StableMindActionGate Workspace
Synthetic tenant · isolated

SIO21 · First Governed Action

Govern the request
before connecting the consequence.

Your first ActionGate decision runs against a bounded synthetic tenant fixture. It is enough to show how authority changes the path, but it cannot reach an executor, release a production credential, move money, alter infrastructure, or create external Proof of Consequence.

AUTHENTICATED · YESREAL MACHINE AUTHORITY · NONEEXECUTOR · NOT CONFIGURED
01 REQUEST02 AUTHORITY03 DECISION04 SANDBOX PERMIT05 EVIDENCE

01 / Synthetic request

PAYMENT / VALUE

Pay the approved supplier

Agent AP-07 requests a supplier payment to a beneficiary already present in its bounded synthetic delegation.

Agent
AP-07
Action
PAY_SUPPLIER
Target
BENEFICIARY_7744
Requested magnitude
$188,000
Authority ceiling
$250,000
Delegation
CURRENT

Change one fact and run the same deterministic governance rules again. No model inference is involved.

02–04 / ActionGate decision

stablemind.first-governed-action.v1
OUTCOMEPERMITcore_decision=ALLOW

The request fits the exact current synthetic authority fixture.

AUTHORITY DIFFrequested power = allowed power
SANDBOX ACTION PERMITISSUED · NON-EXECUTABLE
Permit
SPT-21-PAY-188
Maximum uses
1
TTL
60 seconds
Credential release
PROHIBITED
Production signature
ABSENT
JIT CREDENTIALNOT RELEASED
EXECUTION FABRICNOT CONFIGURED
PROOF OF CONSEQUENCENOT CREATED

05 / Evaluation evidence

SYNTHETIC · ATTRIBUTABLE TO THIS BROWSER CEREMONY
01Request received8fa3…21
02Authority resolved23d1…90
03Decision recorded55b7…ae
04Permit issued / refused91c2…07
05Execution not configurede61d…44
This proves what the synthetic evaluator did. It does not prove an external consequence.

There is no executor receipt and no independent postcondition observation because nothing downstream is executed. Proof of Consequence therefore remains absent by construction.

You have now seen ActionGate govern a request.

Next, make the refused workflow yours.

SIO22 turns the generic synthetic template into a customer-specific Refused Workflow Challenge: exact action, exact target, consequence, authority source, approval boundary, and proof question.

Refused Workflow Challenge
First governed action · consequence-free by design.real_authority=NONE · production_permit=NONE · credential=NONE · execution=NONE · external_proof=NONE