Skip to content

Platform

Governed Execution

Every agent step runs through one contract. The model proposes, guardrails check, only allowed tools run, writes wait for a person and the ledger records it all. The rules sit in the platform, so no single agent can skip them.

Illustration. Sample data. One agent step passing through the runtime contract.

The runtime contract

Five steps, in the same order, every time.

Your risk team reviews one contract instead of a different design per agent. Voice AI, LiveAssist, NEQQO and Collections all run on it.

  1. Model call

    The agent asks a model for its next step through the model router, under the policy your tenant set.

  2. Guardrail checks

    Spine checks the answer before anything happens: personal data, contact rules, hardship policy and more.

  3. Allowed tools only

    The agent can call only the tools its profile lists. Anything else is refused and recorded.

  4. Write gate

    Any action that changes a record waits for a named person to decide. No approval, no action.

  5. Audit append

    The step, its checks and any decision land on the hash-chained ledger for your tenant.

Default deny

An agent can only do what you listed.

Each agent runs from an Agentic Orchestration Profile (AOP): a versioned file that lists the tools it may use and the checks it must pass.

  • Unknown tools count as writes

    A tool not marked as read only is treated as a write and sent to the gate. A new connector cannot quietly change records.

  • Guardrails on every generation

    Checks run after each model step, not once per conversation. Collections guardrails cover FDCPA, Reg F and TCPA style rules.

  • Contact rules before a call

    Before any outreach Spine checks contact windows, do not call lists, consent, open disputes and jurisdiction rules.

Tenant isolation

Your data is separated in the database itself.

Isolation is enforced by Postgres row level security, not only by application code. A bug in one screen cannot show one tenant's records to another.

  • Every table carries a tenant

    Each record is stamped with its tenant and the database only returns rows for the tenant on the request.

  • Ledger and tools are tenant scoped

    Connector calls and audit entries carry the tenant too, so each tenant has its own chain of evidence.

Why it matters to you

When an auditor asks how you know an agent stayed inside the rules, you point at one contract and one ledger, not at a code review of each agent.

Watch one governed step end to end.

We will run a real agent step and show each check, the gate and the ledger entry it leaves.