Decision-integrity infrastructure for autonomous AI agents. It gates every agent action on certified authority and emits a Provable Authority Package answering one question: was this agent allowed to do that?
Autonomous agents act from memory, prompts, and inherited context. None of that is an authority system — it is a guess about what the agent is allowed to do. The risk is not merely an incorrect answer; it is an unauthorized action: an agent moving funds, changing a policy, or calling a tool that no human ever authorized — with no way to prove afterward whether it was allowed.
Every action passes a deterministic runtime gate. No model is in the loop — the gate is a boolean evaluation over signed inputs, so it is replayable and its verdict is stable.
no_read_attestation, capsule_invalid, not_activated, stale_authority). No silent allow, no silent reject.Agent-008 composes Agent-Zero as its privacy-preserving classification layer — Agent-Zero performs encrypted classification on CKKS ciphertexts so the agent never sees plaintext. Agent-Zero is a distinct product with its own identity; Agent-008 uses it as a part, it does not absorb it.
Agent-008 is built on shared substrates it uses — it never claims to own them:
| Relationship | Concept | Role |
|---|---|---|
| DEPENDS_ON | Q-Sign | delegation & authority governance |
| USES | H33-Root | certified root of human intent |
| USES | Verification (ZK-Verify) | independent artifact verification |
| USES | H33-Key | secret protection (raw values never reach the agent) |
| BUILT_ON | H33-74 | the 74-byte proof / replay substrate the PAP is sealed on |
| MONITORED_BY | HATS | continuous evidence of governance (external — not a component Agent-008 owns) |
Agent-008 is the govern step of the platform lifecycle: APQC migrates an environment to a governed state, Agent-008 enforces authority on every action, HATS continuously monitors that it holds, Verification proves it independently, and Authority Center preserves the resulting authority over time.
The strongest evidence is a downloadable audit bundle you re-verify offline, with no contact to H33:
A signed evidence tar with signer_pub.bin and an offline verification_report.md — re-check the decision yourself, and confirm a substituted value is rejected. Run the demo →
Each decision seals a Provable Authority Package (allowed) or negative authority proof (prevented), verifiable independently. Preflight →
Point Agent-008 at a request and it returns an authorized decision plus its PAP:
agent-008 run --request <path>
A local HTTP serve mode is coming next — disclosed on the page as not-yet-available rather than presented as shipped. Documentation · Whitepaper
Who: teams deploying autonomous agents that take real actions — move value, change state, call tools. What it replaces: prompt- and memory-based “trust the agent” with a deterministic, provable authorization gate. Without it: an agent can take an action no human authorized, and you cannot prove afterward whether it was allowed.
See Agent-008 govern your agentsAgent-008 does not make model outputs correct, does not replace an identity provider, and does not prove any claim without an artifact. It does determine whether an action is authorized and preserve replayable evidence of that decision.
In progress (disclosed, not asserted as live): Authority Freshness enforcement and Root-lineage verification are on the roadmap; the current verification level reports stage_d_attest_bound and advances to aggregate_v1 when Root lineage wires in — not a fake green check.