Skip to main content
EMILIA Authority Brain · Local-first

See where your AI can act. Put a human in control before it matters.

Discover the declared actions your scanner can see. Review the proposed Authority Map. Put customer-controlled Gate in front of one consequential action. Preserve evidence without sending your code, credentials, or policy to us.

The scanner proposes. The owner reviews. Gate enforces.
Authority topologyIllustrative
MCP toolsOpenAPIUnknownOWNERREVIEWGateEvidence
Visible surface Owner decision Blind spot
One operating loop

Discover → Map → Protect → Prove

One local path from visibility to a customer-owned refusal boundary. Discovery never silently upgrades itself into an enforcement claim.

  1. 01

    Discover

    Enumerate the declared MCP and OpenAPI action surfaces the local scanner can actually see.

  2. 02

    Map

    Propose consequence classifications, exact material fields, confidence, and blind spots; authority source remains an owner decision.

  3. 03

    Protect

    For a reviewed MCP surface, generate the scaffold and place Gate at one credential-owning executor boundary.

  4. 04

    Prove

    Refuse insufficient authority, consume accepted authority once, and preserve portable evidence under customer-pinned rules.

SYNTHETIC LOCAL DEMO

Authority Map / declared surfaces

Static fictional inputs. This hosted page has not scanned your device, connected to your systems, blocked production, or detected fraud.

Browser-only simulation · no external effect
Visible actions4synthetic records
Review required3owner decision
Pass-through1proposal only
Visibility gaps1no judgment
02 / Inspect proposal

Release wire transfer

Review required

Moves funds to an externally controlled beneficiary account.

Authority source
Not established by static scan — owner review required
Assurance
Proposed receipt · class_a
Category
money_movement.release
Confidence
medium
Required exact fields
action_typeamount_usdcurrencypayment_instruction_idbeneficiary_account_hash
Named blind spots
  • Direct provider API paths and alternative payment rails are not visible in this declaration.
  • Whether production credentials are isolated behind Gate is not established by a scan.
03 / Synthetic proof path

From proposal to portable evidence

  1. 01
    Scan proposal

    The synthetic declaration produced a proposed disposition and named its blind spots.

  2. 02
    Human review

    A fictional owner accepts the material fields and required authority for this demonstration.

  3. 03
    Synthetic refusal

    A local mock call without authorization is refused before its supplied handler runs.

  4. 04
    Exact-action approval

    A synthetic approval artifact binds the selected action and exact field values.

  5. 05
    One-time execution

    In-memory demo authority is consumed once. No external provider or production system is touched.

  6. 06
    Portable evidence

    A synthetic evidence packet records the bounded demo result without claiming production enforcement.

Current synthetic stateScan proposal

The synthetic declaration produced a proposed disposition and named its blind spots.

Synthetic packet preview
{
  "artifact": "EP-SYNTHETIC-AUTHORITY-DEMO-v1",
  "selected_action": "releaseWire",
  "result": "pending",
  "handler_invoked_without_authority": false,
  "authority_consumed_once": false,
  "visitor_environment_scanned": false,
  "production_enforcement": false
}
This proves only the browser simulation shown here. Production prevention requires a completely mediated Gate, durable shared state, pinned trust roots, credential custody, and deployment-specific verification.
Deliberately bounded

The unknowns stay visible.

Authority Brain reduces the cost of finding and reviewing declared action surfaces. It does not turn incomplete visibility into a safety score.

What the local product can establish

  • Which supported declared actions were visible to this scan
  • Why a consequence classification was proposed
  • Which exact fields and authority sources require owner review
  • Whether a supported local synthetic refusal kept its mock handler from running

What remains a deployment question

  • Whether every consequential path reaches the same Gate
  • Whether provider credentials are unavailable through another path
  • Whether production state, keys, policy, and approvers are configured correctly
  • Whether external effects occurred beyond the evidence an observer can verify
Start with the free local product

Map one declared action surface.

The generated dashboard uses no account, upload, telemetry, or remote asset. When invoked through npx, npm may download the package before scanner startup. The scan itself launches no configured server.

TerminalLocal command
npx @emilia-protocol/scan brain ./tools.json
 
Authority Brain — Map and Protect AI Agent Actions | EMILIA