Product one · the Governed Agent Trust Engine

GATE

The operating system of trust beneath an AI agent deployment. Agents produce; a gate holds the action; a qualified human approves; the decision is sealed. Autonomy is earned, never assumed.

The loop

Five steps, every time an agent acts.

There is no path around the gate. Every consequential action an agent takes runs the same loop — and every pass through it adds to a record you can inspect.

01

Produce

An agent drafts an action — a message, a term, an access or record change. It is a proposal, nothing more. Nothing leaves the gate.

02

Gate

The action is held, scoped, and checked against the hard limits you set. Anything over a guardrail is routed to a human by construction.

03

Approve

A qualified human — never the agent, never the person who submitted it — signs off, edits, or hands it back with a reason.

04

Seal

The decision is written to a hash-chained record: who, what, when, why, and the exact content approved. Tampering with a past entry is evident — the chain breaks visibly.

05

Earn

Cleared evidence raises an agent's standing; autonomy is proposed only when it clears the bar — and revoked the instant it turns.

The record is the product

Evidence that survives an adversary.

Most "audit logs" are a convenience for the operator — and the operator can edit them. That's a story, not evidence. GATE's record is hash-chained: every entry seals the fingerprint of the one before it, so altering any past decision breaks the chain visibly. Remove a row, backdate an approval, soften a rejection after the fact — the math stops matching, and anyone can check.

That single property is what turns a dashboard into an instrument a third party can rely on. It's the difference between "trust us" and "verify us." And it's why the record — not the console around it — is the thing Claire actually sells.

Each sealed decision also captures the human's edit and reason. Over time that becomes a correction corpus — the signal that makes the next draft better and the case that the agent is improving, provably.

TRUST LEDGER — SEALEDHASH-CHAINED
Outreach draft · approved w/ edits
approver ≠ submitter · Aria → M.C.
9f2a…c41
✓ sealed
Pricing term · handed back
reason recorded · out of guardrail
b7e0…18d
✓ sealed
Record change · approved
within limits · logged
3c55…a90
✓ sealed
Governed-auto send · reverted
one-click · trust self-corrected
e14f…7b2
✓ sealed
What's inside

Four mechanisms. One guarantee:
autonomy compounds instead of accumulating risk.

Trust, earned

Scored ledger

Autonomy is proposed only when the evidence clears a statistical bar — never granted by default, always revocable.

Hard guardrails

Limits you set

Every graduated action stays inside bounds you define. Anything over a guardrail always routes back to a human.

Maker–checker

Tamper-evident audit

Every decision — human or agent — is hash-chained into an immutable record. Who did what, when, and why.

One-click revert

Safe by construction

A governed-auto action can be undone instantly, and the agent's trust self-corrects. Reversibility is the floor.

Architecture, stated plainly

A control plane — not another runtime.

GATE does not build, author, or sell agents — it governs the ones you already run. It does not replace your agent framework, and it doesn't lock you into ours. Your agents can run anywhere — on any framework (LangGraph, CrewAI, the OpenAI Agents SDK, Microsoft Agent Framework), on any model provider (Claude, GPT, Gemini, Llama). GATE is the control and trust plane above them: it holds their actions, records the human decisions, and keeps the evidence. An "agent in GATE" is a governed identity — a role, its limits, and its trust history — attached to work it must clear through the gate.

This is deliberate. A trust layer welded to one vendor's runtime or one model isn't a trust layer — it's a lock-in with a nicer name. GATE's independence is what lets it govern a fleet you assembled from many sources, and what lets the record mean something to a party who trusts none of those vendors individually.

Model- & framework-agnostic

The governance core — gate, approval, hash-chained record, guardrails, earned autonomy — is deterministic. It needs no particular model to function, and it survives swapping every model underneath.

Portable by design

An agent's cleared record can be issued as a Trust Passport — a verifiable credential a counterparty can check without taking your word for it.

Who it's for

Built for regulated finance, first.

GATE earns its keep where an agent's action moves money or triggers compliance exposure and someone will later be asked to prove it was sound — lending, fintech, banking, and insurance most of all. If your agents take consequential actions — approvals, borrower and customer communications, pricing and terms, servicing, collections — and you answer to examiners, auditors, or a board, this is built for you. If they only draft low-stakes internal text, it's a smaller fit, and we'll say so. Finance is where the need is sharpest today; healthcare, legal, and insurance operations need the same proof next.

See who gets the most value →

See it running — on us.

GATE governs Claire's own agents and LoanCirrus, a regulated fintech under common ownership, in glass. Inspect the proof, or start a conversation about governing yours.

Inspect the proof Book a conversation