Control and evidence infrastructure
Give agentsroom to work.
Fulcrum checks actions routed through it against your rules before the tool runs. Disallowed actions do not proceed.
Evidence covers captured decisions, not every action.
Intent is not authority.
A decision before the tool call.
- 01RoutedAn agent prepares an action through a configured route.
- 02EvaluatedFulcrum applies the relevant policy, budget, approval, and trust checks.
- 03DecidedThe outcome is allow, deny, or escalate, decided before the tool executes.
- 04RecordedCaptured decision context stays available for team review.
For routed actions, evaluation happens before forwarding. This drawing explains the mechanism. It is not captured traffic.
See the denial happen before the write.
This recorded session reads tainted GitHub issue content, evaluates a write to a private repository, denies it before the upstream call, emits a decision record, then verifies the integrity of that same record.
Fixture mode: no credentials, no network, no live repository change, and no deployment-topology validation. Direct upstream access remains a bypass unless operators remove it.
GitHub lethal-trifecta demo status: pass fixture-only: true credentials: none network: none live mutation: none tainting context: github.issue_body via github.get_issue -> session tainted proposed tool: github.create_or_update_file -> fixture-org/fixture-private-repo (private, private_repo_content_write) expected action: DENY actual action: DENY reason: lethal_trifecta_detected matched rule: deny-github-write-after-taint-fixture upstream_called=false read_upstream_called=true decision record id: rec_a0fec7d8fb1d decision hash: sha256:a0fec7d8fb1da137e1781812f251ccec0261dcbf98a4927390ffcbdfa8f7b5d1 Checks: - [pass] inventory_fixture_loads: github_servers=1 - [pass] risk_graph_detects_path: repo_write_paths=2 - [pass] starter_policies_verify: files=6 rules=12 - [pass] secure_github_fixture_setup: fixture profile and policy artifacts written - [pass] redteam_denies_scenario: actual_action=DENY - [pass] write_denied_before_upstream: upstream_called=false - [pass] decision_record_emitted: rec_a0fec7d8fb1d record verification: ok record_id: rec_a0fec7d8fb1d
What the record shows
- The covered fields match the stored decision hash.
- The captured context of this one routed decision.
- The fixture reports the upstream write was not called: upstream_called=false.
What it does not establish
- That the verdict itself was correct.
- That all governed traffic was captured, or that the route cannot be bypassed.
- Who produced the record. That needs signature verification and trusted key custody.
- Legal admissibility, certification, or independent witnessing.
Recorded session · Boundary v0.11.0 · commit a394488 · 2026-07-03 UTC. Historical fixture capture. The current Boundary release is v0.13.1. This is not current-release or live-deployment evidence.
The record stays with the decision.
Operators read the capture. Platform teams read the sequence. Audit reads the fields. Risk reads the schedule. Every view below renders the same record: rec_a0fec7d8fb1d.
decision record id: rec_a0fec7d8fb1d decision hash: sha256:a0fec7d8fb1da137e1781812f251ccec0261dcbf98a4927390ffcbdfa8f7b5d1 tainting context: github.issue_body via github.get_issue -> session tainted proposed tool: github.create_or_update_file -> fixture-org/fixture-private-repo (private, private_repo_content_write) expected action: DENY actual action: DENY reason: lethal_trifecta_detected matched rule: deny-github-write-after-taint-fixture upstream_called=false read_upstream_called=true record verification: ok
Lines from the recorded transcript and the verify pass, verbatim.
Order from the recorded transcript. Bar lengths show order, not duration; the capture carries no timings.
- Record
- rec_a0fec7d8fb1d
- Verdict
- DENY
- Matched rule
- deny-github-write-after-taint-fixture
- Reason
- lethal_trifecta_detected
- Proposed tool
- github.create_or_update_file
- Target
- fixture-org/fixture-private-repo
- Upstream called
- false
- Verification
- ok · unsigned, covered fields
- Captured
- 2026-07-03 UTC
- Binary
- Boundary v0.11.0 · a394488
An unsigned pass shows covered fields match the stored hash. Changed fields with a recomputed hash can still pass. Authenticity needs signature verification and trusted key custody.
| Captured (UTC) | Route | Proposed action | Target | Verdict | Rule | Upstream | Record |
|---|---|---|---|---|---|---|---|
| 2026-07-03 | Secure GitHub fixture | create_or_update_file | fixture-private-repo | DENY | deny-github-write-after-taint-fixture | not called | rec_a0fec7d8fb1d |
| — | — | — | — | — | — | — | — |
One row per captured decision, in a layout a spreadsheet opens. This schedule holds the one recorded fixture and nothing else.
The agent can prepare the claim without authority to change its outcome.
In this example, a claims assistant reads the file, drafts a recommendation, and proposes an outcome update. The routed write is denied because the configured policy does not allow this assistant to make final claim changes.
- ALLOWReads the claim file.
- ALLOWDrafts a recommendation.
- DENYProposes the final outcome update.
Denied. No claim update was sent on this path.
Illustrative workflow. No claim system is connected and no action is executed here.
Using Boundary? Here is where Fulcrum fits.
Boundary and Fulcrum work on the same routed-action problem at different layers. Boundary is available now. Fulcrum is the prelaunch management platform.
Boundary
Open source · Apache-2.0 · v0.13.1Boundary is the OSS action boundary for routed agent tools.
It decides routed tool calls at configured connections and keeps local decision records you can verify. Each adapter documents its own readiness.
Fulcrum
PrelaunchA shared platform for policies, budgets, approvals, and captured decisions across routed agent actions.
The waitlist sends availability notices only. It does not grant access, onboarding, or enrollment.
Manage Fulcrum from your terminal.
We are building Fulcrum so every management workflow can run through the CLI or an authorized agent, with the dashboard as another way to work.
Complete CLI and agent management is in development.
Formal proof core for scoped governance guarantees.
Machine-checkable
Fulcrum has a formal proof core with machine-checkable Lean 4 proofs.
Theorem status is read from the pinned theorem inventory.
Zero-sorry
First-party Lean proofs are zero-sorry for the scoped theorem portfolio.
Zero-sorry does not mean zero assumptions or zero axioms.
Trust termination
Trust circuit breaking has a formal termination claim under sustained failure, scoped to the Beta trust model and stated threshold assumptions.
The proofs cover model properties under stated hypotheses. They are checked offline and do not verify runtime behavior. Source: Fulcrum-Proofs, Lean 4, public tag v0.3.0.
Paper: A Bounded, Machine-Checkable Governance Kernel for Trust-Gated Agent Execution (Zenodo, 2026)Stop the action.Keep the proof.
Controls apply to actions routed through Fulcrum or Boundary. Evidence covers captured decisions, not every action.
Get notified when Fulcrum opens to new teams.