The Execution Verifiability Gap: Why Model Governance Cannot Authorize Consequential Actions
Positioning Decision Dossiers alongside Policy Decision Records and policy-state serializability
Technical notes on execution authority, decision evidence, policy-state concurrency, and the controls required before consequential actions commit.
Positioning Decision Dossiers alongside Policy Decision Records and policy-state serializability
Reproducible tool-payload failures and paired controls for destructive SQL, credential disclosure, and unbounded action fan-out. The reference run passes 6/6 cases.
Synthetic Decision Dossiers — portable artifact, inputs snapshot, JSON-LD and execution binding — signed by a deliberately published Ed25519 key, with the negative cases a verifier must refuse, so the verifier's behaviour can be reproduced by anyone without an account.
The corpus proves the verifier behaves correctly, including when it should refuse. It does not prove that a production dossier verifies — that needs a real dossier and the live JWKS, and the repository documents that check separately rather than shipping a production artifact it should not have.
npx -y @decionis/verify \
--file dossiers/vectors/owned-execution-bound.json \
--jwks dossiers/corpus-jwks.jsonIn one week Broadcom, JetStream and ChainIT each moved to the execution-time boundary. Good: the category exists. This note compares what each announcement establishes against twelve capabilities of an execution authority, cites the primary source for every cell, and shows the same protocol reaching agents, runtimes and enterprise systems — with the corpus and verifier that let you check the Decionis column yourself.
Read the postThe identity vendors, the guardrail vendors and the card-standards body are all rediscovering the same question — was this specific action authorised, with proof — from three directions. Why that is a third box, why the first two are inputs to it rather than rivals, and how you can check the claim without trusting us.
Read the postWhat a public corpus of signed authorization records proves, what it deliberately does not, and the exact commands — two files, one package — that reproduce every check this site makes, including the negative cases a verifier must refuse.
Read the postThe public comment Decionis filed on EMVCo's draft Agentic Payments framework: twelve comments on evaluating final values at fulfilment time, a held outcome for the consumer, failing closed when state is unavailable, evidence a third party can verify, and shared state the agent must not hold — with the filed form and the reasoning behind each row.
Read the postWhen an automated system or AI agent does something expensive, 'we have the logs' is the standard answer — and it doesn't survive contact with an auditor, a bank, or a buyer. What proof at the moment of decision looks like, in plain language.
Read the postSign-off worked when actions moved at the speed of meetings. Pricing engines, payment jobs, and AI agents don't book meetings. How teams keep real approval power without becoming the bottleneck — in plain language.
Read the post