Ingestion & Normalisation
The interaction enters the pipeline. Payload validated, canonicalised under RFC 8785, hashed under SHA-256, timestamped at ingestion.
interaction_hash = SHA-256(payload_canonical)
Veridom · Control for agent actions
The model isn't the blocker. What's blocking production is the question your risk owner keeps asking — what happens when it does something it shouldn't? Give them a boundary the agent cannot cross, and the pilot ships.
That line is the whole product: someone decides where it sits, and everything past it needs a human who is accountable.
01 · The part nobody catches
No error. No alert. Nothing to investigate, because nothing failed — the action simply executed, cleanly, and nobody with the authority to permit it was ever asked.
Monitoring won't surface it. Monitoring finds anomalies, and a clean unauthorised action isn't anomalous. You find out in a month, when someone complains, or never.
Failures announce themselves. Unauthorised successes don't.
02 · How it works
Most systems collapse these into one log line. Separating them is what makes an action provable rather than merely recorded.
Routing
AUTONOMOUS
ASSISTED
ESCALATED
Who was supposed to be involved.
Authority
BOUND
UNBOUND
EXEMPT
Whether an accountable human actually attached. A human can be present without being authorised.
Execution
PERMITTED
BLOCKED
What was allowed to happen — and a sealed record either way.
ACE is the layer that decides them. It sits between the agent and the action, in three parts:
Define
Your thresholds, authority rules and hard-block conditions — written by the people who already own the policy.
Enforce
Every proposed action evaluated before execution, then permitted or blocked. Nothing executes unexamined.
Prove
Sealed records, retrievable and verifiable years later without access to your systems.
Nothing in that is specific to an industry. A refund ceiling, a dosage limit, a filing deadline, a disconnection rule — same shape. The domain lives in a policy file you own.
03 · The protocol
The Decision Engine determines what the system does. The Evidence System proves what the system did.
Keep scrolling — the pipeline advances
04 · Who has to agree
Most agent projects stall because each side answers only their own. One artifact answers both.
The person carrying the risk
The person shipping it
The boundary is the only thing both of them will sign.
05 · Two ways in
You do not have to talk to us to find out whether this works.
Door one · free
Put a boundary around a single agent action with one decorator, watch it block something it shouldn't do, and verify the sealed record from your shell.
Free · about an hour
Start with the codeDoor two · the sprint
One workflow, one autonomy boundary, one authority model, one evidence readout — the artifact your risk owner needs in order to sign.
Exploratory £7,500–£10,000
Standard £15,000–£25,000
Design-partner pilot £35,000–£75,000
What you walk away with. A sealed evidence pack covering every agent-taken action in the period — produced in seconds, verifiable by anyone, without access to your systems.
Veridom is early. You would be among the first outside the design-partner group — which is exactly what the exploratory band is for.
sha256:8f4b2a9c…77f0 · TIMESTAMPED · INSTITUTION-SIGNED
SEALEDSAMPLE PACK — YOUR PERIOD, YOUR NUMBERS
Fixed scope, fixed weeks. The sprint does not claim production deployment or regulatory approval — it claims one boundary in your organisation becomes provable.
06 · Questions we get
You put something in the execution path. Veridom sits between the agent and the action, evaluates the proposed action against a boundary you configure, and permits or blocks it before it runs. A blocked action never reaches your systems — and the refusal is sealed as evidence.
Those watch; this decides. Tracing and evals tell you what an agent did, after it did it. Content guardrails filter what a model says. Veridom governs what an agent is allowed to do — it is a gate, not a lens, and it sits in the execution path where it can actually stop something.
Yes. You wrap the function that performs the action with one decorator, so it is indifferent to which model or framework proposed it. Python, standard library, no external dependencies. If the action is blocked, your function never runs.
It keeps verifying. The record format is OMP™, an open protocol published as IETF Internet-Drafts and archived with a permanent DOI. Anyone can read the specification, implement it, and check a record without our software, our servers or our permission — which is the point of putting it in the open. Evidence that depends on a vendor staying alive isn't evidence.
Any domain where an agent takes an action with a limit and someone accountable. The engine has no concept of an industry — routing, authority and execution are domain-neutral, and the domain lives in a policy file you write. It runs today across customer operations, healthcare, legal, public sector, utilities and financial services.
Nothing, if you wrap one action yourself. If you want the artifact your risk owner needs in order to sign, the Boundary Proof Sprint is fixed scope, four weeks, from £7,500 — one workflow, one boundary, one authority model, one evidence readout.
07 · Start
If you can name one thing an agent should never do alone, we can put a boundary around it and prove it held. If you can't name one yet, there's nothing to test — and we'll say so.
Confidential intake