Who is acting?
Authentication establishes the actor. Execution Fabric consumes that identity context but never promotes it into authority.
Execution Fabric · Bounded machine execution
Execution Fabric is the StableMind execution boundary that materializes technical access only after ActionGate has issued an exact, valid Action Permit. It binds credentials, connector behavior, target systems, time, and resulting receipts to the authorized consequence instead of treating standing access as ambient machine power.
service: payments-api
environment: production
window: 90 seconds
Credential exists only inside the exact permit envelope.
Synthetic architecture illustration. No credential is issued and no system is executed from this public page.
Product definition
Execution Fabric is the bounded execution layer between an authorized machine action and the downstream system that can make the consequence real. It verifies an Action Permit, resolves only the credential material and connector path required by that permit, constrains execution to the named action and target, records the result, and destroys or expires the temporary capability afterward. Identity systems can authenticate an agent and vaults can hold powerful secrets, but neither fact proves that this action is institutionally authorized now.
The credential distinction
01 / CAPABILITY
Authentication establishes the actor. Execution Fabric consumes that identity context but never promotes it into authority.
The permit binds action, target, limits, validity, authority lineage, and policy decision before technical capability appears.
A token, certificate, secret, or delegated session is execution material. It is resolved just in time and only inside the permit boundary.
The connector returns attributable execution evidence. That receipt becomes an Evidence input, not self-certified Proof of Consequence.
Permit to execution
02 / SIX BOUNDARIES
Confirm signature, issuer, action, resource, destination, limits, expiry, revocation state, and required execution profile. A stale, broadened, malformed, or revoked permit fails closed.
Select an execution adapter that is approved for the permit's action and target. An arbitrary tool exposed to the agent cannot silently substitute for the certified path.
Request the smallest credential or delegated technical session needed for this permit. Long-lived standing secrets are not handed to the model as a convenient shortcut.
Parameters, target, amount, resource, destination, environment, and temporal window are checked against the exact authorized envelope immediately before execution.
The connector performs the authorized operation and returns attributable execution state, including failure or partial outcome, without inventing a stronger consequence claim.
The ephemeral credential expires or is revoked, and the request, permit, execution attempt, receipt, and relevant runtime facts flow into the Evidence lineage.
Credential lifecycle
03 / NO AMBIENT POWER
Credential material is not exposed merely because an agent is authenticated, subscribed, integrated, or technically capable of naming a tool.
The execution service resolves only the credential form and scope required for the authorized action, with the shortest useful lifetime.
The executor checks the action, resource, destination, limits, and permit validity so technical access cannot be stretched into a neighboring consequence.
Temporary capability is destroyed or made unusable and cannot be treated as standing evidence of future permission.
Where bounded execution matters
04 / CONSEQUENCE
A permit can authorize one restart, deployment, configuration mutation, or containment action against an exact production resource without granting the agent an open-ended administrator session.
Payment credentials can remain downstream of verified authority, destination, amount, consequence reserve, and rail-specific execution constraints rather than sitting in agent context.
User, access, data, and workflow mutations can be routed through certified adapters that enforce exact resource and action scope immediately before the change is made.
When a machine action crosses organizational boundaries, the executor can bind the action to the accepted authority exchange and return evidence to both sides without treating integration connectivity as permission.
Runtime control
05 / GUARDIAN HANDOFF
Execution Fabric therefore does not own the last word. Guardian provides an independent intervention path that can make a permit, credential, connector, or execution path unusable when revocation, incident state, policy change, or observed runtime conditions require the organization to stop or contain machine power.
Issues an exact permit only after valid authority and policy.
Materializes bounded capability and starts the certified action.
Observes an independent interruption and revocation path.
Accepts only the bounded execution path that remains valid.
Records execution, interruption, and resulting state without granting authority.
Constitutional boundaries
06 / WHAT IT NEVER BECOMES
Possession, availability, vault policy, token scope, or connector reach is technical capability and cannot replace an attributable grant plus ActionGate decision.
An adapter may reject, narrow through its own safety constraints, or fail. It may not reinterpret an exact permit into a larger action, target, amount, or duration.
Retry logic must remain idempotent or explicitly bounded so a transient failure cannot multiply the authorized effect.
A successful API response is execution evidence. Independent consequence verification belongs downstream in Evidence and may require external facts.
A StableMind account, paid entitlement, enabled connector, or website session cannot cause credentials to materialize or a downstream action to execute.
The execution path cannot disable the control plane responsible for containment, revocation, or recovery merely because an action was once authorized.
Evaluator questions
07 / BUYER CLARITY
Public truth boundary
This page describes StableMind architecture and product behavior. Its runtime example is synthetic. It does not claim a named legal customer, live governed customer action, live credential release, external production proof, recognized revenue, or realized customer value.
Read the Public Truth ContractAuthority before capability
Start with the exact action and the authority required to permit it. When public onboarding arrives in SIO19, ActionGate remains the commercial front door; SIO21 remains the first governed-action experience. This website creates no permit, credential, execution session, or downstream authority.
website_session_creates_authority=falseConsequence boundary
Execution Fabric remains downstream of both the Action Permit and any required Consequence Capital. Technical success does not release reserve.