Connection check
verified live · 20h ago
governance-platform
Pre-execution governance for AI agents. Deterministic PASS/FAIL/REVIEW verdicts, replayable proof.
Tools
37
GitHub stars
—
Installs / wk
—
Licence
—
Transport
streamable-http
Last checked
20h ago
Tools & capabilities
37 toolsRead from the running server on 20h ago.
account_status
read-only
api_key*
This account's plan, key usage, Blueprint counts, and the deployed platform build fingerprint (version, build, deployed). This account's plan, key usage, Blueprint counts, and the deployed platform build fingerprint (version, build, deployed).
analyze_anomaly
read-only
api_key*structured_data*
Explain whether a record fits the usual pattern for records like it, and which fields stand out. No Blueprint required. Explain whether a record fits the usual pattern for records like it, and which fields stand out. No Blueprint required.
approve_rule
api_key*rule_id*blueprint
Promote a rule discovered by discover_patterns into Blueprint-ready form. Promote a rule discovered by discover_patterns into Blueprint-ready form.
authorize_execution
api_key*blueprint*structured_data*
Go/no-go for a real-world action (payment, filing, API write): runs full validation, then the Blueprint's execution gate. authorized=true only on PASS; REVIEW means do not… Go/no-go for a real-world action (payment, filing, API write): runs full validation, then the Blueprint's execution gate. authorized=true only on PASS; REVIEW means do not proceed automatically. Different from validate: validate asks is this data correct, authorize_execution asks should this action happen.
check_blueprint_health
read-only
configapi_key*blueprint
Static pre-deploy analysis of a Blueprint's rule set. Returns a health verdict - healthy, acceptable, fragile, rigid, split, brittle_islands, or unsatisfiable - with advice… Static pre-deploy analysis of a Blueprint's rule set. Returns a health verdict - healthy, acceptable, fragile, rigid, split, brittle_islands, or unsatisfiable - with advice, including joint conflicts pairwise checks miss.
check_drift
api_key*blueprintstructured_data*
Check whether recent submissions still match the established pattern for this Blueprint. Returns a stability verdict and observation count. Check whether recent submissions still match the established pattern for this Blueprint. Returns a stability verdict and observation count.
check_realization
api_key*blueprintstructured_data*
Structural realization analysis of a payload against the Blueprint's reference configuration (requires a 'realization' block; otherwise status=skipped). Diagnostics-tier to… Structural realization analysis of a payload against the Blueprint's reference configuration (requires a 'realization' block; otherwise status=skipped). Diagnostics-tier tool; prefer validate or analyze_anomaly for standard checks.
compare_semantic_equivalence
read-only
api_key*payload_a*payload_b*
Compare two payloads under the dual-hash design: content_hash is invariant to field order and numeric formatting (5 vs '5.00'); semantic_hash additionally to field renaming… Compare two payloads under the dual-hash design: content_hash is invariant to field order and numeric formatting (5 vs '5.00'); semantic_hash additionally to field renaming. Verdicts: identical_content, same_structure_and_values_renamed_vocabulary, or semantically_different.
counterfactual
read-only
api_key*rules_bblueprintconstraints_bstructured_data*
Run the same data under two rule sets and compare which future states remain valid - what-if analysis for rule changes. Run the same data under two rule sets and compare which future states remain valid - what-if analysis for rule changes.
create_blueprint
modeapi_key*require_mathcustomer_name*workflow_name*derived_fields
+10
Create a Blueprint - the governance contract validation runs against. A Blueprint defines what correct means for your data: fields, the math that must hold between them, a… Create a Blueprint - the governance contract validation runs against. A Blueprint defines what correct means for your data: fields, the math that must hold between them, and acceptable ranges. Start from load_rule_pack or discover_patterns if you have no rules yet; invoke the blueprint_guide prompt for the full rule/constraint reference. Returns the new Blueprint's API key.
create_chain
ttlstages*api_key*blueprint*
Create a multi-agent sequential chain: stages validate in order against one Blueprint, repairs propagate forward, TTL bounds the run. Siblings: submit_chain_stage advances… Create a multi-agent sequential chain: stages validate in order against one Blueprint, repairs propagate forward, TTL bounds the run. Siblings: submit_chain_stage advances the chain; handoff_audit verifies a transition between stages. Returns chain_id.
decompose_failure
read-only
api_key*blueprintoriginal_values*corrected_values*derivation_rulesformal_constraints
Split the error between original and corrected values into direct rule violations, boundary violations, and systemic structural error, with per-field contributions. Use wit… Split the error between original and corrected values into direct rule violations, boundary violations, and systemic structural error, with per-field contributions. Use with a known-correct version to diff against; use analyze_anomaly when you only have the suspicious payload. Diagnostics-tier tool.
delete_api_key
can modify data
api_key*confirmkey_to_delete*
Permanently delete one of the caller's API keys. DESTRUCTIVE — agents using the deleted key will receive auth errors immediately. The Blueprint a key was tied to (if any)… Permanently delete one of the caller's API keys. DESTRUCTIVE — agents using the deleted key will receive auth errors immediately. The Blueprint a key was tied to (if any) is NOT affected; only the credential is revoked. To delete a Blueprint and all its keys, use delete_blueprint. The target key can be specified two ways: - As the full key string (gai_...). - As a key_id (SHA-256 hash from list_api_keys).
delete_blueprint
can modify data
api_key*confirmworkflow_name*
Permanently delete a Blueprint and revoke its API keys. Irreversible; requires confirm=true. Account-level keys are unaffected. Permanently delete a Blueprint and revoke its API keys. Irreversible; requires confirm=true. Account-level keys are unaffected.
discover_patterns
api_key*blueprintdocuments*
Learn candidate validation rules and structural document types from a batch of your records, deterministically - no Blueprint required. Promote results with approve_rule. S… Learn candidate validation rules and structural document types from a batch of your records, deterministically - no Blueprint required. Promote results with approve_rule. Source data is not stored.
forecast
read-only
api_key*rank_byblueprintmax_depthmax_branchesstructured_data*
Deterministic forward reasoning: from the current data state, generate and rank the valid next states reachable under the Blueprint's rules. Deterministic forward reasoning: from the current data state, generate and rank the valid next states reachable under the Blueprint's rules.
geometric_confidence
read-only
api_key*state_vector*
Summarize an already-computed state_vector into a confidence level (high/medium/low) with a recommendation. Post-hoc digest - use analyze_anomaly or check_drift for fresh a… Summarize an already-computed state_vector into a confidence level (high/medium/low) with a recommendation. Post-hoc digest - use analyze_anomaly or check_drift for fresh analysis of raw data.
get_execution_trace
api_key*blueprintstructured_data*
Run validation and return the per-node execution trace (node names, deterministic flags, timing) plus the verdict and determinism hash. Use validate for normal operation; t… Run validation and return the per-node execution trace (node names, deterministic flags, timing) plus the verdict and determinism hash. Use validate for normal operation; this is for debugging and audit preparation.
get_inference_trace
read-only
api_key*inference_id*
Retrieve the durable audit trail for a governed generation: every recorded decision and its reasons. Retrieve the durable audit trail for a governed generation: every recorded decision and its reasons.
govern_inference
sourceapi_key*payload*task_type*step_indexconstraints
+1
Quality-govern an in-progress AI generation step BEFORE its output is used (complements validate, which checks finished documents). Returns an action - STOP, CONTINUE, REPA… Quality-govern an in-progress AI generation step BEFORE its output is used (complements validate, which checks finished documents). Returns an action - STOP, CONTINUE, REPAIR_REGION, REUSE_MOTIF, REVIEW, ESCALATE - with a plain-language explanation. Durably recorded; retrieve later with get_inference_trace.
handoff_audit
read-only
api_key*chain_id*to_stage*from_stage*proposed_data
Audit a handoff between two chain stages: a context capsule of verified facts from the prior stage, and (if proposed_data is given) a compatibility verdict that catches fie… Audit a handoff between two chain stages: a context capsule of verified facts from the prior stage, and (if proposed_data is given) a compatibility verdict that catches fields mutated in transit. Siblings: create_chain, submit_chain_stage.
list_api_keys
read-only
api_key*
List this account's API keys (masked) with their Blueprint bindings. List this account's API keys (masked) with their Blueprint bindings.
list_blueprints
read-only
api_key*
List the Blueprints on this account with field/rule/constraint counts and mode. Use the returned workflow_name as 'blueprint' in validate. List the Blueprints on this account with field/rule/constraint counts and mode. Use the returned workflow_name as 'blueprint' in validate.
load_rule_pack
read-only
api_key*pack_id
Load a prebuilt Blueprint template (invoices, timecards, legal, POs, claims). Call without pack_id to list packs; then create_blueprint to save a customized copy. Load a prebuilt Blueprint template (invoices, timecards, legal, POs, claims). Call without pack_id to list packs; then create_blueprint to save a customized copy.
profile_blueprint_robustness
read-only
configapi_key*blueprint
Sweep the Blueprint's numeric constraint bounds and report verdict stability: the stable band, the scales where the verdict first flips, and advice. Use before deploying bo… Sweep the Blueprint's numeric constraint bounds and report verdict stability: the stable band, the scales where the verdict first flips, and advice. Use before deploying bound changes.
recent_inference_decisions
read-only
limitactionapi_key*
Recent generation-governance decisions across all runs - what was approved, held, and escalated. Recent generation-governance decisions across all runs - what was approved, held, and escalated.
reject_rule
api_key*rule_id*blueprint
Reject a discovered candidate rule so it will not be promoted into a Blueprint. Pair with approve_rule after discover_patterns. Reject a discovered candidate rule so it will not be promoted into a Blueprint. Pair with approve_rule after discover_patterns.
repair
read-only
api_key*blueprintstructured_data*derivation_rulesformal_constraints
One-shot repair: return corrected values that would make failing data valid under the Blueprint. Use repair_path to see the steps instead. One-shot repair: return corrected values that would make failing data valid under the Blueprint. Use repair_path to see the steps instead.
repair_path
read-only
api_key*rank_byblueprintmax_depthstructured_data*
Find the shortest sequence of field changes taking invalid data to a valid state, as an ordered path of intermediate states. Different from repair (one-shot nearest fix): u… Find the shortest sequence of field changes taking invalid data to a valid state, as an ordered path of intermediate states. Different from repair (one-shot nearest fix): use repair_path to explain or audit the fix, or compare alternative repairs.
rotate_api_key
can modify data
api_key*key_to_rotate*
Replace an API key with a fresh one. The old key stops working immediately; the new key inherits its bindings. Replace an API key with a fresh one. The old key stops working immediately; the new key inherits its bindings.
structural_types
read-only
api_key*blueprint
Retrieve the document categories a discover_patterns session identified (counts, distinguishing fields, domain hints). Read-only; returns status=no_session if discovery has… Retrieve the document categories a discover_patterns session identified (counts, distinguishing fields, domain hints). Read-only; returns status=no_session if discovery has not run for this namespace.
submit_chain_stage
stage*api_key*chain_id*structured_data*
Submit data for the chain's current stage; the platform validates it and advances the chain if it passes. Response includes next-stage info and accumulated repairs. Submit data for the chain's current stage; the platform validates it and advances the chain if it passes. Response includes next-stage info and accumulated repairs.
update_blueprint
modeapi_key*require_mathcustomer_nameworkflow_name*derived_fields
+10
Update an existing Blueprint in place. Only passed fields change; pass [] to clear a list. workflow_name cannot be renamed and existing API keys keep working. Different fro… Update an existing Blueprint in place. Only passed fields change; pass [] to clear a list. workflow_name cannot be renamed and existing API keys keep working. Different from create_blueprint: modifies an existing Blueprint, mints no new key.
validate
api_key*blueprintstructured_data*
Validate structured data against a Blueprint's rules BEFORE the result is used. Returns PASS, FAIL, or REVIEW with plain-language findings, repair suggestions, a determinis… Validate structured data against a Blueprint's rules BEFORE the result is used. Returns PASS, FAIL, or REVIEW with plain-language findings, repair suggestions, a determinism hash, and a re-verifiable certificate. Same input + same rules = same verdict, every time.
validate_repair
api_key*blueprintstructured_data*
Validate structured data against a Blueprint and, when it fails, include repair suggestions (corrected values with the rule each fix is based on) in the same call. Same ver… Validate structured data against a Blueprint and, when it fails, include repair suggestions (corrected values with the rule each fix is based on) in the same call. Same verdicts as validate: PASS, FAIL, or REVIEW, with reasons and proof.
verify_certificate
read-only
dataapi_key*certificate*derivation_rules
Independently re-verify a validation certificate. Integrity mode checks the hash chain; full mode (certificate + original data) recomputes every attested rule from scratch… Independently re-verify a validation certificate. Integrity mode checks the hash chain; full mode (certificate + original data) recomputes every attested rule from scratch - trust nothing, recheck everything.
verify_replay
read-only
api_key*contract_a*contract_b*