NAOS / CONTROL BOUNDARYINITIALIZING CONTROL PLANE
00%
AGENT ACTION CONTROLVERIFIABLE EVIDENCE
NAOS / CONTROL BOUNDARY
AGENT ACTION CONTROL + VERIFIABLE EVIDENCE

AI CANACT.

THE QUESTION CHANGED

The model is no longer only generating an answer. It can now change the system behind the screen.

Naos controls AI agent actions before execution and creates verifiable evidence after.

TOOL CALL / github.delete_repository
NAOS / BOUNDARY
DENYBEFORE EXECUTION
SIGNED EVIDENCENOT EXECUTED
ROOTSHA-256
SIGNED25519
TIMERFC 3161
MCP INLINE CONTROL
SHADOW / ENFORCE · OFFLINE VERIFICATION
HOW THE BOUNDARY WORKSACT · DENY · PROVE
AGENTTOOL CALL
→
NAOSPOLICY
×
SYSTEMNOT EXECUTED
TAKE 01 / ACTION

The agent wants to act.

The request carries real permission. It can change a real system.

TOOL CALLgithub.delete_repository
TAKE 02 / DECISION

The request meets a boundary.

Naos evaluates the MCP tool-call before execution. The target system is never touched.

POLICYrepo-destructive-actions/v3DENY
TAKE 03 / EVIDENCE

The decision becomes proof.

The decision is sealed into an independently verifiable artifact.

PROOFED25519 · RFC 3161 · SHA-256
BOUNDARY STATE
ACTION REQUEST
ACT
DENY
PROVE
TAKE 01 / ACTION

The agent wants to act.

The request carries real permission. It can change a real system.

TOOL CALLgithub.delete_repository
TAKE 02 / DECISION

The request meets a boundary.

Naos evaluates the MCP tool-call before execution. The target system is never touched.

POLICYrepo-destructive-actions/v3DENY
TAKE 03 / EVIDENCE

The decision becomes proof.

The decision is sealed into an independently verifiable artifact.

PROOFED25519 · RFC 3161 · SHA-256
01 / ACTACTION REQUEST
01 / REQUESTagent forms an action request
CONTROL BOUNDARY / SYSTEM STUDYOne request. One decision. One proof artifact.

Do not trust the dashboard.
Verify the artifact.

A dashboard asks you to trust the vendor. A proof artifact can be checked independently. Change one field and verification fails.

TAMPER ONE FIELD / PROOF REACTS LIVE
{
"agent": "build-agent-07",
"tool": "github.delete_repository",
"decision": "DENY",
"policy": "repo-destructive-actions/v3",
"event_root": "8d61…c4a2",
"signature": "ed25519:4f9e…17b0"
}
VERIFICATIONVALIDsignature + timestamp verified

Evidence you can hand to someone else. The same signed artifact can be independently verified by your auditor, legal team or insurer — without relying on the Naos dashboard.

PRODUCT TRUTH

What is live.
What is not.

Naos separates enforceable control from visibility and partial provider actions.

NO BLURRED CLAIMS
LIVE01

MCP gateway

Inline policy enforcement before MCP tool execution.

CONTROL BEFORE EXECUTION
LIVE02

Proof

Ed25519-signed artifacts, RFC 3161 timestamping and offline verification.

INDEPENDENT EVIDENCE
OBSERVE03

Copilot / ChatGPT / Claude

Detection and logging are available. Inline blocking is not represented as live.

VISIBILITY, NOT INLINE CONTROL
PARTIAL04

SaaS provider actions

Local Naos control exists. Provider-side administrative actions remain outside the live claim.

PROVIDER BOUNDARY
If Naos cannot enforce it today, this page says so. THE BOUNDARY IS THE PRODUCT.

Start in shadow mode.

One non-critical workflow is enough to understand how the agent acts, where policy belongs and what evidence Naos leaves behind.

No production-wide rollout. One agent. One workflow. Start in shadow mode, learn, then enforce deliberately.

Two teammates reviewing a low-risk AI workflow together during a shadow pilot
01

Bring one real workflow

Choose an agent that already has permission to touch a real system.

02

Observe before enforcing

See actions, decisions and proof without blocking production.

03

Enforce deliberately

Turn on inline control only where the policy is explicit.

ONE QUESTION / QUALIFICATION

Do you have one agent with real permissions?

That's enough to start.

Run a shadow pilot ↗