Decides before consequence
ActionGate evaluates the exact request and may issue a bounded permit. Guardian is not a substitute for that deterministic decision boundary.
Guardian · Independent intervention
Guardian is StableMind's independent runtime intervention plane for consequential machine authority. It can narrow, revoke, contain, quarantine, or coordinate recovery when authority changes or runtime risk demands intervention, without depending on the agent that requested the action to voluntarily surrender power.
agent: deployment-operator
target: production-edge
permit: active when event observed
Guardian may remove power. It may never create or broaden it.
Synthetic architecture illustration. No live agent, permit, credential, or downstream system is affected by this public page.
Product definition
Guardian is the independent control path that makes machine authority interruptible after delegation and authorization. Organizations often search for an AI agent kill switch, but a useful intervention system is more precise than a single red button. It needs current revocation state, bounded permit invalidation, credential and connector containment, agent quarantine, recovery state, and attributable evidence, all without accidentally granting new authority to the intervention mechanism itself.
Intervention is its own authority boundary
01 / INDEPENDENCE
ActionGate evaluates the exact request and may issue a bounded permit. Guardian is not a substitute for that deterministic decision boundary.
Execution Fabric binds temporary credentials and certified connectors to the permit. Guardian can make that downstream capability unusable when the control state changes.
Guardian owns containment and revocation paths that do not rely on the requesting agent's cooperation or on a prompt telling the model to stop.
Revocation, quarantine, attempted execution, recovery, and resulting state become attributable evidence. Evidence still cannot create authority.
Intervention anatomy
02 / SIX BOUNDARIES
Revocation, expiry, incident state, human authority, policy lifecycle change, runtime anomaly, downstream rejection, or another explicit control event becomes an attributable Guardian input.
Guardian identifies the delegation branches, permits, credentials, sessions, connectors, agents, and in-flight actions that depend on the changed control state.
The response can constrain one target, invalidate a permit, revoke a credential, quarantine an agent, halt a connector path, or escalate to a broader incident boundary. Intervention is not automatically maximal.
Execution Fabric and downstream controls receive the intervention state quickly enough to remove future capability and, where supported, interrupt an in-flight operation before additional consequence.
Recovery can require re-authentication, new delegation, fresh ActionGate evaluation, changed policy, human review, or connector repair. Guardian does not simply re-enable yesterday's permit.
The trigger, affected lineage, actions taken, acknowledgments, residual exposure, and recovery state flow into Evidence so the organization can reconstruct what was stopped and what remained.
Intervention modes
03 / NARROW FIRST
Reduce targets, amount, concurrency, duration, or other execution scope when policy supports safe attenuation without granting anything new.
Make a delegation branch or exact permit unusable for later decisions and execution, then propagate that state to dependent capabilities.
Remove an agent, connector, credential broker, executor, or environment from the trusted operating set while investigation or remediation occurs.
Restore service only through explicit recovery criteria and, when consequential power is needed again, fresh authority and ActionGate decisioning.
When intervention matters
04 / RUNTIME CHANGE
Guardian helps ensure descendant permits and temporary capabilities do not continue acting as if the historical grant were still current.
The affected path can be quarantined independently of the agent's reasoning state while other unrelated authority remains intact.
Guardian can remove execution capability that no longer satisfies current policy rather than allowing stale permits or cached sessions to outlive the governing rule.
An action that was authorized under one operational state may become unsafe when the target, destination, balance, incident state, or other consequence facts change materially.
Revocation speed
05 / OUTRUN CONSEQUENCE
A database flag saying “revoked” is not enough when an agent still holds a reusable token, active cloud session, queued payment instruction, or connector retry. Guardian treats revocation as a propagation problem: authority state must reach permits, credentials, sessions, executors, agents, and downstream systems according to the interruption semantics each consequence actually supports.
Human authority, lifecycle policy, incident response, or another governed event changes the current state.
Affected Action Permits become unusable for new execution attempts.
Temporary credentials, delegated sessions, and connector paths are removed or constrained.
Interruptible operations are halted or prevented from taking additional steps; non-interruptible consequences are surfaced as residual exposure.
Any return to consequential power requires explicit recovery and, where needed, fresh authority plus a fresh ActionGate decision.
Constitutional boundaries
06 / REMOVE, NEVER GRANT
Intervention may preserve, narrow, suspend, revoke, or quarantine. It cannot add an action, resource, destination, amount, duration, or delegation right that did not already exist.
Emergency stopping matters, but it cannot compensate for giving agents ambient power in the first place. ActionGate and Authority Cloud remain upstream.
Telling an agent to stop is behavioral guidance. Guardian uses control-plane mechanisms that can make permits, credentials, sessions, or execution paths unusable independently.
The trigger, actor, reason, affected scope, acknowledgments, failures, residual risk, and recovery state should be reconstructable instead of disappearing into an opaque emergency action.
After an incident or revocation, reopening an execution path does not automatically restore prior delegations, permits, or credentials. Current authority must still be valid.
A website account or subscription cannot secretly obtain the power to revoke a customer's machines. Customer control and deployment authority remain explicit and separate.
Evaluator questions
07 / BUYER CLARITY
Public truth boundary
This page describes StableMind architecture and product behavior. Its runtime example is synthetic. It does not claim a named customer deployment, live agent containment, live revocation, external incident proof, recognized revenue, or realized customer value.
Read the Public Truth ContractControl that survives runtime change
StableMind's customer path still begins with ActionGate. Public account onboarding remains SIO19 and SIO21 remains the first governed-action experience. This public Guardian surface demonstrates architecture only and creates no revocation, credential, permit, execution, or customer authority.
website_session_creates_authority=falseConsequence boundary
Guardian may preserve, narrow, suspend, revoke, quarantine, or coordinate recovery while required Consequence Capital remains governed by its own reserve and release gates.