VESOSVerifiable Engineering Stewardship & Oversight System

Human authorization for consequential agent actions

Keep coding agents fast. Keep consequential actions under human authority.

VESOS is a local-first authorization and evidence layer. It binds an agent’s exact action, target, revision, scope and expiry to one accountable human decision; a connected adapter enforces the external command.

For CTOs, platform leads, security engineers and assurance teams that must show who authorized an agent’s release, infrastructure change or credential-bearing action—and exactly what was allowed.

Development preview · V06 API test-validated locally · Owner Console in local development · No live provider-to-executor path qualified end to end

The approval was valid when recorded. The action changed before admission.

A person approves one revision, target and scope. Before execution, the code, target or policy changes. A generic permission prompt may still look valid. VESOS makes the mismatch explicit: the old decision is not authority for the new action.

One decision boundary. Four distinct responsibilities.

The proposal, human decision, external action and resulting evidence remain separate records with separate responsibilities.

  1. 01

    Propose the exact action

    An agent or tool proposes one action and its technical context. The proposal is candidate data, never authority.

  2. 02

    Evaluate and authorize

    VESOS evaluates the submitted context. A person authorized for that tier and scope approves or rejects the exact request.

  3. 03

    Enforce and execute externally

    The kernel checks the submitted admission record against recorded authority and a scoped, expiring lease. The adapter and executor remain responsible for the actual command. The kernel never runs it.

  4. 04

    Bind evidence and decide acceptance

    Reported evidence is bound to the attempt. Independent review can then inform a separate human acceptance decision.

Who the owner isAn owner is not a job title. It is the person authorized and accountable for deciding this particular action at its stated risk tier and scope.

Enforcement boundaryVESOS governs only actions routed through its connected enforcement point. It cannot block a tool or credential that bypasses that point.

Local-firstVESOS control records remain local. A connected cloud model may still process data under that provider’s configuration and terms.

Agent speed without invisible authority.

01

Explicit authority

A decision states precisely what it covers—and what it does not.

02

Fail-closed behavior

Expiry, revision drift, scope conflict or tampering remains blocked instead of becoming implied permission.

03

Inspectable accountability

Separate records show what was proposed, authorized, attempted, evidenced and accepted.

Different evidence supports different claims.

No single badge or test count is allowed to stand in for product readiness.
Recorded evidence supports traceability within its stated boundary; it does not independently prove every external effect.

TEST-VALIDATED LOCAL DEVELOPMENT

V06 kernel and API

The pinned snapshot exercises signed decision-envelope verification, tamper rejection, stale or expired authority, conflicting replay, receipt binding and audit continuity.

Development behavior, not production certification.
LOCAL DEVELOPMENT INTERFACE

Owner Console

The console inspects decision context and records an owner’s approval or rejection. Recording authority never executes the action.

Not publicly distributed; no stronger public test claim is made here.
SYNTHETIC PUBLIC DEMO

Guided browser demo

The demo calculates SHA-256 over the exact synthetic DEMO-JSON-1 bytes displayed in the browser.

No API, signature, real decision, audit-chain verification or execution.
SEPARATE EVIDENCE BOUNDARY

Workspace and applied method

The Workspace is a separate reference application. The Donation Recognition case documents one applied engineering-governance method.

Neither is proof of the V06 runtime or live agent-to-executor path.

What exists today—and what does not.

Claims below are intentionally scoped to a component, date, evidence identity and explicit limitation.

Test-validated local developmentv06-api

V06 governance API

A pinned local development snapshot exposes 65 HTTP operations and recorded 937/937 passing offline automated tests.

Development behavior only; the internal qualification artifact is not publicly reproducible and is not production or security certification.
Development buildowner-console

VESOS Owner Console

A local browser interface and BFF inspect decision context and record owner approval or rejection. Recording authority never executes an action.

Not publicly distributed; no public test-count claim is made.
Under qualificationadapter-executor

Live adapter and executor path

No live provider-to-executor path has been qualified end to end.

Under qualification does not mean implemented or available.
Planneddistribution

Public distribution

No public installer, hosted operational service or production deployment is available today.

Roadmap item only.

The 65 HTTP operations and 937/937 offline tests describe one pinned V06 development snapshot recorded on 4 September 2026. They support named invariants; they are not production readiness or an independent security audit.
commit eacf01d7b8c43295236174f8c8f556338483ea43 · OpenAPI SHA-256 b652a133…b193ab35

The engineering method has been applied. The live agent path has not.

One bounded Donation Recognition Platform increment applied the VESOS engineering-governance method to requirements, authority boundaries, implementation, deterministic verification, independent review and a separate publication decision.

This n=1 case supports decision traceability and evidence discipline. It does not validate the V06 API, Owner Console, provider hook, external executor or production safety.

Bring one consequential workflow.

If your team uses coding agents around releases, infrastructure, repositories, credentials or regulated data, talk directly with the VESOS project team about a bounded evaluation in your engineering environment.

Active contact emailcontact@vesos.aiEmail opens in your mail application. This site collects no application data; the public demo stores no decision and executes no action.