon Scoped Pause
Operon's scoped pause. Halts new dispatch at configurable scope. Lets in-flight actions complete to their next transactional boundary. Places subsequent steps behind explicit human approval. Requires dual-control quorum to resume above a severity threshold. Logs every paused state to EDT for forensic reconstruction.
Risk and ethics guardrails

The pre-deployment checklist.

Before an agent reaches production, three questions have to be answered with evidence, not intent: is it safe to run, is it fair to the people it affects, and can you prove what it did. These are the gates Operon is built to enforce and record.

Pillar 01

Safety and control

  • Risk tier assigned and documented
  • Fails-safe scoped pause and rollback tested
  • Action permissions set to least privilege
  • Blast radius bounded and rehearsed
Pillar 02

Fairness and ethics

  • Bias and disparate-impact tested
  • Human rights and dignity reviewed
  • Disclosure to the people it affects
  • Contestability and appeal path defined
Pillar 03

Trust and assurance

  • Evaluation baseline and golden datasets
  • Data lineage and privacy verified
  • Full audit logging enabled to the EDT
  • Incident response plan in place

Operon replaces the raw kill switch with a fails-safe scoped pause, so halting a problem never leaves a record half-written or a transaction with orphaned compensating actions. Every item on this list produces an artifact in the Evidence Data Trace, not a line in a slide.

Governance operating model

Autonomy with accountability.

Agents can act on their own. Accountability never should. As autonomy rises, the question is not whether a human is in every loop, it is whether a named human owns every boundary the agent operates inside.

The agent executes the action. A named human owns every decision boundary it runs inside.
Influencing roles Who enables the agent
Provides the modelSupplies the reasoning capability
Runs the platformSets the runtime constraints
Integrates itConnects workflows and tools
Operating ownership Who runs it day to day
MonitorWatches behavior in production
ApproveGates the high-stakes actions
InterveneHandles drift and exceptions
Primary accountability Who owns the authority
Determines authority scopeSets how far the agent may act
Approves the use caseOwns why it runs at all
Defines permissionOwns what it may touch
Incident ownership Who owns it when it goes wrong
ReportOwns the impact assessment
SuspendHalts execution under authority
InvestigateRuns the root-cause from the trace

Operon binds each of these boundaries to policy, records who holds them in the audit trail, and routes every escalation to the human who owns it.

Cross-boundary federation

Sovereign intelligence sharing. Without merging trust boundaries.

Fleets in different legal entities, regions, or classification levels can exchange signed results through the Control Plane without exposing prompts, weights, or private memory. Federation flows through audit, not around it.

Fleet-to-fleet federation between sovereign boundaries
Compliance posture

One audit trail. Every evidence pack.

Because EDT is one open-schema record, evidence packs for SOX, HIPAA, GDPR, EU AI Act, and ISO 27001 generate from the same source, no hand-assembly across five systems.

HIPAA

PHI access, agent identity, reviewer attribution. Evidence packs map to 45 CFR Part 164.

SOX

Material control evidence with deterministic compile artifacts and signed runtime decisions.

GDPR Art. 22

Decision traces include the human-in-the-loop attribution required for automated-decision-making controls.

EU AI Act

Article-by-article alignment for high-risk AI systems; conformity-assessment-ready evidence.

Your existing ISMS

Private-cloud and air-gapped deployments inherit your existing ISMS controls. Certification status for Operon Cloud is available on request.

Show your auditor, regulator, or board the trace.

Schedule a 45-minute architecture review. We'll map Operon's governance artifacts to your current evidence model, and show you the gaps either way.