Who is it?
Necessary for attribution. Insufficient for authority.
ActionGate · Flagship control plane
ActionGate puts a deterministic machine-authority boundary between agent intent and consequential execution. It evaluates the exact requested action against delegated authority, policy, revocation, separation of duties, and required Consequence Capital before a narrow Action Permit can exist. See where delegated authority comes from
Principal: deploy-agent-07 · target: production billing service · duration requested: 45m
Permit may authorize the deployment role for 15 minutes. Requested 45-minute elevation is outside delegated authority.
Synthetic product illustration. No customer environment, production action, external proof, or realized customer result is represented.
Product definition
ActionGate is a deterministic authorization control plane for consequential AI-agent and machine actions. It does not ask whether an agent sounds confident, whether a model believes an action is safe, or whether a credential can technically reach the target. It asks whether this exact action is inside explicitly delegated authority right now, under current policy and revocation state, with every required boundary satisfied.
The control gap
01 / WHY ACTIONGATE
Identity establishes who or what is acting. Credentials establish technical reach. Guardrails influence model behavior. Workflow tools coordinate steps. Audit records what was observed. ActionGate owns the narrower question that becomes critical once software can create real-world consequence: may this machine exercise this exact power now?
Necessary for attribution. Insufficient for authority.
Capability is not permission to use that capability.
Probabilistic behavior controls do not issue institutional power.
Deterministic authorization for the exact requested consequence.
Decision anatomy
02 / EXACT REQUEST
The agent can reason broadly. The permit cannot. ActionGate collapses a semantic request into a bounded authorization decision tied to an exact subject, action, target, scope, time window, consequence boundary, and evidence lineage.
Normalize what the machine intends to cause, not merely which API endpoint it called.
Resolve the principal, delegation source, scope, expiry, recursive delegation, and current revocation state.
Evaluate exact constraints, separation of duties, approvals, limits, target boundaries, and required consequence capacity.
Permit, narrow, deny, or require human authority. The model does not vote on the result.
If allowed, issue a narrow, short-lived artifact bound to the authorized action rather than a broad ambient capability.
Bind request, authority, decision, permit, execution evidence, and later consequence proof into attributable lineage.
Four outcomes
03 / DECISION
The exact action is allowed under current delegation, policy, revocation, and required consequence conditions.
ActionGate can reduce duration, amount, target, scope, rail, resource, or other dimensions to the authorized boundary.
Requests requiring new power can be routed to a human or external authority source rather than inferred from urgency.
Expired, revoked, prohibited, unreserved, structurally invalid, or otherwise unauthorized actions fail closed.
Where the boundary matters
04 / CONSEQUENCE
ActionGate is designed for workflows where the cost of false authority is materially different from the cost of a bad answer. The same authorization primitive can govern very different consequences without pretending those domains are identical.
Amount, beneficiary, payment rail, timing, approvals, reserve conditions, and settlement-bound execution.
Role elevation, production changes, destructive operations, secret access, recovery, and bounded maintenance windows.
Administrative changes, record mutation, approvals, sensitive exports, account controls, and business commitments.
Authority that must remain attributable when machines act across organizational, contractual, or execution boundaries.
Designed to sit between, not replace
ActionGate is designed as an independent control plane. Identity systems can continue authenticating principals. Agent frameworks can continue planning. Policy sources can continue expressing institutional rules. Credential brokers and execution systems can continue doing their specialized work. ActionGate binds those facts to an exact authorization decision without pretending one neighboring system should become the whole constitution.
Action Permit lifecycle
05 / BOUNDED POWER
Operating model
06 / IN PRACTICE
Choose a workflow the organization will not delegate blindly today. The refusal exposes the missing authority facts more clearly than a generic automation inventory does.
Customer-controlled shadow mode can compare what an agent wants to do with what the current authority model would permit, without granting downstream execution power.
The useful output is not simply “blocked.” It is the difference between requested power and delegated power: missing scope, excessive duration, wrong target, absent approval, expired authority, or another exact constraint.
When a workflow is eventually activated under the production program, the Action Permit should remain exact, revocable, attributable, and limited to the smallest consequence the organization has actually authorized.
Guardian and revocation paths remain separate from the agent that requested the action, so the system can remove or narrow machine power without depending on the machine to agree with the intervention.
Broader automation should follow observed authority coverage, decision quality, intervention readiness, and attributable execution evidence. A successful demo, integration, or commercial purchase does not expand machine authority.
Non-negotiable properties
07 / CONSTITUTION
Model reasoning may shape a request; the final authority decision is governed by explicit machine-evaluable facts and policy.
No credential, urgency signal, subscription, integration, or confident model output silently fills an absent delegation.
Permits bind an authorized consequence instead of turning one approval into ambient machine power. Execution Fabric then binds technical capability to that permit.
Authority that can be granted must also be capable of becoming unusable before a later prohibited action completes.
Execution capability should materialize after permission exists, not serve as evidence that permission must have existed.
Observing or proving what happened cannot retroactively legitimize an action that lacked authority before execution.
Evaluator questions
08 / BUYER CLARITY
Interactive evaluation
The Authority Lab ↗ is a synthetic browser-local demonstration of PERMIT, NARROW, HUMAN_AUTHORITY, and DENY outcomes. It creates no real permit or execution.
Public truth boundary
This page describes StableMind architecture and product behavior. Its examples are synthetic. It does not claim a named legal customer, a live governed customer action, external production proof, recognized revenue, or realized customer value.
Read the Public Truth ContractStart with ActionGate
That is the shortest path into machine authority: define the consequential action, expose the authority boundary, then move toward synthetic evaluation and customer-controlled shadow mode. SIO19 introduces the commercial account and organization boundary. Deployment still requires a configured external identity provider, and the resulting account creates no permit, credential, delegation, or machine authority.
website_session_creates_authority=false
After the decision
ActionGate decides before action. The Proof Explorer follows the later request, permit, executor receipt, verifier observation, and Proof of Consequence without letting evidence grant authority.