Every agent records purpose, owner, model, tools, data, memory, instructions, permissions, autonomy, approvals, environment, MCP, APIs, and loop limit. Boundaries are ALLOWED, RESTRICTED, APPROVAL_REQUIRED, or DENIED. The Governor decide API records ALLOW or DENY against policy-to-code rules. It is an assurance decision point, not a silent intercept of third-party agents.
Outcomes
- Agent-first register and card
- Declared assurance boundary per tool
- Governor ALLOW/DENY with an audit trail
