Architecture

Execution authority architecture

Technical flow: intents → deterministic decisions → audited execution. Built for provable guarantees.

System diagram

Gvner Execution Authority Architecture Agents propose intent → Gvner decides → Execution is allowed or denied with evidence. Agent Runtime OpenClaw / Temporal / Tools Gvner Decision Engine Policy • Approvals • Budget • Guardrails Execution Target Tools / APIs / Workflows Evidence & Audit Layer Immutable ledger, receipts, registry hashes, WORM sealing Identity & Change Control SSO, SCIM, session policy, approvals, receipts Operational Integrity Health digest • SLA tracking • Integrity verification • Incident workflow • Regulator packets

Guarantees

Fail‑closed enforcement

Execution requires explicit ALLOW. Timeouts or ambiguity deny by default.

Immutable evidence

Every decision generates a ledger record, receipt, and export hash.

Deterministic policies

Policy evaluation is reproducible across environments and time.

Approval gates

Changes require multi‑party approvals with audit trails.

Integration points

Execution flow (technical)

1. Intent request

Agent submits intent with scope, budget, and context.

2. Deterministic evaluation

Policy engine evaluates constraints and required approvals.

3. Decision + evidence

ALLOW/DENY with ledger entry, receipt, and registry hash.

4. Enforced execution

Execution proceeds only if allowed; denials are final.

Trust artifacts

Where to go next