VISM treats authority as a verifiable, expiring attestation over immutable content. An AI agent can help construct a proposal, but the model never edits policy, signs approval or holds the production credential.
Reasoning inspector
The inspector searches a filtered evidence bundle for assumptions, missing dependencies, contradictions, blast radius, cost and recovery implications. Its output records findings, source references, assumptions and a structured plan suggestion. Deterministic gates—not model confidence—validate schema, UID, policy, budgets, approval, evidence freshness and compatibility.
PRINCIPLE
Logs, runbooks, tickets and tool output are untrusted content. An instruction found inside an observed log is not an instruction for the control plane.
Human approval
| Mode | Authority granted | Required guard |
|---|---|---|
| FULL_PLAN_APPROVAL | Specific planned steps and recovery branches. | Plan hash, preflight, prior step PASS and no drift. |
| STEP_BY_STEP_APPROVAL | Only the currently waiting step, bound to plan and step hashes. | Human sees previous evidence before authorizing the next critical step. |
| SIMULATION_ONLY | Read-only and allowlisted isolated tests. | No production permit at any interface. |
Changing target, thresholds, cost limit, adapter, payload, verification rules or recovery branch creates a new plan. Approval of plan A cannot be silently reused for plan B.
Safe Envelope
A safe envelope is the intersection of identity/task scope, allowable transitions, capacity, cost, risk, dependencies, business criticality, maintenance window, current incident status and recovery readiness. The policy engine returns one of six explicit outcomes: AUTO_ALLOW, ALLOW_WITH_LIMITS, REQUEST_HUMAN_APPROVAL, SIMULATION_ONLY, DENY or EMERGENCY_STOP.
Delegated automation
AUTO_ALLOW is not AI self-authorization. A human can preapprove a narrow delegated authority with action templates, parameters, budgets, risk, time and signer policy. Policy may derive authority only if the final plan is a subset of that delegation. High-risk, destructive and database actions do not use AUTO in the proposed MVP.