The decision point

Control before execution.

Guardian sits between authority and action. Every consequential request must pass through Guardian before any work is permitted. Nothing is done first and reviewed later. Nothing is left to convention. Every decision is explicit, recorded and reviewable.

Guardian's decision is not simply yes or no. It evaluates the request against policy, risk and control requirements, and returns one of four outcomes — each of which shapes what happens next.

  • Checks verified authority from Passport
  • Evaluates the request against policy and risk
  • Applies control requirements to the specific action
  • Returns an explicit decision before work may proceed
Decision outcomes

Four possible outcomes.

Guardian returns one of four explicit decisions. Each shapes whether — and how — the work proceeds.

Allow

Proceed as requested

Authority is verified, policy permits the action, risk is within tolerance. The work proceeds under the authority named. Sentinel records the decision and the outcome.

Allow with limits

Proceed under constraints

Policy permits the action but only under defined conditions — a narrower scope, a time window, a supervised mode, an additional control. The limits are recorded and enforced.

Require human approval

Pause for a named approver

The action is not denied, but it cannot proceed on automated authority alone. Guardian escalates to the named human approver, who either approves or declines the action.

Deny

Refuse the action

Authority is missing, policy forbids the action, or risk exceeds tolerance. The action is refused, the reasoning is recorded, and the decision is returned to the client through FORGE.

Function

What Guardian evaluates.

Guardian's decision is never a single check. It evaluates six things before returning an outcome.

Authority

Is the actor entitled to act?

Guardian takes the authority Passport has verified and evaluates it against the specific action being requested.

Policy

Does the action conform to policy?

The action is checked against the policies in force — organisational, regulatory, operational, and any context-specific rules.

Risk

Is the risk within tolerance?

Risk is evaluated for the specific action, in the specific context. High-risk actions may be denied or escalated to a human approver.

Evidence

Is the required evidence present?

Some actions require evidence to be attached before they can proceed. Guardian checks that the evidence exists and is complete.

Control

Are the controls in place?

Where the action requires specific controls — a second sign-off, a time restriction, a scope limit — Guardian confirms they are applied.

Context

Is the context as expected?

The same action may be permitted in one context and denied in another. Guardian evaluates the current context, not just the request.

Decision model

How a Guardian decision is made.

Outcome When it applies What happens next
Allow Authority verified, policy permits, risk within tolerance, evidence and controls in place Work proceeds. Sentinel records decision and outcome. VAULT preserves the record.
Allow with limits Action is permitted but subject to defined constraints Work proceeds within limits. Limits are enforced and recorded. Sentinel tracks compliance.
Require human approval Action cannot proceed on automated authority alone Escalation to named human approver. Work is paused until approval or decline is recorded.
Deny Authority missing, policy forbids, or risk exceeds tolerance Action refused. Reasoning recorded. Decision returned to client through FORGE.
Role in the platform

Guardian sits between Passport and Authorised Work.

After Passport verifies authority, Guardian decides whether the work may proceed. Only after Guardian's decision does Authorised Work begin.

See control before execution.

One platform journey, from problem to proven outcome, using synthetic data only. See Guardian return an explicit decision before any consequential action proceeds.