Architecture, evidence, and deployment boundaries.

FieldHash is the authority and evidence layer for enterprise AI agents. It connects the governing records and reviewed decisions behind a workflow, checks whether they still authorize what agents may use, do, and reuse, and records each governed decision.

Abstract

FieldHash is an independent authority and evidence layer for enterprise AI. It materializes the authority state supplied by customer systems and authorized reviewers. At connected handoffs, it checks which records may influence an answer, which effects may proceed, and which reviewed decisions may govern a later case, then records the decision in an evidence packet. It works with the customer's existing model, memory store, database, review system, and tool registry.

Governed Memory controls memory influence: approved/current records can shape the model input; stale, rejected, superseded, out-of-scope, or rolled-back records remain reviewable but blocked from steering future answers without review.

Governed Actions applies the same authority pattern to proposed effects and whole-task boundaries. It keeps current authority and relevant prior action state outside the model and checks them before an instrumented effect proceeds.

Governed Precedent lets review compound outside the model: a reviewed decision may guide later work only while the customer-defined conditions that authorized it remain valid.

The Governed Learning Loop is the controlled process around those surfaces: uncertainty returns to authorized review, approved outcomes update external Authority State, and reviewed judgments may become Governed Precedent when the workflow's authority policy permits reuse. Future use remains linked to the original evidence and stops when its authority changes.

FieldHash does not decide truth by itself. Customer systems of record, review signals, supersession events, and rollback operations define real-world authority for a workflow; FieldHash applies that customer-defined authority at the context, action, and reviewed-decision handoffs the workflow connects.

FieldHash Ledger records the decision surface: evidence packets, packet hashes, checkpoint references, customer-owned exports, and stronger signing or transparency anchoring where configured. Base packets make the governed path reviewable; operator resistance depends on where anchors, logs, and keys are held.

In plain English

Retrieval answers “what looks relevant?” FieldHash asks, “is this record, tool, or reviewed decision allowed to shape the answer or action, and can we prove what happened later?”

Product

Authority and evidence layer at context, action, and reviewed-decision handoffs.

Buyer

AI platform, security, legal, compliance, and model-risk teams.

Failure mode

A relevant record or individually permitted action can still carry the wrong authority into an answer or outcome.

Proof boundary

Separate self-administered studies test influence, action, and reuse controls. They do not establish an integrated customer lifecycle or third-party validation.

The enterprise problem

An agent can retrieve a record, propose an action, or reuse an earlier review decision. Each raises the same question: does the authority behind it still apply to this task, at this handoff?

Stale memory still looks relevant

A superseded decision can remain semantically close to the query and keep winning retrieval.

Permitted actions can accumulate

An action can be allowed on its own while the next step would exceed the configured workflow limit.

An earlier review can expire

A reviewed exception stops authorizing reuse when its scope, supporting evidence, or dependencies no longer hold.

Reviewers need the decision path

Security, legal, compliance, and model-risk teams need to trace what proceeded, what was withheld, and which authority governed each handoff.

FieldHash checks current authority outside the model, at the handoffs you connect. Your systems and authorized reviewers establish that authority; the evidence records how it governed the decision.

Product architecture

FieldHash applies customer-defined authority at context, action, and reviewed-decision handoffs. Existing source systems, agent runtimes, models, and review tools keep their roles. The integration connects the governing records and decisions each selected handoff depends on.

Simple workflows can use simple flags. FieldHash is designed for the workflows where authority spans stores, reviewers, supersession chains, rollback operations, scope boundaries, and evidence requirements.

Authority State maintains the customer-scoped status, scope, source bindings, and precedent dependencies needed between governed handoffs. When a connected source changes, recorded dependencies identify which workflows or reviewed decisions need re-evaluation. Required dependency mismatches suspend precedent reuse and return the case to review.

The documented integration paths use separate context, exact-action, and precedent interfaces. The retrieval example shows one surface. Governed Memory can also govern context cleanup, retaining approved records and recording what was kept or excluded where configured.

LayerTechnologyFunction
Candidate sourcesExisting enterprise records, memory systems, tool catalogs, and review systemsSupplies candidates and authority signals without requiring a rip-and-replace of the customer stack.
Authority StateCustomer-supplied authority and change signalsCarries current organizational authority to governed handoffs and identifies when prior use must be reconsidered.
Governed Learning LoopAuthorized review, bounded carry-forward, and evidence lineageLets review improve future handoffs without turning every outcome into a permanent hidden rule.
Governed MemoryCurrent, superseded, rejected, and out-of-scope record stateDetermines which records may influence the next answer and keeps excluded alternatives reviewable.
Governed ActionsCurrent action authority and whole-task limitsDetermines which proposed effects may proceed and prevents individually allowed steps from combining into an unauthorized sequence.
Agent and action adaptersGoverned discovery and structured action mediationPlaces the authority decision at instrumented model and execution handoffs.
Governed PrecedentReviewed decisions with customer-defined validity conditionsAllows bounded reuse while the authorizing conditions hold and returns changed cases to review.
Semantic support checksProfiled support checks with abstentionWithholds a clean packet when the governing source does not sufficiently support the proposed answer.
Governance engineAllow, withhold, caveat, and review routingApplies configured authority decisions outside the model.
FieldHash LedgerEvidence packets and customer-controlled verificationRecords the governed path for later inspection.
Model routeCustomer-approved hosted, cloud, VPC, or local modelReceives only the context allowed by the governed handoff.
Deployment substrateHosted, VPC, or private deployment profilesSupports a scoped deployment without requiring the customer to replace its model or memory store.

Current implementation boundary

Governed Learning does not mean online model training. FieldHash records authorized changes outside the model. Model output, confidence, or observed success may propose a candidate update, but cannot grant that update authority by itself.

The current Authority State pilot path connects customer-approved authority and change signals to selected governed handoffs. Managed SaaS connectors remain design-partner scoped and customer systems remain canonical.

The supporting connector reliability diagnostic publishes aggregate restart, rejection, replay, and scoped-impact results with a public verification manifest.

FieldHash can mediate supported agent discovery, instructions, resources, prompts, interactive work, deferred work, and action dispatch at an instrumented boundary. Trusted identity, upstream permissions, and runtime isolation remain customer responsibilities; material changes or uncertain authority require a new decision or review.

The current computer-use path is a structured reference integration. The host supplies the proposed action and trusted workflow context; FieldHash checks current authority at the configured boundary and records the decision separately from the observed execution outcome. It does not infer authority from pixels or operate as a managed browser service.

Keep your systems

Customer systems and authorized reviewers establish authority; existing agents and stores remain in place.

Connect each use

Apply current authority before information influences, an effect proceeds, or a reviewed decision carries forward.

Verify the path

Evidence records the governing source, decision, and reason separately from any observed execution outcome.

Governed inference loop

At each connected handoff, the workflow supplies candidates and current authority evidence. FieldHash applies the relevant context, action, or reuse check and records the decision. An approved review may inform a later handoff within its recorded limits; it does not train the model or become permanent permission.

1

Retrieve candidate records, memories, tools, or reviewed precedent candidates from approved systems.

2

Apply governed-state metadata: current, superseded, rejected, revoked, rolled back, expired, or out of scope.

3

Apply the relevant check: source support for context, authority for a proposed effect, or scope and dependencies for reviewed-decision reuse.

4

Release allowed context or permit the governed action or reuse at its connected handoff. Withhold uncertain cases or return them to review.

5

Re-evaluate affected uses when connected authority changes. Preserve the earlier decision and the reason for its new disposition.

6

Record governance reasons, selected inputs, blocked alternatives, packet hashes, and ledger references.

The production context handoff returns an allow decision only after its evidence seal and durable ledger chain verify. Caveated records stay out of model context; by default, a caveat routes the handoff to review. This gives the application a decision backed by a retained, verifiable record before it proceeds.

Evidence: Governed inference proof paths

Public diagnostics with explicit boundaries

The synthesis pages connect the architecture and separate findings across governed surfaces, review, and agent behavior. Individual studies carry the measured claims with their own designs and denominators. The research archive retains semantic limits, ties, losses, and supporting diagnostics. These materials do not establish the full authority-continuity lifecycle in one live study or customer workflow.

Authority Continuity

SYNTHESIS

Across the governed surfaces

Connect the separate Memory, Actions, and Precedent findings with the Ledger evidence architecture. Each study keeps its own design and denominator; this synthesis is not a new benchmark or a demonstrated customer lifecycle.

Read proof path

The Governed Learning Loop

SYNTHESIS

Start here

See how uncertainty returns to authorized review, approved outcomes become bounded external authority, and drift suspends reuse.

Read proof path

Governed Agents

SYNTHESIS

Start here for Governed Actions

See how FieldHash keeps organizational authority decisive as agents act, accumulate effects, substitute routes, replan after denial, and change execution surface.

Read proof path

Governed Agents: Authority Under Organization

AGENTS

Current organizational study

Across three evaluated models, full mediation completed 84/84 main workflows safely; strong per-action authority completed 75/84, with seven known unauthorized workflows and two failures whose safety remained unknown. This authored, self-administered synthetic study used five configured roles and serialized execution. It does not establish large-swarm control or production safety rates. Shared limits across cooperating agents were demonstrated in this study's harness. The shipped kernel enforces per-workflow cumulative budgets; the shared-budget runtime is a qualified research candidate and not part of the current pilot deployment.

Read proof path

Governed Actions: Authority Across Execution Surfaces

ACTIONS

Supporting live execution-surface study

Across separate live episodes, Kimi recorded 46 prompt-only, 47 request-local, 42 incomplete-mediation, and 0 enumerated-surface unauthorized outcomes; Terra recorded 47, 48, 42, and 0. All 128 authorized objectives completed under enumerated-surface FieldHash authority.

Read proof path

Governed Actions: Authority After Denial

ACTIONS

Supporting live replanning study

Across separate live episodes, Kimi produced 45 prompt-only, 44 exact-action, and 0 FieldHash-governed unauthorized executions; Terra produced 45, 44, and 0. Across the governed arms, 127 of 128 authorized objectives completed and 60 of 61 recovery opportunities found an authorized continuation.

Read proof path

Governed Actions: Boundary Crossing

ACTIONS

Authority across the sequence

In the sealed 600-episode flagship, DeepSeek produced 76 unauthorized effects under prompt-only control and 58 cumulative-limit crossings under exact-action checks. FieldHash carried authority across the sequence: no unauthorized effects occurred, while all 48 governed authorized-control episodes completed.

Read proof path

Governed Actions: Effect Substitution

ACTIONS

Supporting matched-counterfactual study

DeepSeek and Terra selected 37 substitutions that crossed reviewed authority boundaries across all eight tested families. Holding those choices constant, prompt-only and exact-action control each permitted 45 unauthorized effect executions. Semantic effect authority permitted none, while all 96 authorized objectives completed. The study page links the public working paper, methods, and signed receipt. The matched counterfactual evaluation provides mechanism evidence. Live adaptive behavior remained outside that study.

Read proof path

Governed Memory (MemConflict)

MEMORY

Governing record only

FieldHash forwards the governing record, withholds the superseded alternative, and records the governed context supplied for the answer.

Read proof path

Governed Precedent

PRECEDENT

Review compounds within bounds

A reviewed decision can guide a later case only while its scope and evidence still hold. In adversarial traps, expired, drifted, conflicted, or unsupported precedents never received a clean allow.

Read proof path

Boundary Research

BOUNDARIES

Ties, losses, and limits

Semantic support, authority inference, public-corpus ablations, and answer attribution show where the mechanism holds, where simpler controls are enough, and where the claim stops.

Read proof path

Verification paths

The Boundary Crossing study publishes a portable projection with the sealed corpus, model traces, replay results, checksums, signed receipt, and offline verification instructions. Download the Boundary Crossing evidence. The Effect Substitution study separately publishes its matched-counterfactual contract, model-stratified results, claim boundary, preauthorization analysis, and signed publication receipt. Read the Effect Substitution methods note. The governed-context evidence package separately includes the consolidated FieldHash methods report, aggregate figures, source-artifact hashes, and public claim boundaries. Download the FieldHash methods report.

Latency diagnostic

The context integration runs after retrieval and before generation. This diagnostic measures that one surface: deterministic local governance over candidate memories. It does not measure action execution, reviewed-decision reuse, or the full application path.

100 candidate memories

3.87-3.89 ms p50

FieldHash enforcement across three 500-iteration local runs.

Ledger evidence add-on

+0.09-0.10 ms p50

Hash-chained evidence serialization plus a local JSONL write over enforcement.

Boundary

local only

No retrieval, network, external provider, or model-generation calls were included.

Claim boundary

This supports a narrow deployment claim: the local governance step was millisecond-scale under this diagnostic. It is not a production SLO, not a network benchmark, and not an end-to-end latency guarantee.

FieldHash Ledger evidence

Current diligence starts with the executable govern and ledger packages, their package tests, the reference single-tenant deployment path, and offline packet verification. Historical enterprise prototype artifacts are retained in the repository but are explicitly excluded from current release substantiation.

Package contract

Python 3.11-3.13

The Govern, Ledger, and MCP packages build as wheels and run standalone package tests across the supported Python matrix.

Published integration

Executable in CI

The public govern-and-verify snippet runs before the site deploys, including blocked-record handling and signer-pinned packet verification.

Reference images

Built in CI

The single-tenant control-plane image and static operator-console image are built from the current checkout. The console image is checked for a static-only runtime.

Verification boundary

Manifest + CLI

Current diligence covers package source, tests, deployment guidance, packet verification, and the offline ledger CLI. Customer-specific infrastructure is validated inside the pilot SOW.

Qualified diligence

Standard governed-inference deployments do not require specialized assurance infrastructure. For long-retention or disputed-evidence workflows, deeper technical review can cover stronger signing profiles, customer key custody, transparency anchoring retained outside the operator boundary, or advanced provenance profiles where configured.

Enterprise deployment posture

Model/store agnostic

FieldHash can govern candidate context, action candidates, and reviewed precedents from existing systems while routing to customer-approved hosted, EU-cloud, VPC, or local models.

Reviewer-facing evidence

Reviewers can inspect which source, action, or reviewed decision was allowed, withheld, or returned to review, with the governing reason.

Controlled inline boundary

After pilot acceptance, selected governed handoffs may be configured to fail closed when required authority or evidence checks cannot complete.

Not a compliance guarantee

FieldHash can generate review artifacts for legal, model-risk, security, and governance teams; it does not replace counsel or certify statutory compliance by itself.

Private deployment path

The architecture supports VPC/on-prem patterns and customer-controlled infrastructure where you require it.

Review security and deployment

Related work and positioning

Stateful and memory-augmented LLM agents are an active area. Relevant reference points include Letta/MemGPT for agent-managed context, Mem0 for production memory across users and sessions, Zep for temporal knowledge-graph memory, Oracle-style enterprise memory substrates, and retrieval-centric systems such as HippoRAG.

FieldHash governs answer and action paths. Trusted workflows supply candidate memory, tools, reviewed precedents, and authority evidence. FieldHash enforces what may influence the answer or action, keeps blocked alternatives reviewable, and records the decision path. Existing stores remain canonical, and FieldHash does not infer truth from arbitrary prose.

Incorrect upstream authority can still be enforced. The value is that the decision path remains inspectable and correctable: reviewers can see which signal governed, which records were withheld, and where the authority decision must be changed if the source system is wrong.

Limitations

FieldHash does not update base-LLM weights during normal use.

The governed-inference studies are self-administered diagnostics with explicit caveats, not third-party validation.

Authority inference from arbitrary prose is separate from enforcement of explicit governed state; semantic binding results are profile-scoped unless customer-corpus or cross-generator validation is run.

Base ledger packets are reviewer-verifiable records. Stronger tamper evidence and operator resistance require configured anchors, logs, key custody, and retention procedures.

Advanced assurance profiles depend on configured dependencies and verified deployment settings.

Status

Shadow-mode pilots open
  • Governed Memory is implemented as an answer-path control layer for candidate context.
  • Governed Actions is implemented as an action-path and sequence-authority control layer where configured.
  • Governed Precedent is implemented as bounded reuse of reviewed authority decisions where configured.
  • Semantic binding and abstention gates are tested as configured packet-eligibility controls, not as autonomous truth inference or open-world semantic generalization.
  • Current govern, ledger, deployment, and verification artifacts are classified in a reviewed diligence manifest.
  • Governed proof paths are linked with explicit caveats, sample sizes, and methodology notes.

For technical diligence

Public materials summarize FieldHash at a product and evidence level. The FieldHash governed-context methods report is available as a direct PDF; deeper architecture notes, benchmark methodology, ablation summaries, trace examples, evidence-export examples, and governance controls are available selectively for qualified technical reviewers.