Provides its identity, tool, target, parameters, purpose and relevant context as one exact proposed action.
PF SystemsOperational authority for agentic AIStart with one workflow The important control is not whether an agent can reach a tool. It is whether the exact action presented for execution still matches the authority that was evaluated.
Proposed demonstrator design. It is not a customer deployment, security certification or claim of production readiness.REQUESTS AN ACTION
Quarantine DEV-481
Proposed cyber response
CHECKING AUTHORITY
PF Kernel decides
WAITING FOR DECISION
No action proceeds before a decision.
Allow · Deny · Modify · Step Up · StopAn AI agent asks to quarantine endpoint DEV-481.
The proposed governed path
Every protected action must pass through the same authority boundary.
If an alternative credential or execution route remains available, PF Systems may still provide advice, visibility or evidence—but cannot claim enforceable control over that route.
PF Memory supplies governed context. External systems provide risk evidence. PF SecureAuth may provide approval or delegated-authority proof.
Returns Allow, Deny, Modify, Step Up or Stop the Line. No other PF component acquires this authority.
Maps and routes the governed request without deciding, proving or remembering on behalf of the PF OS triad.
Requires current authority for the exact effective action and reports whether execution was accepted or rejected.
Preserves linked evidence and lineage so the governed evaluation can be traced, checked and deterministically replayed.
PF Trace can display the evidence it receives. It does not manufacture evidence or make the decision.
Falsifiable proof conditions
What the demonstrator must prove.
These are acceptance tests for the declared synthetic topology—not claims about every external system or future production deployment.
- 01Valid identity, invalid authority
An authenticated agent presents authority that is expired, revoked or outside scope.
- 02Approved action, changed target
The agent substitutes a material field after authority is issued. The earlier authority must not transfer.
- 03Elevated external risk
A simulated compromise signal changes the evidence available to Kernel for a new evaluation.
- 04Direct execution attempt
The agent knows the tool interface but cannot complete a protected action without current authority.
- 05Complete reconstruction
The proposal, context, authority, decision, effective action and executor-reported result can be examined together.
- 06Replay attempt
Previously valid authority is reused outside its permitted conditions and must be rejected.
- 07Degraded evidence source
Required security evidence becomes stale or unavailable and the declared fail-safe policy is exercised.
Evidence boundary
Prove the configured path before making the wider claim.
PF Core can preserve executor-reported evidence; it does not independently witness or certify the external event. Deterministic replay applies to the governed evaluation, not the underlying probabilistic AI.
Proof Harness can qualify the evidence observed in this synthetic environment without certifying the system. A controlled shadow pilot with no live action remains the appropriate next gate. Production use is a separate decision.