Every agent needs an identity. Every action needs an authority. Every authority needs proof. StructureClerk turns 192 jurisdictions and your internal policies into decisions your agents can consume, before they act.
Okta, Auth0 and your IAM know who your agent is. Policy engines like OPA know how to evaluate a rule. StructureClerk provides what's missing: the content of the rule. Which action this agent may perform, in this jurisdiction, on this data, at this autonomy level — and what proof remains. Built to complement your identity and enforcement stack, not to replace it.
What happens between an agent's request and the action your infrastructure takes.
Agent request
StructureClerk Authority
Regulatory rules
Decision
Signed evidence
Your infrastructure enforces
Same agent, same action, same data. Only the origin and destination change, and the decision with them.
| Action | From | To | Decision | Why |
|---|---|---|---|---|
| read.customer_record | AU | AU | ALLOW | stays in Australia |
| read.customer_record | AU | US_FED | ALLOW | conditional regime: accountable disclosure, no mechanism imposed |
| read.customer_record | NZ | US_FED | APPROVE | restricted regime: transfer mechanism required |
| read.customer_record | AE | US_FED | APPROVE | transfer mechanism required |
| read.customer_record | BR | US_FED | APPROVE | transfer mechanism required (LGPD) |
| score.applicant | AE | — | DENY | right to human involvement |
| score.applicant | AU | — | ESCALATE | no equivalent rule: escalated, never guessed |
Jurisdiction rules can only tighten a decision, never relax one: the engine evaluates the table without them, then with them, and keeps the stricter answer. Naming a jurisdiction is therefore never a way to obtain permission. When no destination is supplied, the answer carries a warning rather than an implied clearance.
Four possible answers. Each maps to a zone of the Three Zones Framework.
The action is in Zone 1: the agent may act alone, within policy limits.
The action is in Zone 2: the agent prepares, a human approves before execution.
The action is in Zone 3: the decision is reserved for humans. The agent cannot take it.
Confidence < 90%: the Doubt Threshold routes the request to human review instead of guessing.
Advisory decisions. StructureClerk decides. Your infrastructure enforces.
A finance agent wants to execute a 12,500 AED payment involving health data in the United Arab Emirates. Here is what the engine answers.
POST /api/v1/authority/decide
{
"agent": {
"id": "financebot-01",
"autonomy_level": 3
},
"action": {
"type": "payment.execute",
"amount": 12500,
"currency": "AED",
"data_categories": [
"personal",
"health"
]
},
"context": {
"jurisdictions": [
"AE"
],
"sector": "health"
}
}{
"advisory": true,
"decision": "APPROVE",
"zone": 2,
"reason": "financial_threshold_exceeded",
"reasons": [
"financial_threshold_exceeded",
"sensitive_data_regulated_sector"
],
"confidence": 0.96,
"frameworks": [
{ "name": "Federal Decree-Law 45/2021", "domain": "data_protection", "jurisdiction": "AE", "coverage_tier": "priority" },
{ "name": "AI Strategy 2031", "domain": "ai_governance", "jurisdiction": "AE", "coverage_tier": "priority" }
],
"regulatory_flags": [
{ "code": "automated_decision_rights", "jurisdiction": "AE", "framework": "PDPL (EAU)" }
],
"sector_risk_level": "high",
"evidence": {
"id": "EVD-1c9a7e58-2b41-4f6e-9c3d-8a5b0e7f21d4",
"timestamp": "2026-09-18T07:40:11.000Z",
"sha256": "5b2aeaa5261c375a..."
},
"rules_version": "2026-09-18.1",
"disclaimer": "Décision consultative fondée sur une cartographie réglementaire. Ne constitue pas un avis juridique. L'application de la décision relève de votre infrastructure."
}Try it now
This form calls the real public endpoint. The response below, signature included, is exactly what your agent would receive.
// Pick a scenario or compose an action,
// then request a decision.Advisory decisions. StructureClerk decides. Your infrastructure enforces.
Agent interoperability
Your agents already query StructureClerk over A2A, MCP and REST. They can now ask it for a decision before acting.
Google Agent-to-Agent protocol. Lets AI agents query StructureClerk via JSON-RPC.
/api/a2aModel Context Protocol. Exposes 5 compliance tools for MCP-compatible clients.
/api/mcp-httpClassic REST API. Compliance analysis, jurisdiction mapping and roadmap endpoints.
/api/agent/compliance-checkPick your protocol. Copy. Execute. Each example is replayed against the server by the integration suite: what is printed here is what it answers.
// A2A — JSON-RPC 2.0
const res = await fetch(
"https://structureclerk.ca/api/a2a",
{
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
jsonrpc: "2.0",
method: "compliance/check",
params: {
jurisdiction: "AE",
company_size: "11-50",
sector: "health",
uses_ai: true
},
id: 1
})
}
);
const { result } = await res.json();
console.log(result.applicable_frameworks);
// ["Federal Decree-Law 45/2021", "AI Strategy 2031"]An agent's autonomy level is not a technical variable. It is a governance boundary.
→ ALLOW
The agent acts alone, within policy limits. Reads, classifications, drafts, reconciliations without sensitive data.
→ APPROVE
The agent prepares, the human approves. Financial actions above a threshold, irreversible actions, sensitive data in regulated sectors.
→ DENY
Decision reserved for humans: hiring, termination, credit, compensation, medical decisions, legal settlements. The agent cannot take it.
Cross-cutting: The Doubt Threshold→ ESCALATE
When the engine's confidence drops below 90%, the request is routed to human review, whatever the rule outcome. The system is designed to know what it doesn't know.
Three Zones Framework, L'Architecte Numérique, Michel Fotsing (2026), distributed by Hachette. larchitectenumerique.com
Who asked, which action, in which context, which policy applied, which decision was rendered, at what time. Every decision is cryptographically signed and appended to a chained log. Any third party can verify, without trusting us, that an agent held that authorization, at that moment.
A scan of your site, an issued attestation, a connector observation and an agent decision all enter one append-only, hash-chained ledger. Your posture timeline shows them on the same axis, and anyone can verify a record without a StructureClerk account. Authority is not a second product: it is the same regulatory engine and the same evidence infrastructure, exposed to your agents.
This approach follows the direction set by NIST's AI Agent Standards Initiative (February 2026) on agent identity and authorization.
The orchestration layer is decoupled from any single model provider. If a model degrades or a provider changes its pricing, the system switches without touching decision logic.
The decision contract is open. Implement it, criticize it, extend it. See the spec (JSON Schema, OpenAPI, MIT)
Already running an agent platform? Integration scenarios are documented for ten of them, monday.com, Agentforce, Copilot Studio and the rest