Agent-008 is decision-integrity infrastructure for autonomous AI agents. It gates every agent action on certified authority and emits a Provable Authority Package — portable evidence of why an action was allowed, or a negative authority proof of the governed action that was prevented. It answers the question above with cryptographic authority evidence rather than with a policy document.
Agent-008 is a runtime gate that authorizes AI-agent actions and emits a Provable Authority Package (PAP) — portable evidence of why an action was allowed, or a negative authority proof (NAP) of the governed action that was prevented. The decision it makes is authorization, not correctness. Agent-008 is not an AI safety model — it is an authority system for AI actions. It does not own the substrates it uses, does not make model outputs correct, and does not replace your identity system.
Agent-008 does not decide whether an AI answer is correct. It decides whether the requested action is authorized.
Standalone Rust binary · deterministic gate · offline-verifiable evidence
An autonomous system needs more than good decisions. It needs a trusted history of authority — because the question an auditor asks is rarely “what did it decide?” and almost always “what was it allowed to decide, at that moment, and who moved that boundary?”
Agent-008 preserves that chain on H33-Stamption, the post-quantum governance commitment layer, so every authorization, transition and evidence event travels on one verifiable track. The railway is the useful picture:
The chain Agent-008 preserves runs human intent → authority → execution → evidence. Code, build and artifact identity along that chain come from H33-GIT; Agent-008 governs the runtime and does not claim code identity as its own.
Stated plainly: H33-Stamption and H33-GIT are admitted identities with no published deployment of their own yet. Agent-008’s own evidence — the whitepapers, the adversarial testing report, the offline bundle below — covers Agent-008. Composition does not extend it to what Agent-008 is built with.
Autonomous agents act from memory, prompts, and inherited context. None of that is an authority system — it is a guess about what the agent is allowed to do. The risk is not merely an incorrect answer; it is an unauthorized action: an agent moving funds, changing a policy, or calling a tool that no human ever authorized — with no way to prove afterward whether it was allowed.
Every action passes a deterministic runtime gate. The gate is a boolean evaluation over signed inputs — so it is replayable and its verdict is stable.
no_read_attestation, capsule_invalid, not_activated, stale_authority). No silent allow, no silent reject.Agent-008 composes Agent-Zero as its privacy-preserving classification layer — Agent-Zero enables privacy-preserving classification workflows on CKKS ciphertexts, so protected data can stay encrypted through the computations it supports. Agent-Zero is a distinct product with its own identity; Agent-008 uses it as a part, it does not absorb it.
Agent-008 is built on shared substrates it uses — it never claims to own them:
APQC migrates an environment to a governed state, Agent-008 enforces authority on every action, HATS continuously monitors that it holds, Verification proves it independently, and Authority Center preserves the resulting authority over time.
The strongest evidence is a downloadable audit bundle you re-verify offline, with no contact to H33. The proof page is not the proof — the artifact is.
The website is not the proof. The artifact is the proof.
A signed evidence tar with signer_pub.bin and an offline verification_report.md — re-check the decision yourself, and confirm a substituted value is rejected.
Each decision seals a Provable Authority Package (allowed) or negative authority proof (prevented), verifiable independently by a zero-state verifier.
Preflight a decision →Point Agent-008 at a request and it returns an authorized decision plus its Provable Authority Package:
A local HTTP serve mode is coming next — disclosed here as not-yet-available rather than presented as shipped. Documentation · Whitepaper
Agent-008 does not ask whether an AI is intelligent enough to act. It asks whether that action had cryptographic authority to occur.
The contrast below is with a category, not with a vendor. Conventional AI controls describe intent and record activity; both are useful and neither produces something an outsider can check.
The right-hand column is not a claim that the left-hand one fails. It is a claim about what each produces: a policy states what should happen, a log states what was observed, and an authority proof states what was permitted — in a form somebody outside the system can check without asking us.
Teams deploying autonomous agents that move value, change state, or call tools. Agent-008 replaces prompt- and memory-based “trust the agent” with a deterministic, provable authorization gate. Especially where an unauthorized action carries financial, operational, regulatory or safety consequences.
Without it: an agent can take an action no human authorized, and you cannot prove afterward whether it was allowed.
See Agent-008 govern your agentsAgent-008 does not make model outputs correct, does not replace an identity provider, and does not prove any claim without an artifact. It does determine whether an action is authorized and preserve replayable evidence of that decision.
Authority Freshness enforcement and Root-lineage verification are on the roadmap; the current verification level reports stage_d_attest_bound and advances to aggregate_v1 when Root lineage wires in — not a fake green check.
Apply for research access to run governed adversarial testing and independently review the resulting evidence and Replay.