Skip to main content
Verifiable human-authorization evidence · for autonomous action

Make the approval boundary
checkable after the fact.

Oversight rules differ by system, jurisdiction, and consequence. EMILIA does not decide when a human must act. It gives the relying party a way to require an enrolled approver credential over the exact action or a finite operating mandate, then verify that artifact offline under pinned keys and rules. On a completely mediated covered path, Gate refuses provider entry when the required evidence is missing.

Scope the protected-workflow pilotSee the receipt verify offline
The evidence gap

The hard problem isn't the policy. It's the evidence.

A session log can show who was logged in without preserving the exact action, accepted authority, approver credential, policy, and validity window as one portable record. EMILIA makes those stated inputs independently re-performable. The relying party still owns the approver directory, role assignment, policy, and conclusion drawn from that evidence.

At the authorization boundary

Not every cycle. The moments that matter.

A finite operating mandate can let an agent work unattended inside clear limits. Fresh approval is reserved for the actions or exceptions the buyer's policy selects.

Human-in-the-loop
Fresh approval for the selected action.

When local policy requires a fresh decision, Gate checks an accepted enrolled approver credential bound to the exact action. On a completely mediated covered path, missing or invalid required evidence means no provider entry.

Human-on-the-loop
Finite authority for unattended work.

An accepted authority source can define a bounded envelope — effect class, target set, geofence, time window, limits, and exception rules. Gate admits only matching actions while that authority remains current and unexhausted.

Evidence mechanisms

Map each local requirement to a checkable artifact.

An accountable approver credential, not a shared session
Device-bound signoff plus a relying-party-pinned approver directory and role policy
Two-person rule / launch authority
Quorum over distinct enrolled approver credentials with ordered-chain support
Authority bounded by rules of engagement
Monotonic delegation constraints + signed ROE / policy reference
The order was current, not a stale standing authorization
Validity window + observed-evidence freshness (fail-closed)
Revoke or halt an autonomous envelope
Revocation + continuous evaluation
Contested, disconnected, classified operations
Offline verification and an air-gap-capable deployment pattern
No accepted fresh approval when policy requires it
No provider entry on a completely mediated covered path
Reference points

Use the evidence in an authorized review, not as a shortcut.

DoD Directive 3000.09

Programs define their own human-judgment, authorization, review, and system-safety procedures under the controlling directive and implementation guidance.

EMILIA can preserve exact-action or bounded-envelope approval evidence for a program-authored procedure. It does not determine whether that procedure satisfies the directive.

EU AI Act · Article 14

Organizations assessing Article 14 need to document how their complete high-risk AI system enables the applicable human-oversight measures.

An action-bound approval or refusal can support that evidence file. A receipt alone does not establish natural-person identity, effective oversight, system classification, or legal compliance.

NIST AI RMF

The framework gives organizations a vocabulary for governing, mapping, measuring, and managing AI risk.

EMILIA publishes a control-to-evidence mapping and can preserve action-level inputs for an organization's own assessment. The mapping is not certification or a compliance verdict.

UN CCW · LAWS

Discussions about autonomous weapons include contested questions about human judgment, responsibility, predictability, and control.

A signed action or envelope record can answer one evidentiary question: what a pinned credential signed. It does not resolve the policy or legal debate.

Stated plainly

It verifies a signed authorization artifact. Not wisdom.

Serious programs will ask exactly where the line is. So we draw it.

Verifies

A specific enrolled credential — or quorum of distinct enrolled credentials — signed this exact action or bounded envelope, at a stated scope and within a validity window. Under the verifier's assumptions and the relying party's pinned keys, the signature and action binding can be checked offline. The relying party separately decides whether that credential was accepted for the required role.

Does not prove

The artifact does not establish the approver's civil identity, understanding, freedom from coercion, legal authority, or the wisdom or lawfulness of the action. It is one verifiable input to the relying party's broader control and review procedure.

Make required approval evidence checkable.

$25K · 90 days · 1 protected workflow. Map the authority source, produce synthetic and read-only evidence, and run a tabletop re-performance. Production is separately scoped after buyer acceptance.