Constitution Engine
Enforces signed non-negotiable rules above model output, policy and execution adapters.
Operational assurance for AI agents. Fresh Direction is an R&D-stage governance and control layer designed to assess, constrain, monitor and evidence AI-agent behaviour before consequential actions can affect real systems.
Provider-neutral architecture. Evidence-led decisions. Governed execution.
Enforces signed non-negotiable rules above model output, policy and execution adapters.
Normalises provider-specific AI requests into a standard evidence package before they enter the single mandatory governance path.
Applies default deny, least privilege, target scope, time limits and revocable authority.
Validates provenance, freshness, confidence and conflicts, and can challenge insufficient evidence before policy and risk decisions are made.
Binds consequential approvals to verified identity, exact action scope, target and expiry.
Governs password, API-key and secret rotation through prepare, validate, switch, verify and revoke stages.
Seals decision evidence, verifies outcomes and blocks consequential actions when critical controls degrade.
Operational dashboard for AI requests, evidence, decisions, estate health, incidents, policy state, credentials and verified outcomes.
423/423 root regression passes in the original Fresh Direction supervision proving ground. This is separate from the Governor test suite.
The current Governor passes 225/225 internal tests and 225/225 clean-room internal qualification tests. Six remediation phases are complete, with no Critical or High findings outstanding within the tested internal scope. External validation, representative-environment testing and production acceptance remain future work. The Constitution remains NOT ACTIVATED.
Observe → Advise → Approve → Bounded Enforce. No unrestricted autonomous mode in V1.
AI requests do not create authority. Model communication is normalised through the Model Adapter, and real-world execution requires independently issued, scoped authorisation through the governed tool boundary.
Fresh Direction separates AI reasoning from authority and execution. Provider-specific model communication is normalised through a Model Adapter before independent evidence, policy, risk and approval controls determine whether scoped execution authority can exist.
Capture AI events, system state, tool use, cost, latency and expected business outcomes as structured evidence.
Apply deterministic rules, transparent baselines, policy boundaries and evidence confidence to detect meaningful failure or drift.
Normalise model requests through a provider-neutral adapter, then apply capability, evidence, policy, risk and human-approval controls before execution authority exists.
Check the real downstream result, detect side effects and seal the complete decision and outcome chain into audit evidence.
Fresh Direction sits between AI and the real world. It lets AI think, plan and suggest actions, but before anything important happens it checks what the AI is trying to do, whether it has permission, what could be affected and whether a human needs to approve it.
The AI can think, plan and suggest an action, but the request does not automatically give it permission to affect a real system.
It checks who is asking, what they want to do, what could be affected, what evidence supports it and whether a human must approve it.
If the action is allowed, authority is limited to that purpose and Fresh Direction keeps watching while the action happens. Unexpected behaviour can be paused or stopped.
An AI asks to change production. Fresh Direction checks the target, authority, likely impact and rollback position before any write access is issued.
Fresh Direction treats external content as untrusted data. A webpage, email or document cannot silently become authority for the AI.
Each permission may look harmless alone. Fresh Direction also checks their combined authority so separate agents cannot quietly assemble enough access to create a higher-risk capability.
If the target, scope, credential, tool, purpose or behaviour materially changes, the previous approval no longer silently carries forward. The action can be paused, revoked or escalated.
Documented incidents show both sides of the problem: AI systems can find routes beyond intended containment, and humans can deliberately use AI agents to accelerate real attacks. Fresh Direction is designed to govern the point where capability becomes consequence.
During cybersecurity evaluations, AI agents circumvented intended isolation and reached real third-party systems. The lesson is simple: telling an AI that a boundary exists is not the same as technically enforcing that boundary.
OpenAI incident report →Security investigators documented a human-directed attack in which multiple AI agents handled substantial parts of reconnaissance, credential access and intrusion activity in parallel. The lesson is that governance must cover authorised AI capability as well as unintended AI behaviour.
Unit 42 investigation →Core rule: no supervised AI may possess enough standing authority to defeat its own supervision. The Governor evaluates effective authority, not merely individual actions.
Fresh Direction began as a read-only supervisor for a multi-system automated trading environment. That reference implementation forced evidence integrity, reassessment, recovery, drift detection, controlled promotion and audit to work against real system state.
The provider-neutral Governor now extracts those supervision disciplines into a separate constitutional control architecture for AI systems, agents and automations.
View the original proving ground →The original Fresh Direction reference supervisor recorded 423/423 root regression passes after architecture completion. The current Governor passes 225/225 internal tests and 225/225 clean-room internal qualification tests. Six remediation phases are complete, and the latest post-audit remediation reports no Critical or High findings outstanding within the tested internal scope. These are HelpfulCo internal engineering results, not external certification. The Constitution remains NOT ACTIVATED and privileged operation remains disabled while representative-environment testing, production provisioning, acceptance and external validation continue.
The Control Room exposes supervised systems, incoming requests, supporting evidence, decisions, outcomes, incidents, policy state and security controls. It is designed to show why a request or system is healthy, challenged, blocked or approved — not just display a status colour.
A model or agent request enters through the provider-neutral Model Adapter with its action, target, justification and supporting evidence. Provider-specific communication stays outside the constitutional core.
Constitution, capability, evidence, policy and risk are checked independently. Missing, stale or contradictory evidence can be challenged before the request is allowed, denied or escalated.
Where approval is required, the operator receives an evidence-rich review. Approved actions then receive short-lived, single-purpose authority before governed execution and post-action verification.
A supervised model or agent submits a request with its justification and evidence through the Model Adapter Layer. The Governor does not grant the model direct authority and can challenge insufficient evidence before deciding to allow, deny or escalate the request. Where human approval is required, the Decision Centre presents the evidence before any scoped execution authority is issued. Real-world actions then cross the governed Tool Gateway and are independently verified. Any direct model-to-execution bypass is a security defect.
The provider-neutral governance core separates model communication, reasoning, evidence, policy, authority, execution and independent verification behind fail-closed controls.
Six remediation phases have hardened constitutional release, trusted authority, Tool Gateway execution, evidence, authoritative persistence, remote trust and recovery.
225/225 Governor internal tests and 225/225 clean-room internal qualification tests pass at the current engineering baseline. Post-audit remediation reports no Critical or High findings outstanding within the tested internal scope; the Constitution remains NOT ACTIVATED.
Next-stage development is focused on the Decision Centre, evidence-rich human review, bulk decision handling, reclassification and escalation workflows.
Representative-environment demonstration, production provisioning, protected operational credentials, real-workflow failure injection, acceptance testing and external validation remain required before any production-ready or TRL 6 claim.
HelpfulCo currently assesses Fresh Direction at TRL 5. The integrated Governor is being validated through controlled regression, security and failure-mode testing against representative workflows. A future TRL 6 claim would require repeated integrated demonstration in a representative environment, including governed tool requests, evidence-rich human approval, recovery, reconciliation and audit. Fresh Direction is not presented as production-ready or independently certified.
AI can reason. Fresh Direction controls what is actually allowed to happen.