Connect what authorizes the work to what the agent does.
FieldHash is the authority and evidence layer for enterprise AI agents. It checks governing records, proposed effects, and applicable reviews outside the model at the decision points you connect.
Keep your agent runtime and source systems. Start in shadow mode: record what FieldHash would allow, withhold, or send to review. Production enforcement remains off.
What runs, and what your team sees.
Connect selected authority sources and the context, action, or review decisions that depend on them. Your systems remain canonical. FieldHash evaluates the supplied authority and records the result.
- Authenticated gate
- Checks supplied records, proposed actions, or precedent reuse through their documented interfaces. In shadow, the host records the decision; a separately accepted inline integration makes it affect context or dispatch.
- Private operator console
- Shows source health, governing state, decisions, and active precedents. Operators can inspect which source and review a decision depends on.
- Durable review queue
- Keeps uncertain, conflicting, or changed authority visible to authorized reviewers. Their recorded judgment can be reused only within the approved conditions.
- Signed Ledger and recovery tooling
- Retains decision evidence for inspection and configured integrity checks. Backup and restore procedures support the deployment's agreed recovery requirements.
These are the single-tenant reference deployment components. The SOW identifies which are included in your proposed deployment, their access controls, and required recovery checks. A signed record supports integrity verification; it does not establish that the source or reviewer was correct.
Observe first. Enforce after acceptance.
During the shadow evaluation
Record what would be allowed, withheld, or reviewed alongside the existing workflow. Reviewers investigate differences and measure control quality, review burden, latency, and operating effort. Shadow decisions do not block production work.
When enforcement is accepted
Your team approves specific connected points, source-freshness rules, and failure behavior. The host then applies gate decisions before admitting context or dispatching an action. Test denied-action recovery and coverage of alternate paths before enabling it.
Current pilot scope includes configured context, action, and reviewed-decision paths, with per-workflow cumulative budgets. The multi-agent shared-budget runtime remains a research candidate and requires separate scoping. Coverage depends on trusted inputs, connected updates, and mediated paths.
Review the six-week scope and acceptance criteriaInspect an illustrative shadow packet
This illustrative shadow packet shows what would proceed, stop, or require review. It uses synthetic data and records proposed decisions, with production enforcement off.
Candidates in. Governed packet out.
1. Candidates in
Retrieval and agent tooling return current records, stale records, rejected proposals, and possible actions from the systems already in use.
2. FieldHash governs
Configured approval, version, rollback, revocation, scope, and precedent records determine what may influence the answer, action, or next case.
3. Packet out
Shadow decisions identify which context and actions would proceed. Items that would be withheld or reviewed retain a reason and authority source.
4. Review later
The evidence packet gives reviewers a compact record of what was allowed, what was blocked, what needs review, and why.
Illustrative pilot corpus
A support agent asks which refund path is allowed.
Retrieval returns an approved current policy, a superseded amendment, and a rejected proposal. In shadow, FieldHash records that it would admit the current policy and withhold the other two, keeping all three in the evidence record.
Access control determines who can open these records. FieldHash records which would be permitted to influence this answer or proceed under the supplied authority.
Memory candidates
Reviewer-readable trace
POLICY-2026-041
Policy system
retrieval score 0.91
Would allow into model context
current_approved_record
POLICY-2025-118
Policy archive
retrieval score 0.89
Would withhold from model context
superseded_by POLICY-2026-041
EXCEPTION-2026-017
Review queue
retrieval score 0.84
Would retain as evidence only
rejected_exception
Action candidates
Tool-use trace
ACTION-REFUND-STANDARD
Would allow as an action candidate
approved_scope
ACTION-REFUND-OVERRIDE
Would hold for review before execution
approval_required
PACKAGE-REPORTING-2.4.0
Would remove before agent choice
revoked_action
SAMPLE / Illustrative approval lifecycle
Review carries forward while its authority holds.
Follow a newly approved refund exception, separate from the rejected proposal in the packet example. The same policy dependency connects its initial use, valid reuse, and eventual return to review.
Synthetic architectural illustration with shadow decisions and production enforcement off. These stages are not an observed experiment, a customer result, or a combined API response.
01 / Approval
Reviewed
A reviewer approves a bounded exception.
The support lead approves EXCEPTION-2026-018 for up to $50 per duplicate charge, through September 30, with reuse permitted for matching cases. POLICY-2026-041 permits that exception.
Source: policy system. Review: support lead. Dependency: POLICY-2026-041.
02 / Use
Would allow
The current exception supports the proposed refund.
A $35 duplicate charge matches the approved scope. The connected handoffs would admit the governing record and allow the refund under current authority.
Evidence: source version, approval, scope match and proposed action decision.
03 / Valid reuse
Would allow reuse
A later matching case can use the reviewed judgment.
A second $20 duplicate charge falls within the same scope and time window. The policy dependency and review remain current, so the precedent would still apply.
Evidence: prior review reference, current dependency check and reuse decision.
04 / Authority change
Dependency changed
The policy system revokes the exception route.
A connected update marks the authorizing provision in POLICY-2026-041 as revoked. The earlier review remains in the record, but its authorizing condition no longer holds.
Changed condition: permission for this exception. Source: connected policy update.
05 / Dependent reuse
Would withhold · review
Another similar case needs a new authority decision.
A third duplicate-charge case is still similar. FieldHash would withhold reuse of EXCEPTION-2026-018 and send the dependent case to an authorized reviewer.
Evidence: changed dependency, withheld reuse, reason and review destination.
Customer systems and authorized reviewers supply authority. FieldHash checks the configured dependencies at connected handoffs and retains evidence of each disposition. Changes outside those connections require integration or review; the illustration does not imply discovery of every change.
Inspect the separate precedent studySAMPLE / Initial handoff packet
The initial packet records the decision behind the answer.
This display summarizes the initial handoff before the new exception is approved. It shows proposed decisions and their authority sources; its labels are illustrative, not a combined API schema.
packet_type
fieldhash_evidence_packet_v1
workflow_id
support-refund-policy-agent
run_id
fh_demo_2026_06_16_001
mode
shadow
retrieval_route
customer_rag_stack_redacted
model_route
approved_model_route_redacted
allowed_context
POLICY-2026-041
allowed_actions
ACTION-REFUND-STANDARD
blocked_or_caveated
POLICY-2025-118, EXCEPTION-2026-017, ACTION-REFUND-OVERRIDE, PACKAGE-REPORTING-2.4.0
reason_codes
current_approved_record, superseded_by, rejected_exception, approval_required, revoked_action
authority_source
policy approval state + registry revocation state
reviewed_precedent
none in this illustrative packet
evidence_integrity
packet_hash + previous_hash
checkpoint_reference
none in this base illustrative packet
failure_flags
none in this illustrative packet
Output boundary
The packet records the decision outside the model.
This shadow packet records proposed decisions without enforcing them. In an accepted enforcement integration, the host applies those decisions before context reaches the model or an action executes.
FieldHash uses authority established by your systems and reviewers; free text alone does not grant it. If a workflow has no visible authority records, the pilot starts by finding or proposing reviewable signals before enforcement.
When wording differs, the configured resolver must show that the governing source supports the answer. If it cannot, the packet sends the case to review instead of presenting the answer as governed.
Uncertainty returns to review
A missing authority signal never becomes approval by default.
If the current source cannot be identified, the evidence does not support the claim, an action requires approval, or a prior reviewed decision no longer holds, the gate decision withholds a clean allow and records the review route. In shadow, that decision is observed; it does not block production work. A reviewed outcome may guide later cases only while its authorizing conditions remain valid.
The Governed Learning Loop
One reviewed case can improve the next without becoming a permanent rule.
01
A handoff contains missing or conflicting authority.
02
FieldHash sends the case to an authorized reviewer.
03
The reviewer establishes what governs.
04
FieldHash records the scope, evidence, expiry, and dependencies.
05
Future handoffs may reuse the result.
06
Drift, revocation, conflict, or expiry stops reuse and returns the case to review.
A review may update Authority State (the connected view of which records and reviews currently govern), resolve a source binding, revoke or narrow authority, or, when the workflow's authority policy permits reuse, compile the judgment into Governed Precedent. Not every review becomes precedent.
Follow the complete loopUse the shadow evaluation to test the decision and its evidence.
Bring one real workflow. FieldHash will map where authority signals live, run the governed handoff in shadow mode, and return the packet shape reviewers would use before enforcement.
Request a six-week shadow evaluation