Nearly all of these can be watched proving themselves on the narrated guided tour at veridect.ai/governance-suite — about seven minutes, live calls to the production engine. The four beyond-human-oversight analytics at the end run on the engine’s API by design, not as tour stations — as does the newest layer, the fabric between agents.
01
One model grading its own work
The gap. Most systems still trust a single model’s answer — or let the same model check itself.
Veridect verifies what AI says before governing what it does. Multiple independent frontier models — swappable by design, so no vendor lock-in — are adversarial by construction: they check each other’s work rather than their own. Weighted voting produces a calibrated confidence with source attribution: where the answer could fail (reasoning gaps, hallucination risk, domain mismatch, stale knowledge), not just how much to trust it. The result scores 85.0% on MMLU-Pro, 3.0 points above the best single model inside it.
Cost tracks risk by design: routine calls run lean; the full multi-model adversarial pass is reserved for high-impact decisions, where it earns its cost.
02
Pre-action, not post-action
The gap. Most tools review what AI said after the fact.
Veridect intercepts the proposed action itself — the verb, the target, and the parameters — before it executes. The gate enforces each agent’s explicit authority plus four deterministic policy classes: money over a limit, protected personal data, protected-class adjacency, and regulated health data. Sensitive actions escalate to a human; an action reaching past its declared authority is blocked outright.
03
The consensus trap (correlated error)
The gap. Models agreeing isn’t the same as models being right — they can share the same blind spot.
Veridect computes a deterministic independence read on every consensus: model-family diversity, reasoning divergence, and corroboration depth. High agreement with low independence is flagged and escalated to a human.
The independence signal is a reason to look closer, never proof the answer is wrong — and it never alters the confidence number.
04
Slow-burn data theft across a session
The gap. No single step looks dangerous; the theft hides in ordinary steps.
The gate tracks which kinds of sensitive fields an agent has touched across a session — never the values themselves — and escalates the outbound step when cumulative exposure crosses a threshold.
05
Workflows that break rules no single agent breaks
The gap. One agent reads identity data, another reads health data, a third sends a report — each inside its own scope, while the combined workflow assembles something no one authorized.
Constellation governs the crew you declared: it sees the pattern across the workflow’s agents and escalates the moment combined exposure crosses a line, with each agent’s contribution attributed.
Escalate-only by design: Constellation never auto-approves and never blocks on its own.
06
Proof anyone can check — without trusting us
The gap. An audit trail you have to take on faith is not evidence.
Every verdict produces a SHA-256-chained, write-once audit bundle, signed with an Ed25519 proof-of-origin signature. Veridect Proof is a standalone verifier your risk team downloads and runs offline: it re-checks the record’s hash and the signature, and re-derives the deterministic verdict byte-for-byte — no call to our servers. Subpoena-defensible, underwriting-grade evidence.
A whole multi-agent workflow can be sealed the same way: every gate-observed decision in the chain bound into one signed Merkle root, so an entire agent-to-agent-to-tool cascade verifies in a single check by the same offline verifier — and re-checks against the live ledger will distinguish a later legitimate append from tampering.
A seal proves the recorded hops are intact and in the order recorded. It does not prove completeness — an action that never passed through the gate cannot appear in the seal.
07
Who, cryptographically, is asking?
The gap. Agent names in a request can be typed by anyone.
Veridect issues Ed25519 agent passports: signed, replay-proof identity envelopes and signed delegation chains that can only narrow authority hop by hop. In required mode, an unidentified or forged caller is refused before any model is even consulted — zero inference spent on impostors.
08
Oversight that is more than a checkbox
The gap. An escalation only counts if the human actually looked.
Veridect measures review quality at the team level — dissent-blind approvals, rubber-stamp patterns, unusually fast reviews — and reports a risk band.
Aggregate-only: no individual is ever scored, and no band is reported below five reviews. It detects; it never prevents.
09
Tool calls governed at the source
The gap. Agents increasingly act through tool protocols, where enforcement sits beside the traffic instead of inside it.
Veridect’s governed MCP gateway identity-checks and gate-checks every tool call before forwarding it. A refused call is never delivered to the tool — the refusal is returned to the caller and recorded on the ledger. Enforcement lives in the traffic itself.
10
Evidence in the regulator’s language
The gap. “Show us how this is governed” rarely maps to what a system actually logs.
Veridect assembles sealed ledger records into an article-mapped EU AI Act evidence pack — including a serious-incident report skeleton where eligible — and says in writing where the layer does not reach. And the package doesn’t stop at a download: it has been demonstrated landing in a live ServiceNow instance as a standard incident record, through the core Table API every deployment ships with — no GRC module required.
Documentation support for counsel; not a compliance or legal determination.
11
Facts an underwriter can use
The gap. Affirmative AI-agent coverage is young, and underwriters lack structured evidence of how an agent was governed before an incident.
With Veridect Assurance, every governed action becomes a structured, underwriting-grade evidence record, plus 30–90-day portfolio telemetry: decision mix, policy-class fires, ledger integrity, oversight and identity enforcement — counts and rates, deliberately not a composite “AI risk score,” because an invented number helps no one.
Veridect is not an insurer; assurance records and telemetry are not pricing, certification, or coverage.
12
A system that attacks its own defenses first
The gap. Most systems wait to be attacked before they learn anything.
On demand, the engine’s models take turns authoring fresh attack scenarios against a tenant’s own policy — scope violations, authority ambiguity, financial thresholds, protected data, stealth attacks — and the deterministic core judges them in isolation. Contained probes are reported by attack class; anything uncontained is flagged for human review. Nothing auto-tightens.
13
Test tomorrow’s policy against yesterday’s decisions
The gap. Policy changes ship blind, and nobody knows which past calls would have gone the other way.
Replay a proposed change against your own recorded history: which real verdicts flip, and what drives each flip — a single field where one is responsible, a combination where several act together. Zero model calls, zero writes: pure re-derivation of sealed records. Where a record can’t be honestly re-derived, the system refuses to pretend.
And once a change ships, it is on the record. The enforcement configuration the gate actually consults — thresholds, detector set, identity mode, signing state — is attested into its own signed, append-only ledger, with each change mechanically classified as a tightening or a loosening. Decisions carry the fingerprint of the configuration in force when they were made, so “what was the system set to when it cleared this?” has an answer that cannot be quietly rewritten afterwards.
This is self-attestation: the system that enforces policy is the system that records it. It makes a retroactive change to the configuration history evident — it is not independent third-party oversight.
14
The minority report, on the record
The gap. When one model saw what three missed, that dissent usually disappears into an average.
The break from the pack becomes permanent: the dissent ledger records provider stances, lone-dissent patterns, and how the human ultimately ruled — vindicated, partially vindicated, or overruled.
Counts and patterns only: it never ranks providers, and dissent reasoning stays sealed in the audit bundle.
15
The swarm that never declares itself
The gap. Cross-agent defenses watch a declared crew — a shared workflow, a session, a visible link. In July 2026 a research swarm of roughly 700 agents showed the real shape: identities sharing none of those, converging on the same data over days, every single action individually plausible.
Three deterministic fleet classes watch the whole tenant, over days: a sliding seven-day exposure ledger per agent identity and per fleet; swarm convergence — distinct identities converging on the same sensitive category or the same hashed action shape inside a 72-hour window; and target convergence — many identities, one target. When an outbound step then fires inside a converged pattern, it escalates to a human with the cohort size and history on the record. Identity games cut against the attacker: rotating identities makes the cohort count climb faster, and collapsing behind one identity concentrates its ledger. If fleet state is ever unavailable, the call falls back to the normal per-action verdict — the primary gate keeps running.
On the record, at ten thousand. On 10 September 2026 the layer was exercised with ten thousand distinct agent identities on one tenant — one proposed step each, zero model calls: 8,500 confidential reads, 1,000 in-scope sends to an external mailbox, 500 transfers. The first outbound step held for a person came from identity #30, three having cleared before it exactly as the threshold specifies; every one of the 1,496 outbound steps after it was held or blocked. A benign control fleet of ten thousand under the same policy drew zero fleet escalations; an identity-less fleet was caught by the tenant-wide counter; and after its fast state was wiped, the layer rebuilt the window from the sealed ledger and kept escalating. All 10,000 rulings matched an independent re-statement of the policy. Then the same swarm went through the published system as real requests — ten thousand live multi-model rulings, each signed: detection at identity #30 again, every outbound step after it held or blocked, a benign control fleet of 300 live rulings clean, 10,300 of 10,300 signed records verified offline against the published key. The exercise record →
Escalate-only, like every policy class: it can raise a greenlight to human review, never block on its own, never wave anything through. Counters are name-only — field-name categories, verbs, and truncated hashes, never data values. Newest classes, additive beside the externally validated per-action record; the ten-thousand-identity exercise is our own deterministic run of the fleet logic, with a synthetic approve standing in for the model consensus, followed by a separate live run of the same swarm through the published system as real three-provider rulings — both our own runs, and a count of identities, not a rate.
16
The fabric between agents
The gap. Agents don’t just act — they delegate, coordinate, remember, and plan. Every control above judges an action, a session, a crew, or the fleet; none reads how agents work together: authority handed down a chain of hops, the maker becoming its own checker, abandoned plans, unvetted memory, unwatched buses. Twice this August, blind polls of fifteen frontier models named delegation-chain authority the industry’s next unclosed gap.
Seven deterministic policy classes now govern the fabric itself. Delegation-chain authority — too many hops, pass-through relays, wildcard grants, a sensitive action landing far from the root authority that granted it. Separation of duties — maker and checker kept apart. Coordination shapes, two classes — fragments whose reassembled record crosses the line; relay pipelines collected by one identity and transmitted by another, transformed in between or not. Plan pre-commitment — each gated step checked against the sealed plan the agent announced. Memory provenance — unverified or sensitive-named memory writes quarantined at ingest; actions citing them held for a human. Queue and bus provenance — the sender’s signature on every message envelope: unknown sender, revoked key, bad signature, an enqueue that never passed the gate. Every risky shape escalates to a person before the action runs.
Escalate-only, default-off, per tenant; names, shapes, and signatures — never content — at zero model cost; if their state can’t be read they step aside while the primary gate keeps enforcing. The declared side of the fabric whose undeclared side is Problem 15. Live on the engine’s API and documented on the homepage; not yet a tour station. Additive beside the externally validated per-action record.