SECURITY

Keep authority, effect and evidence deliberately separate.

VISM is designed so that no AI output becomes a production credential, no approval silently expands beyond an exact plan, and no worker receipt is mistaken for proof of a healthy state.

TRUST BOUNDARIES

Reasoning can inform a decision. It cannot make the decision alone.

The product design separates the agent, inspector, policy engine, human approver, effect broker, verifier and audit service. Each receives the smallest authority required for its role.

Agent

May submit typed proposals and read scoped, redacted evidence. No production write credentials or approval authority.

Inspector

May analyze a filtered read bundle. No credentials, arbitrary tools or policy-edit authority.

Human approver

May attest to a sealed plan according to current role, environment and scope.

Effect broker

May send an exact typed provider payload after validating a one-use permit.

Verifier

May independently read health/state. It cannot deploy or roll back.

Audit service

May append and sign history. It cannot execute a production action.

HUMAN AUTHORITY

Approval is an attestation, not a button click.

A valid approval binds a human identity, current role, tenant/environment, plan hash, scope and expiry. Changing a target, payload, threshold, artifact or recovery branch requires a new plan and authority.

Read Authority Docs
FULL

Plan approval

The complete sealed plan is approved, then rechecked before each step.

STEP

Critical transition

The next step waits for evidence and a specific human signature.

AUTO

Delegated scope

Only a valid human-approved envelope can derive automatic plan authority.

RESTRICTED EXECUTION

A short-lived permit binds one effect to one step.

The execution permit contains the plan hash, step ID, payload hash, resource UIDs, adapter digest, fencing epoch and expiry. A mismatch is denied rather than adjusted silently.

EXECUTION PERMIT

plan_hash · step_id · payload_hash
resource_UIDs · adapter_digest
fencing_epoch · nonce · expires_at

One dispatch. Exact typed payload. Live revalidation at the effect sink.

SECURITY CONTROLS

Controls must hold at the path where an effect happens.

The security model calls for short-lived scoped credentials, complete mediation of integrated write paths, admission/conditional checks, pinned adapters and an independent audit witness.

Agent identity

Separate agent, human and workload identities; bind tenant and environment at every layer.

Signed plans

Approval attaches to a canonical plan hash and pinned artifacts, not a mutable prose preview.

Immutable history

Append-only signed events and external witness help detect rewriting, truncation or forks.

Emergency stop

Freeze new permit issuance, revoke epochs, observe in-flight effects and reconcile before recovery.

FAILURE-SAFE BEHAVIOR

Uncertainty stays visible.

Policy or audit unavailability prevents new mutation. A provider timeout after a write enters reconcile; it does not cause a blind retry. Verification `UNKNOWN` blocks the next stage.

BOUNDARY OF THE GUARANTEE

VISM can only protect integrated, mediated write paths. An agent that still has a direct administrator key, shell path or bypass route is outside that guarantee until the path is closed.

SECURITY IS A PRODUCT CONTRACT

Review the identities, audit chain and release gates behind the control boundary.