Control at the point of action

Give your agents
room to act.
Keep the authority.

A clear approval and execution boundary for consequential agent actions. Set the limits, authorize the request, and reconcile what the target reports happened.

Development prototype · Sandbox evaluation
Execution workspaceILLUSTRATIVE VIEW
PROCUREMENT / ACTION 0042

Replacement components

Logical actionact_0042 · bound request
✓Request within shared limitsChecked
✓Separate approverAuthorized
✓Worker dispatchPermit consumed
✓Target read-backMatching evidence
RECONCILED OUTCOMEPrior effect confirmed
receipt → act_0042
Recovery checks the target before another write.
01Shared limits across delegated agents02Approval bound to the exact request03Uncertainty held for reconciliation
The platform / 01

From agent intent
to a controlled action.

Keep the important decisions visible across approval, dispatch and recovery. Authority connects the request to its authority and the evidence returned by the target.

Delegate without multiplying limits.

Give agents scoped authority under one shared budget. Concurrent reservations are checked against the complete delegation chain.

Approve the action that will run.

Bind requester identity and purchase details to the action. A different authenticated person approves the exact request.

Recover with evidence.

A missing response leaves an unknown outcome. The worker reads the target back; contradictory evidence remains blocked for review.

How it works / 02

A boundary that survives
the next retry.

Separate the identity of the action from a runtime attempt. Restoring a checkpoint gives recovery context; a new effect still needs current authorization.

One logical actionRequest → evidence
01

Request

Capture a stable action identity, requester and canonical purchase details.

02

Authorize

Check shared limits and obtain a separate approval for the request.

03

Execute

Queue the job, check authority, and consume a one-use dispatch permit.

04

Reconcile

Match target evidence to the action before settling its budget hold.

Unknown stays unknown.A receipt that is not visible does not prove the action failed. Recovery remains non-authorizing until the outcome is established.
A shared-budget example / 03

Three agents.
One budget.
No hidden commitments.

Two sourcing agents request ₹3 lakh each against a shared ₹5 lakh limit. Concurrent reservation admits one request. If its target response is lost, its ₹3 lakh hold remains visible during reconciliation.

Evaluation access
Illustrative procurement state
ROOT LIMIT₹5,00,000
REMAINING AVAILABLE₹2,00,000
First sourcing request₹3,00,000 HELD
Competing reservationLIMIT EXCEEDED
Missing target responseUNKNOWN
Next recovery actionREAD-BACK
Before you explore / 04

Clear about
the boundary.

What can I try today?

The console contains guided demonstrations, shared-budget execution, declaration audit, receipts and isolated tests. External writes require a configured sandbox connector. SSO and workload identity support require identity-provider setup.

What happens when a write times out?

The action keeps an unknown outcome and its budget hold. Recovery reads the target for a matching receipt. Missing confirmation never becomes permission to dispatch again; contradictory evidence remains blocked.

Is this ready for production?

Authority is a development prototype with scoped recovery and authentication tests. Organization SSO enrollment, live connector verification and operational deployment validation are still required. It does not claim universal exactly-once execution or production certification.

Does the demo create purchases or send payments?

No purchase orders or payments are sent. A configured ServiceNow demo can create labeled change-request records in a sandbox. Review the console's connector state before running an external-write scenario.

Start with one consequential action

Make the next step inspectable.

Explore the sandbox, follow an action through its lifecycle, and inspect the evidence behind its outcome.

Evaluation access