AAMARAFRESH DIRECTION
OPERATIONAL ASSURANCE // GOVERNED EXECUTION

Fresh Direction

Operational assurance for AI agents. Fresh Direction is an R&D-stage governance and control layer designed to assess, constrain, monitor and evidence AI-agent behaviour before consequential actions can affect real systems.

Provider-neutral architecture. Evidence-led decisions. Governed execution.

01CORE

Constitution Engine

Enforces signed non-negotiable rules above model output, policy and execution adapters.

02CORE

Model Adapter + Decision Gateway

Normalises provider-specific AI requests into a standard evidence package before they enter the single mandatory governance path.

03CONTROL

Capability Manager

Applies default deny, least privilege, target scope, time limits and revocable authority.

04CONTROL

Evidence & Policy

Validates provenance, freshness, confidence and conflicts, and can challenge insufficient evidence before policy and risk decisions are made.

05VERIFY

Identity & Approval

Binds consequential approvals to verified identity, exact action scope, target and expiry.

06VERIFY

Credential Security & Rotation

Governs password, API-key and secret rotation through prepare, validate, switch, verify and revoke stages.

07SAFE

Audit, Verify & Safe State

Seals decision evidence, verifies outcomes and blocks consequential actions when critical controls degrade.

08DESIGN

AI Control Room

Operational dashboard for AI requests, evidence, decisions, estate health, incidents, policy state, credentials and verified outcomes.

Original reference supervisor423 / 423 PASS

423/423 root regression passes in the original Fresh Direction supervision proving ground. This is separate from the Governor test suite.

Governor internal verification baseline225 / 225 PASS

The current Governor passes 225/225 internal tests and 225/225 clean-room internal qualification tests. Six remediation phases are complete, with no Critical or High findings outstanding within the tested internal scope. External validation, representative-environment testing and production acceptance remain future work. The Constitution remains NOT ACTIVATED.

Operating modesExplicit only

Observe → Advise → Approve → Bounded Enforce. No unrestricted autonomous mode in V1.

Execution boundaryDefault deny

AI requests do not create authority. Model communication is normalised through the Model Adapter, and real-world execution requires independently issued, scoped authorisation through the governed tool boundary.

Architecture shown at capability level only. Internal decision logic, thresholds, evidence schemas and enforcement mechanisms remain proprietary.
THE CONTROL PROBLEM

AI can reason. It should not decide its own authority.

Fresh Direction separates AI reasoning from authority and execution. Provider-specific model communication is normalised through a Model Adapter before independent evidence, policy, risk and approval controls determine whether scoped execution authority can exist.

01

Observe

Capture AI events, system state, tool use, cost, latency and expected business outcomes as structured evidence.

02

Assess

Apply deterministic rules, transparent baselines, policy boundaries and evidence confidence to detect meaningful failure or drift.

03

Govern

Normalise model requests through a provider-neutral adapter, then apply capability, evidence, policy, risk and human-approval controls before execution authority exists.

04

Verify

Check the real downstream result, detect side effects and seal the complete decision and outcome chain into audit evidence.

PLAIN ENGLISH

What Fresh Direction actually does

Fresh Direction sits between AI and the real world. It lets AI think, plan and suggest actions, but before anything important happens it checks what the AI is trying to do, whether it has permission, what could be affected and whether a human needs to approve it.

01

AI wants to act

The AI can think, plan and suggest an action, but the request does not automatically give it permission to affect a real system.

02

Fresh Direction checks

It checks who is asking, what they want to do, what could be affected, what evidence supports it and whether a human must approve it.

03

Approval is not the end

If the action is allowed, authority is limited to that purpose and Fresh Direction keeps watching while the action happens. Unexpected behaviour can be paused or stopped.

01RequestAI asks to do something
02Checkidentity · authority · risk · evidence
03Explain + decideallow · approve · escalate · block
04Execute + monitor + recordlimited authority · live oversight · audit
EXAMPLE 01

Updating a live system

An AI asks to change production. Fresh Direction checks the target, authority, likely impact and rollback position before any write access is issued.

EXAMPLE 02

A webpage contains hidden instructions

Fresh Direction treats external content as untrusted data. A webpage, email or document cannot silently become authority for the AI.

EXAMPLE 03

Several AI agents work together

Each permission may look harmless alone. Fresh Direction also checks their combined authority so separate agents cannot quietly assemble enough access to create a higher-risk capability.

EXAMPLE 04

An approved action changes

If the target, scope, credential, tool, purpose or behaviour materially changes, the previous approval no longer silently carries forward. The action can be paused, revoked or escalated.

WHY ENFORCEMENT MATTERS

These are not only theoretical risks.

Documented incidents show both sides of the problem: AI systems can find routes beyond intended containment, and humans can deliberately use AI agents to accelerate real attacks. Fresh Direction is designed to govern the point where capability becomes consequence.

DOCUMENTED INCIDENT

Containment escape reached real external infrastructure

During cybersecurity evaluations, AI agents circumvented intended isolation and reached real third-party systems. The lesson is simple: telling an AI that a boundary exists is not the same as technically enforcing that boundary.

OpenAI incident report →
DOCUMENTED INCIDENT

AI agents accelerated a real enterprise intrusion

Security investigators documented a human-directed attack in which multiple AI agents handled substantial parts of reconnaissance, credential access and intrusion activity in parallel. The lesson is that governance must cover authorised AI capability as well as unintended AI behaviour.

Unit 42 investigation →
See how the Governor works →
01 · RequestThe AI proposes an action, target, purpose and supporting evidence.GOVERNED
02 · Identity + authorityThe Governor identifies the agent, human or system principal, delegation chain, current permissions and authority ceiling.GOVERNED
03 · Untrusted inputWebpages, email, documents, tool output and other agents' messages are treated as data by default, not as new authority.GOVERNED
04 · Constitution + policyNon-negotiable constitutional rules and the organisation's policy are checked before execution authority can exist.GOVERNED
05 · Cumulative riskThe Governor assesses the combined effective authority of agents, credentials, tools and delegated permissions, not only each request in isolation.GOVERNED
06 · Independent evidenceImportant claims are checked against evidence that is not controlled solely by the AI asking for permission.GOVERNED
07 · DecisionThe outcome can be Allow once, Batch Allow, Human Approval, Escalate or Block. High-risk actions are not bulk-approved.GOVERNED
08 · Human reviewThe dashboard shows a short plain-English reason and likely consequence, with detailed evidence available when needed. Only the highest human authority can downgrade risk.GOVERNED
09 · Scoped authorityAny approval is purpose-bound, target-bound and time-limited. Highest-authority standing approvals remain bounded and cannot override constitutional prohibitions.GOVERNED
10 · Controlled executionThe action crosses the governed Tool Gateway using only the authority required for that approved task.GOVERNED
11 · Live monitoringTool use, network access, credentials, data access, agent coordination and scope are monitored while the action is running.GOVERNED
12 · Intervene + recordMaterial deviation can trigger deny, pause, isolation, revocation or escalation. The decision, evidence and outcome are preserved and temporary authority expires.GOVERNED
View technical architecture →
  • Constitution Engine — signed, non-negotiable rules above model output and ordinary policy.
  • Model Adapter + Decision Gateway — provider-neutral request normalisation into the mandatory governance path.
  • Agent Passport + Delegation Ledger — attributable identity, purpose, authority ceiling, expiry and delegation chain.
  • Capability Manager + Cumulative Authority / Swarm Risk — least privilege plus combined-authority assessment across multiple agents and tools.
  • Untrusted-Input Firewall — external content is data by default and cannot silently grant instruction authority.
  • Evidence & Policy — provenance, freshness, conflict checking and evidence independent of the requesting AI.
  • Hard Tool Gateway + circuit breakers — governed execution with deny, pause, isolate, revoke and safe-state controls.
  • Signed audit evidence — durable, append-only decision and outcome records outside the supervised AI's control.
  • AI Control Room — human-readable decisions first, with deeper forensic evidence available for advanced review.
  • Signed agent supply chain + graduated autonomy — approved models, tools and agent definitions with evidence-led progression from observe to constrained execution.

Core rule: no supervised AI may possess enough standing authority to defeat its own supervision. The Governor evaluates effective authority, not merely individual actions.

ENGINEERING FOUNDATION

Built from a working supervision system, not a blank-sheet governance concept.

Fresh Direction began as a read-only supervisor for a multi-system automated trading environment. That reference implementation forced evidence integrity, reassessment, recovery, drift detection, controlled promotion and audit to work against real system state.

The provider-neutral Governor now extracts those supervision disciplines into a separate constitutional control architecture for AI systems, agents and automations.

View the original proving ground →
ENGINEERING EVIDENCEINTERNAL VERIFICATION · ACTIVE DEVELOPMENT

The original Fresh Direction reference supervisor recorded 423/423 root regression passes after architecture completion. The current Governor passes 225/225 internal tests and 225/225 clean-room internal qualification tests. Six remediation phases are complete, and the latest post-audit remediation reports no Critical or High findings outstanding within the tested internal scope. These are HelpfulCo internal engineering results, not external certification. The Constitution remains NOT ACTIVATED and privileged operation remains disabled while representative-environment testing, production provisioning, acceptance and external validation continue.

  • Provider-neutral Model Adapter boundary between AI providers and the Governor
  • Evidence ledger with provenance and integrity
  • Assessment, reassessment and transparent baselines
  • Business-outcome supervision
  • Default-deny authority and capability boundaries
  • Audit, replay and post-action verification
  • Degraded-state and safe-operation controls
  • Constitutional package integrity and amendment safety
  • Fail-closed release verification for missing, altered or inconsistent constitutional artefacts
AI CONTROL ROOM

The dashboard is the operational surface of Fresh Direction.

The Control Room exposes supervised systems, incoming requests, supporting evidence, decisions, outcomes, incidents, policy state and security controls. It is designed to show why a request or system is healthy, challenged, blocked or approved — not just display a status colour.

AI EstateSystems, current state, expected-outcome success, actions, cost, exceptions and critical incidents.CONTROL ROOM
System ViewReliability, latency, cost, baselines, permitted actions, dependencies, tools and supporting evidence.CONTROL ROOM
Incident ViewDetection, severity, affected runs, baseline versus observed behaviour, evidence, decision, resolution and verified recovery.CONTROL ROOM
Credential SecurityPassword, API-key and secret lifecycle: exposure/expiry, approval, rotation state, recovery proof and service-health verification.GOVERNED
MANDATORY DECISION PATH

Every consequential request crosses independent control gates.

01

Request + adapter gate

A model or agent request enters through the provider-neutral Model Adapter with its action, target, justification and supporting evidence. Provider-specific communication stays outside the constitutional core.

02

Governor decision gate

Constitution, capability, evidence, policy and risk are checked independently. Missing, stale or contradictory evidence can be challenged before the request is allowed, denied or escalated.

03

Approval + execution

Where approval is required, the operator receives an evidence-rich review. Approved actions then receive short-lived, single-purpose authority before governed execution and post-action verification.

CONSTITUTIONAL GOVERNOR

Reasoning, model communication, authority and execution are separate control functions.

A supervised model or agent submits a request with its justification and evidence through the Model Adapter Layer. The Governor does not grant the model direct authority and can challenge insufficient evidence before deciding to allow, deny or escalate the request. Where human approval is required, the Decision Centre presents the evidence before any scoped execution authority is issued. Real-world actions then cross the governed Tool Gateway and are independently verified. Any direct model-to-execution bypass is a security defect.

01AI requestaction, target, justification, evidence
02Model Adapterprovider-neutral normalisation
03Governor decisionchallenge · allow · deny · escalate
04Approve · execute · verifyhuman where required · scoped Tool Gateway
IMPLEMENTATION GATE

Internally verified core. Human workflow and operational proof next.

C1

Governor core

The provider-neutral governance core separates model communication, reasoning, evidence, policy, authority, execution and independent verification behind fail-closed controls.

C2

Security remediation

Six remediation phases have hardened constitutional release, trusted authority, Tool Gateway execution, evidence, authoritative persistence, remote trust and recovery.

C3

Internal verification baseline

225/225 Governor internal tests and 225/225 clean-room internal qualification tests pass at the current engineering baseline. Post-audit remediation reports no Critical or High findings outstanding within the tested internal scope; the Constitution remains NOT ACTIVATED.

C4

Operator workflow

Next-stage development is focused on the Decision Centre, evidence-rich human review, bulk decision handling, reclassification and escalation workflows.

C5

Operational proof

Representative-environment demonstration, production provisioning, protected operational credentials, real-workflow failure injection, acceptance testing and external validation remain required before any production-ready or TRL 6 claim.

ENGINEERING STATUS · TECHNOLOGY READINESS

Current assessment: TRL 5 — active R&D

HelpfulCo currently assesses Fresh Direction at TRL 5. The integrated Governor is being validated through controlled regression, security and failure-mode testing against representative workflows. A future TRL 6 claim would require repeated integrated demonstration in a representative environment, including governed tool requests, evidence-rich human approval, recovery, reconciliation and audit. Fresh Direction is not presented as production-ready or independently certified.

FRESH DIRECTION

Evidence before confidence. Authority before execution.

AI can reason. Fresh Direction controls what is actually allowed to happen.