Explicit authority
A decision states precisely what it covers—and what it does not.
VESOSVerifiable Engineering Stewardship & Oversight System
Human authorization for consequential agent actions
VESOS is a local-first authorization and evidence layer. It binds an agent’s exact action, target, revision, scope and expiry to one accountable human decision; a connected adapter enforces the external command.
For CTOs, platform leads, security engineers and assurance teams that must show who authorized an agent’s release, infrastructure change or credential-bearing action—and exactly what was allowed.
Development preview · V06 API test-validated locally · Owner Console in local development · No live provider-to-executor path qualified end to end
The failure mode
A person approves one revision, target and scope. Before execution, the code, target or policy changes. A generic permission prompt may still look valid. VESOS makes the mismatch explicit: the old decision is not authority for the new action.
How the boundary works
The proposal, human decision, external action and resulting evidence remain separate records with separate responsibilities.
An agent or tool proposes one action and its technical context. The proposal is candidate data, never authority.
VESOS evaluates the submitted context. A person authorized for that tier and scope approves or rejects the exact request.
The kernel checks the submitted admission record against recorded authority and a scoped, expiring lease. The adapter and executor remain responsible for the actual command. The kernel never runs it.
Reported evidence is bound to the attempt. Independent review can then inform a separate human acceptance decision.
Who the owner isAn owner is not a job title. It is the person authorized and accountable for deciding this particular action at its stated risk tier and scope.
Enforcement boundaryVESOS governs only actions routed through its connected enforcement point. It cannot block a tool or credential that bypasses that point.
Local-firstVESOS control records remain local. A connected cloud model may still process data under that provider’s configuration and terms.
What the team gains
A decision states precisely what it covers—and what it does not.
Expiry, revision drift, scope conflict or tampering remains blocked instead of becoming implied permission.
Separate records show what was proposed, authorized, attempted, evidenced and accepted.
Evidence boundaries
No single badge or test count is allowed to stand in for product readiness.
Recorded evidence supports traceability within its stated boundary; it does not independently prove every external effect.
The pinned snapshot exercises signed decision-envelope verification, tamper rejection, stale or expired authority, conflicting replay, receipt binding and audit continuity.
Development behavior, not production certification.The console inspects decision context and records an owner’s approval or rejection. Recording authority never executes the action.
Not publicly distributed; no stronger public test claim is made here.The demo calculates SHA-256 over the exact synthetic DEMO-JSON-1 bytes displayed in the browser.
No API, signature, real decision, audit-chain verification or execution.The Workspace is a separate reference application. The Donation Recognition case documents one applied engineering-governance method.
Neither is proof of the V06 runtime or live agent-to-executor path.Product status
Claims below are intentionally scoped to a component, date, evidence identity and explicit limitation.
v06-apiA pinned local development snapshot exposes 65 HTTP operations and recorded 937/937 passing offline automated tests.
Development behavior only; the internal qualification artifact is not publicly reproducible and is not production or security certification.owner-consoleA local browser interface and BFF inspect decision context and record owner approval or rejection. Recording authority never executes an action.
Not publicly distributed; no public test-count claim is made.adapter-executorNo live provider-to-executor path has been qualified end to end.
Under qualification does not mean implemented or available.distributionNo public installer, hosted operational service or production deployment is available today.
Roadmap item only.The 65 HTTP operations and 937/937 offline tests describe one pinned V06 development snapshot recorded on 4 September 2026. They support named invariants; they are not production readiness or an independent security audit.commit eacf01d7b8c43295236174f8c8f556338483ea43 · OpenAPI SHA-256 b652a133…b193ab35
Applied-method evidence
One bounded Donation Recognition Platform increment applied the VESOS engineering-governance method to requirements, authority boundaries, implementation, deterministic verification, independent review and a separate publication decision.
This n=1 case supports decision traceability and evidence discipline. It does not validate the V06 API, Owner Console, provider hook, external executor or production safety.
Design-partner conversations
If your team uses coding agents around releases, infrastructure, repositories, credentials or regulated data, talk directly with the VESOS project team about a bounded evaluation in your engineering environment.
Active contact emailcontact@vesos.aiEmail opens in your mail application. This site collects no application data; the public demo stores no decision and executes no action.