Skip to main content
EMILIA GATE · THE CONSEQUENCE FIREWALL

Put a refusal boundary in front of consequential machine action.

Protocol proves. Gate prevents.

On a configured, exclusively mediated path, EMILIA Gate sits immediately before protected execution. Before money moves, infrastructure changes, regulated records update, or irreversible state changes, Gate verifies the exact authority and evidence the resource owner requires, consumes accepted authorization once, and records the result.

On a fully mediated path, missing, stale, mismatched, or replayed evidence never reaches mutation. The open Protocol lets the relying party reproduce why the exact action passed or failed under its own pinned trust inputs.

Open Gate referenceFind bypassed effectsOpen reference control planeHow it worksWhere it integratesTry to break itCF-1 conformanceRequest pilot
THE INVARIANT

If the required evidence does not verify, the protected system does not mutate.

The gate is deployed by the resource owner — the bank, the cloud API, the database, the robot controller, the grid. An agent that wants to act must present the mandate and evidence the owner requires for that exact work. The guarantee is only as strong as that mediation: every protected path must reach Gate at the actual system of record or actuator. Verification itself is open and can run offline without an EMILIA service.

Gate Qualification v2 · public experimental implementation profile

Carry accepted evaluation evidence without turning it into execution authority.

Gate Qualification v2 converts accepted evaluation evidence into a portable, time-bounded qualification for one exact measured candidate and assignment. The qualification stays bound to its campaign, current status, runtime measurement, assignment, policy, and protected request.

Qualification travels. Authorization stays local. Gate controls the consequence.

Qualified

The accepted campaign graph and current measurement match this exact candidate, assignment, policy, and request.

Authorized

The resource owner separately requires AEB and AEC evidence, then applies local policy to decide whether this exact action may proceed.

Admitted

Gate atomically reserves the operation and consumes one-time authority before the protected adapter can enter the provider.

Qualification is not authorization, certification, deployment evidence, or proof of a successful effect. A QUALIFIED result is evidence the local Gate may require; it cannot reserve resources, call a provider, or establish that an action is wise, legal, or safe.

RELIANCE RISK PLANE · GATE 0.20.0

Bound unresolved exposure without turning risk evidence into authorization.

Gate now carries customer-owned responsibility terms, declared open exposure, exact technical refusals, and bounded loss evidence alongside the existing authorization lifecycle. Each artifact stays a separate evidence leg under the relying party’s pinned program and authorities.

RP policy · loss schedule

The relying party pins a separately signed loss-allocation schedule to the exact Reliance Program as an admissibility-profile policy input. The schedule never authorizes execution.

Open Exposure Ledger

Before provider invocation, the durable ledger atomically reserves declared exposure against configured ceilings. INVOKING and INDETERMINATE stay open until independent reconciliation.

Exact-action refusal

A signed statement binds the technical refusal to the exact action, failed requirements, challenge, nonce, custody, and time. It is not a legal or adverse-benefit denial.

Coverage attestation

A bounded-period attestation signs the supplied system-of-record and receipt roots, counts, joins, exceptions, and uncertainty. It does not prove that either population is complete.

Receipt census + loss feed

Governed aggregate receipt buckets use coarse primary suppression. Signed loss-experience records preserve external provenance and correction lineage without becoming adjudicated losses.

The boundary: EMILIA does not insure, bear or allocate loss, adjudicate disputes or losses, establish legal enforceability, prove coverage, causation, solvency, or population completeness, or move money.

Inspect the executable claim →Read the architecture contract →
PROOF IN ONE COMMAND

The product is the refusal sequence.

A dangerous action is not argued with. It is challenged, verified, bound to real execution fields, consumed once, and turned into a reliance packet. The demo runs locally with generated keys; no EMILIA server is trusted.

node packages/gate/demo.mjs

# output:
# release_payment, no receipt       -> REFUSE 428 (receipt_required)
# release_payment, observed drift   -> REFUSE 428 (execution_binding_failed)
# release_payment, class_a + bound  -> ALLOW
# same receipt again                -> REFUSE 428 (replay_refused)
# reliance packet                   -> RELY
read_status
passes through
release_payment, no receipt
428 Receipt Required
software receipt
refused; needs Class A
valid receipt, observed drift
refused; field binding failed
Class A + bound fields
runs
same receipt again
replay refused
tampered amount
signature rejected
WHAT IT GATES

Default packs for high-risk action families.

This is not just an amount threshold. EMILIA Gate treats entire action categories as high risk and binds the material system-of-record fields for each category.

payment.release
Class A
Money movement
Release payment, wire transfer, treasury disbursement
payment.bank_details.change
Class A
Bank-detail change
Vendor, beneficiary, payroll, or payout destination update
deploy.production
Quorum
Production deploy
Deploy, migration, secret rotation, production config
permission.admin.change
Quorum
Permission change
Admin grant, role expansion, privileged scope change
data.export
Class A
Sensitive data export
Bulk customer, claims, patient, citizen, or employee data export
record.delete
Class A
Record deletion
Delete or destroy system-of-record state
regulated.decision.override
Quorum
Regulated override
Benefit, credit, clinical, compliance, or safety decision override
ONE AUTHORITY PROFILE · RECEIPT REQUIRED

Request → challenge → sign → verify → execute → proof.

When a mandate requires a fresh exact-action human or quorum decision, Gate can run this approval loop. It is one supported profile, not a requirement that every action receive a new human click; bounded mandates can authorize unattended work inside their finite scope.

1
Request
An agent or system requests a consequential action at the actuator boundary.
2
Challenge
If the action is guarded and no valid receipt is present, the gate returns 428 Receipt Required and tells the agent exactly what to bring.
3
Authorize
A directory-bound approver — or a quorum, for hard cuts — signs the exact action on an enrolled device-bound authenticator.
4
Verify
Offline, fail-closed: any required current qualification, authority (pinned key), action-binding, assurance tier, freshness, and one-time consumption — no trust in the operator.
5
Execute
Only a passing check reaches the actuator. Deny by default; absence of a receipt is the anomaly, not the default.
6
Execution receipt
On execution the gate emits proof bound to the exact authorization decision — the artifact an auditor, regulator, or incident review replays.

Assurance tiers set the floor per action: softwareA valid receipt — a software-held key. class_aA device-bound human signoff (WebAuthn / passkey). quorumm-of-n distinct humans — the cryptographic two-person rule.

THE COMPLETE SYSTEM

Gate enforces. The surrounding layers keep authority bounded, open, and reproducible.

Approver AppsLock the human decision to the exact CAID, show material revisions, and track the consequence without blind replay.Action EscrowKeep document execution, exact release approval, custodian state, and one-time consequence control as separate verifiable rows.EMILIA ProtocolDefine the portable evidence and open verification rules beneath Gate.Assurance PlaneRe-perform exact-action evidence, conformance results, and stated formal-model scope; record drift and prepare the technical handoff.
COMPOSE, DON'T REPLACE

A distinct job at each control layer.

AgentROA governs calls. ORPRG proves policy permitted the effect. EMILIA verifies the exact authority and any required approver evidence under the relying party’s pinned rules, then controls admission at covered consequence boundaries.

Evaluation qualification
Gate Qualification v2
Does accepted evaluation evidence still match this exact measured candidate, assignment, and protected request?
Call governance
AgentROA
Does the call remain inside the agent’s verified delegated scope?
Policy permit
ORPRG
Does the native policy evidence prove this effect was permitted?
Exact authority + control
EMILIA
Does the mandate and any required approver evidence authorize this exact action, and may the protected executor mutate now?

EMILIA does not collapse machine delegation, machine policy, and human authorization into one verdict. CAID can correlate their native action descriptions only under the exact mapping profiles the relying party pins. A match is not authorization, and a missing or lossy mapping returns INDETERMINATE instead of guessing.

A QUALIFIED decision can satisfy only the qualification leg of Gate composition. Local authorization, atomic admission, provider entry, and effect evidence remain separate decisions.

THE PRODUCT API

One ordered path: reserve, execute, commit, prove.

`gate.run()` makes the ordering hard to get wrong. It reserves the receipt while the action is in flight, commits one-time consumption only after success, releases on pre-mutation failure, and returns the reliance packet.

Gate's experimental recovery developer surface follows buyer policy before execution. The reference scaffold demonstrates a mocked PostgreSQL transaction-control trace; it does not establish database mutation, durability, or sandbox confinement. After a provider may have acted but the result cannot be established, Gate consumes the reservation as indeterminate: no blind retry or refund. Any remedy is a new, separately authorized action. Remote compensation is a reserved-capacity building block, not a guarantee that an external effect can be reversed.

import { createTrustedActionFirewall } from '@emilia-protocol/gate';

const gate = createTrustedActionFirewall({
  trustedKeys: [process.env.EMILIA_ISSUER_PUBKEY],
  store: sharedConsumptionStore,
});

const observedAction = await paymentSystem.describeRelease('pi_123');

const out = await gate.run({
  selector: { protocol: 'mcp', tool: 'release_payment' },
  receipt,
  observedAction,
}, () => paymentSystem.release(observedAction));

if (!out.ok) return out.body; // 428 Receipt Required
return out.packet;            // auditor-ready reliance artifact
428 challenge
Missing or bad receipt never reaches the mutation.
Observed fields
Executor binds facts from the real system, not the request body.
Execution record
The post-action record commits to the authorization decision and reported outcome; it is not physical proof of effect.
Reliance packet
Reproducible technical record with checks, evidence head, and limitations.
LOCAL AUTHORITY ENGINE · PRIVATE ALPHA

Authorize a bounded mission once. Let agents operate locally inside it.

A human signs the permitted action classes, targets, time window, and typed limits. The local engine checks each exact action against that program before the credential-owning adapter can act.

Finite by construction

Child authority transfers from the signed root; it is never copied into an unlimited fleet credential.

AI can only tighten

Risk signals may reduce budgets, require review, suspend, or refuse. They cannot widen human-granted authority.

No blind retry

A lost provider result becomes INDETERMINATE and stays closed until authenticated reconciliation.

Current boundary: a private, single-host alpha for governed pilots. It makes no complete-mediation or customer-deployment claim; only actions forced through its adapter receive this control.

Design a bounded-authority pilot →
RECEIPT PROGRAMS

The instruction, delegated budget, effect, and terminal evidence stay bound.

The receipt-program kernel freezes one CAID-bound action and stable operation ID, executes it through Gate's real bounded-capability path, and signs and records a content-addressed certificate over the bounded result and Gate evidence. It is a developer surface behind the Consequence Firewall, not a second policy engine or ledger.

Provider deadline expiry, response loss, or invalid output becomes INDETERMINATE. The budget and operation remain closed to blind replay. Production requires durable capability state, an atomic evidence log, KMS/HSM signing, a pinned certificate context, and a pinned result projection. Signing or logging failure preserves the Gate outcome without claiming complete proof.

npm run demo:receipt-program

# Parent capability: 1000 USD -> delegated 100 USD
# CAID: recomputed from the exact payment action
# RECEIPT -> MATCH -> RESERVE -> EXECUTE -> COMMIT -> CERTIFY
# Child capability remaining: 50 USD
# Certificate: context-bound and present in the evidence log
What the certificate proves

Integrity and exact internal binding under a relying-party-pinned operator key and context, including CAID re-performance, action and operation identity, result digest, opcode sequence, authorization-to-execution linkage, and the complete certificate evidence record.

What it does not prove

It is not a ZK proof, consensus result, provider attestation, or proof of legal, physical, or commercial correctness. Full re-performance still verifies the referenced authorization, capability, and evidence records under independent trust inputs.

WHERE IT INTEGRATES

One Gate pattern, several integration boundaries.

MCP
Shipped
Agent tools
Wrap any MCP tool in one line (gateMcpTool); a dangerous call without a receipt returns 428.
API
Shipped
HTTP middleware
Express / Connect / Next / Go — protect POST / PUT / PATCH / DELETE.
FRAMEWORKS
Shipped
Agent runtimes
OpenAI, LangChain, CrewAI, AutoGen — guard tool calls in one wrap().
CLOUD
Shipped
Infra & platforms
System-of-record adapters shipped for GitHub, Stripe, Supabase/Postgres, AWS, Kubernetes, Terraform, GCP, Vercel, Cloudflare, Linear, Jira, and Salesforce.
ROBOTS
Reference
Actuator sidecar
A local daemon before motion/tool commands. Pre-authorize a bounded envelope; verify each act offline.
CF-1 / EG-1 CONFORMANCE

Does your integration actually enforce the gate — or are you just claiming it?

CF-1 is a public self-description, not a certification. EG-1 is the runnable Gate harness behind it: point the harness at your dangerous action; if it passes all eight checks, you have a reproducible conformance record instead of a claim. It makes an open PR crisp:“this makes delete_row earn EG-1 / CF-1.”

01
missing receipt → 428
02
software receipt on a Class-A action → refused
03
observed execution drift → refused
04
valid Class-A / quorum receipt → runs
05
same receipt replay → refused
06
tampered receipt → refused
07
execution proof binds to the authorization decision
08
reliance packet returns verdict: rely
node packages/gate/eg1.mjs

# EG-1 Conformance — does this integration ENFORCE EMILIA Gate?
#   PASS  missing receipt -> 428
#   PASS  software receipt on Class-A action -> refused
#   PASS  observed execution drift -> refused
#   PASS  valid Class-A/quorum receipt -> runs
#   PASS  same receipt replay -> refused
#   PASS  tampered receipt -> refused
#   PASS  execution proof binds to authorization decision
#   PASS  reliance packet returns verdict "rely"
#   ✓ EG-1 Enforced  (8/8)
EG-1 Enforced
Consequence Firewall: CF-1

Public definition: CF-1 Consequence Firewall conformance.

THE HONEST LIMIT

It does not stop every bad actor. It makes unauthorized paths visible and refusable.

A bad actor can build an unguarded machine. EMILIA Gate makes legitimate infrastructure refuse consequential actions that lack the authority evidence the resource owner requires — so parties with leverage can require an appropriate profile. It cannot constrain a path that bypasses Gate. Complete mediation requires the resource owner to place the verifier immediately before every protected mutation and to remove alternate execution paths. Necessary, not sufficient.

Verify a receiptRe-perform the evidenceRequest pilot
EMILIA Gate: Consequence Firewall for AI Agents | Product