Your platform's permissions say who can touch what. They do not say whether the action is permitted by your regulatory obligations — and that is the question a customer, an auditor or a regulator will ask you.
An advisory ALLOW / APPROVE / DENY / ESCALATE decision before every sensitive action, over REST, MCP or A2A — with signed evidence your counterparty verifies themselves, no account needed.
Whatever the platform, the decision rendered is the same and signed the same way. Only the access path changes.
It is deciding, before an agent acts, whether the action it is about to take is permitted — and keeping a verifiable record of that. Platform permissions govern access to data; agent governance covers the action itself, its recipients and its jurisdiction.
Because a platform's guardrails are written, evaluated and attested by that same platform: it is self-attestation, unverifiable from outside. An independent layer renders a signed decision a third party checks themselves — and it covers all your agents, whatever platform hosts them.
By rendering a decision before each sensitive action: every call produces Ed25519-signed evidence, timestamped and chained to the previous one, carrying the rule applied and the reason. The evidence verifies publicly, without an account — a trail a third party can rely on, not an internal log.
No, and that is deliberate: StructureClerk decides, your infrastructure enforces. The decision is advisory, which keeps the layer out of your critical path — your workflow chooses whether to stop, request validation or continue.
The assessment that produces your profile is free. For decisions, the design partner program is 0 $ for six months — the offer built for first integrations. After that, Authority plans bill by decision volume, with prepaid credits beyond the allowance rather than a wall.