GateAgent GuardProtocolStandardsMCPGovGuardSovereigntyFinGuardQuorumDemoTry itVerifyPricingDocsRequest Pilot
EMILIA GOVGUARD

Pre-payment control for government fraud.

GovGuard catches the fraud path authentication misses: vendor payment destinations, disbursements, benefit routing, provider enrollment, and eligibility overrides changing inside valid sessions. High-risk actions get named human approval and a verifiable authorization receipt before money or regulated state moves.

For treasurers, controllers, program-integrity teams, and Inspectors General: your logs prove it to you. The receipt proves it to everyone else - auditors, insurers, regulators, and courts - without trusting your logs, your vendor, or EMILIA.

The Government Accountability Office estimated in 2024 that federal fraud losses are hundreds of billions of dollars annually. GovGuard does not claim to detect every fraud pattern; it closes the action-level proof gap before high-risk changes execute.

GovGuard binds each action to one accountable approver. Where statute or policy requires dual approval — the two-person rule — escalate to a multi-party quorum with EMILIA Quorum.

Run the GovGuard fire drillScope a 60-day pilot

Start in observe mode. Nothing gets blocked at first. You see what would have needed signoff and get a procurement-grade evidence packet.

GG-1 EnforcedConformance specCI test
PILOT SHAPE

Start with a fire drill on one workflow.

One workflow
Pick a single disbursement or change flow to watch first.
Observe mode
Nothing is blocked. You see what would have needed signoff.
60 days
Long enough to catch the actions that matter, short enough to scope.
$25K
Scoped enough for a departmental pilot.
Audit packet
Receipts, decisions, and evidence your auditors can verify offline.
THE WOUND

A fake bank-change email is how the money leaves.

Government payment fraud often doesn’t break in. It walks through an approved-looking workflow:

1
A "we changed banks, please update our payment details" email arrives, formatted like every other vendor notice.
2
The vendor banking record is updated. The clerk is logged in, the role can edit the field, the form submits.
3
The next disbursement run queues a payment to the new account.
Without GovGuard
The payment releases to the fraudulent account. The money is gone and irreversible. The audit log shows a valid session, but no one can prove who approved the bank-account change before it moved.
With GovGuard
The bank-account change is flagged at the action boundary and held pending a named human's device signoff. Once that person approves, an authorization receipt is issued and the payment releases with provable approval. If no one approves, no money moves.

Your audit evidence survives vendor turnover, acquisition, and SaaS sunset.

WHY AUTHENTICATION IS NOT ENOUGH

Most payment failures start inside approved-looking workflows.

The employee is logged in. The role can edit the record. The form submits. The audit log records a valid session. None of that proves the exact action was authorized before money moved.

GovGuard sits at the action boundary and asks the question authentication cannot answer: who approved this irreversible change, under which policy, for these exact parameters?

PROTECTED ACTIONS

Government fraud-control action pack.

gov.vendor_payment_destination_change
Vendor payment-destination change
A supplier payment destination changes before the next disbursement run.
gov.disbursement_release
Disbursement release
A high-value payment is ready to leave treasury or accounts payable.
gov.grant_disbursement
Grant disbursement
A program payment is released against a grant or award.
benefit_bank_account_change
Benefit bank-account change
A direct-deposit destination changes on a benefits case.
benefit_address_change
Benefit address/contact change
A mailing address or contact route changes in a way that can redirect notices or credentials.
caseworker_override
Caseworker override
An operator bypasses a system recommendation or eligibility control.
gov.provider_enrollment_change
Provider enrollment change
A provider status or payment address changes before future public funds flow.
gov.eligibility_override
Eligibility override
A regulated benefit decision is manually changed from the system result.
HOW IT WORKS

Six audit points, from action to evidence.

1
Observe
GovGuard receives a copy of the proposed action. It logs the action, evaluates policy, and does not block the existing system.
2
Classify
The action is checked for payment destination changes, new vendors, after-hours updates, missing authority, and policy-specific risk flags.
3
Bind
The actor, policy, action parameters, nonce, and time window are bound into the authorization context for the exact action.
4
Signoff
If policy would require approval, GovGuard records the named approver path and forbids self-approval in the evidence model.
5
Receipt
The completed authorization receipt proves who authorized what, under which policy, for which exact parameters.
6
Evidence packet
The fire-drill report shows which actions would have required signoff and gives auditors verification material they can check offline.
ENFORCEMENT MODES

Observe first. Enforce only after the evidence is trusted.

Government programs cannot move from zero to blocking overnight. GovGuard begins as a fire drill: an evidence layer that shows what would have needed signoff before it becomes a control layer.

observe
Evaluate protected actions, produce authorization receipts, and report what would have required signoff. No production blocking.
warn
Return a decision to the caller while the agency decides when to honor warnings by workflow.
enforce
Fail closed only after policy owners are comfortable with the evidence and escalation path.
AUTHORIZATION RECEIPTS

The artifact auditors can verify later.

A GovGuard pilot produces EP-RECEIPT-v1 authorization receipts. Each receipt is tied to the action hash, policy hash, approver path, nonce, expiry, and log checkpoint.

POST /api/v1/adapters/gov/vendor-payment-destination-change/precheck
POST /api/v1/adapters/gov/disbursement-release/precheck
POST /api/v1/adapters/gov/grant-disbursement/precheck
POST /api/v1/adapters/gov/provider-enrollment-change/precheck
POST /api/v1/adapters/gov/eligibility-override/precheck
POST /api/v1/trust-receipts
GET /api/v1/trust-receipts/{receiptId}/evidence
POST /api/v1/signoffs/request
POST /api/v1/signoffs/{signoffId}/approve
DEPLOYMENT & ASSURANCE

It runs where your security review needs it to run.

On-prem and air-gapped deployment is available - a self-contained offline installer that runs with no route off the host. SSO (SAML 2.0 / OIDC) and SCIM 2.0 provisioning connect the named humans who can sign off to your directory. And the evidence is verifiable offline, without EMILIA: a receipt checks out with pure crypto, on a machine that has never touched our network.

Run the fire drill. Then scope the pilot.

Pick one workflow: vendor payment destination, disbursement release, grant disbursement, provider enrollment, benefit routing, or eligibility override. GovGuard observes for 60 days, produces the authorization evidence, and shows what would have required named signoff. Pilot fee: $25K.

Run the GovGuard fire drill

For your compliance file: EU AI Act mapping for government programs · RFP language

GovGuard - Pre-Payment Control for Government Fraud | EMILIA Protocol