Agent-008 is decision-integrity infrastructure for autonomous AI agents. It gates every agent action on certified authority and emits a Provable Authority Package — portable evidence of why an action was allowed, or a signed proof of what was prevented.
Agent-008 is a runtime gate that authorizes AI-agent actions and emits a Provable Authority Package (PAP) — portable evidence of why an action was allowed, or a negative authority proof (NAP) of what was prevented. The decision it makes is authorization, not correctness. It does not own the substrates it uses, does not make model outputs correct, and does not replace your identity system.
Standalone Rust binary · deterministic gate · offline-verifiable evidence
Autonomous agents act from memory, prompts, and inherited context. None of that is an authority system — it is a guess about what the agent is allowed to do. The risk is not merely an incorrect answer; it is an unauthorized action: an agent moving funds, changing a policy, or calling a tool that no human ever authorized — with no way to prove afterward whether it was allowed.
Every action passes a deterministic runtime gate. The gate is a boolean evaluation over signed inputs — so it is replayable and its verdict is stable.
no_read_attestation, capsule_invalid, not_activated, stale_authority). No silent allow, no silent reject.Agent-008 composes Agent-Zero as its privacy-preserving classification layer — Agent-Zero performs encrypted classification on CKKS ciphertexts so the agent never sees plaintext. Agent-Zero is a distinct product with its own identity; Agent-008 uses it as a part, it does not absorb it.
Agent-008 is built on shared substrates it uses — it never claims to own them:
APQC migrates an environment to a governed state, Agent-008 enforces authority on every action, HATS continuously monitors that it holds, Verification proves it independently, and Authority Center preserves the resulting authority over time.
The strongest evidence is a downloadable audit bundle you re-verify offline, with no contact to H33. The proof page is not the proof — the artifact is.
A signed evidence tar with signer_pub.bin and an offline verification_report.md — re-check the decision yourself, and confirm a substituted value is rejected.
Each decision seals a Provable Authority Package (allowed) or negative authority proof (prevented), verifiable independently by a zero-state verifier.
Preflight a decision →Point Agent-008 at a request and it returns an authorized decision plus its Provable Authority Package:
A local HTTP serve mode is coming next — disclosed here as not-yet-available rather than presented as shipped. Documentation · Whitepaper
Teams deploying autonomous agents that move value, change state, or call tools. Agent-008 replaces prompt- and memory-based “trust the agent” with a deterministic, provable authorization gate.
Without it: an agent can take an action no human authorized, and you cannot prove afterward whether it was allowed.
See Agent-008 govern your agentsAgent-008 does not make model outputs correct, does not replace an identity provider, and does not prove any claim without an artifact. It does determine whether an action is authorized and preserve replayable evidence of that decision.
Authority Freshness enforcement and Root-lineage verification are on the roadmap; the current verification level reports stage_d_attest_bound and advances to aggregate_v1 when Root lineage wires in — not a fake green check.