Only within valid delegated authority and after live preflight.
PRODUCT
Control the transition, not just the identity.
VISM is a control layer for AI-driven production state transitions. It sits between a proposal and the infrastructure effect, binding evidence, policy, authority and verification to the same transition record.
WHAT VISM PROTECTS
The decision to make a production change.
The protected unit is not a chat response or a generic permission. It is a typed proposal with a current-state context, explicit targets, defined preconditions, a signed plan and a verified outcome.
Schema, target UID, evidence freshness, dependencies, policy and authority are evaluated.
A short-lived permit binds one adapter action to one plan step and payload.
Independent evidence determines PASS, FAIL or UNKNOWN; recovery follows its own authority.
CONTROL PLANE ARCHITECTURE
A chain of bounded responsibilities.
Gateway, inspector, policy, planner, approval, execution, verification and audit are deliberately separated so a model output cannot become a production credential.
DECISION OUTCOMES
A firewall returns an explicit outcome.
Policy does not hand a broad credential to the agent. It returns a deterministic decision and constraints for a sealed plan.
Only a narrowed final plan may proceed to authorization.
Evidence is sufficient to review, but human authority is required.
Analysis may run; no production permit is issued.
A hard invariant, scope or forbidden action prevents execution.
Freeze new dispatch and reconcile any in-flight effect.
WHAT VISM DOES NOT REPLACE
It is a control layer, not a replacement stack.
VISM is designed to work alongside identity, cloud platforms, observability, incident command, backup and delivery systems. It does not promise to eliminate incidents or formal-verify an entire cloud.
Not IAM
Identity and access remain the credential foundation. VISM adds state- and plan-bound control for integrated changes.
Not monitoring
Observability supplies signals. VISM evaluates selected evidence and makes verification outcomes explicit.
Not generic automation
The MVP does not execute arbitrary shell, generic apply, schema changes or destructive database automation.
MVP BOUNDARY
Narrow scope preserves the safety core.
The design starts with one Kubernetes cluster, selected namespaces and stateless workloads with clear ownership. Initial action templates are replica scaling and pinned image changes.
MVP SHOULD REMAIN SIMULATION_ONLY
When restore evidence, write-path mediation, telemetry or ownership is insufficient. A smaller truthful scope is safer than a broad unverified claim.
ROADMAP DIRECTION
Expand only when evidence supports the next authority boundary.
The proposed sequence moves from a narrow pilot to repeatable workload templates, selected cloud adapters and enterprise deployment options. Each new control domain needs a separate threat review, conformance evidence and recovery drill.
EXPLORE THE MECHANICS