Clone & install
cd agent-trust-gate
npm ci
The ATG public repository is designed to let technical reviewers see what is implemented, what refuses, what remains synthetic and where the production boundary sits.
The shortest technical route is deliberately simple. From a fresh clone, install dependencies and run the compact reviewer sequence. It exits non-zero if a required invariant fails.
Runs the compact fixed-fixture reviewer sequence and outcome-derived scorecard.
These are deterministic local demonstrations using fictional identities, permissions and transactions. They are built to show both successful and refused outcomes.
Inspect identity-control evidence, accountable principal, delegation, limits, expiry, revocation, counterparty and standing handoff into GatePass evaluation.
Open Agent Standing demo →Inspect active identity, authority limits, self-approval restrictions, second approver policy, changed action, expiry, replay and dual-human approval.
Open Human Authority demo →Review Agent Standing, mandate, evidence, Verified Human Authority, GatePass, refusal and execution-receipt relationships.
Open control model →ATG keeps the commercial story attached to inspectable technical material. The evidence below is public and intended to support challenge rather than prevent it.
GatePass and execution-receipt schemas define machine-readable proof structures.
Browse schemas →Round-trip threat modelling and reviewer limitations document failure boundaries and assumptions.
Read threat model →Public mapping to the OWASP Agentic Top 10 provides control-oriented reviewer context without claiming certification.
Open mapping →Identity and authorisation reference material connects the demonstrator to relevant NIST concepts.
Open NIST map →The commercial route is published alongside explicit constraints on scope, access and production claims.
Review pilot boundary →The mission register preserves development history and helps reviewers understand how the architecture evolved.
Open mission register →ATG treats expected refusal scenarios as successful test outcomes only when the observed result actually refuses the unsafe action. The demonstrator includes changed-action, expiry, replay, exceeded-authority and other negative paths because a trust gate that only demonstrates approval is not much of a gate.
Expected refusals count as success only when the system actually refuses.
That sounds obvious. In AI demonstrations it is worth making explicit.
A professional technical site should be as clear about absences as capabilities. ATG currently makes no claim of production readiness, adoption or certification.
No real external tool, payment, settlement, checkout, live agent interception or autonomous financial action is executed.
The public demonstrations use fictional/synthetic material and no production credentials or private enterprise datasets.
Public evidence is review material, not a legal, security, regulatory, procurement or safety assurance certificate.