Pre-Execution Recoverability Control For AI Actions

Govern AI-agent actions before irreversible damage occurs.

SMERC, short for Structural Momentum Entropy Range Confidence, checks whether high-impact automated actions are recoverable, bounded, and supported by trusted evidence before execution. Its reference implementation is runtime permission infrastructure that returns a replayable posture: allow, throttle, freeze, deny, or escalate.

Mission

SMERC helps intelligent systems make safer decisions before irreversible actions occur, so people and organizations can trust the technology shaping their lives.

01 Admit

Check identity, authority, typed contracts, attestation, and expected object shape.

02 Score

Evaluate reversibility, containment, rollback latency, evidence validity, anomaly pressure, and impact scope.

03 Route

Return a posture, controls, review path, signed evidence, and lifecycle ledger record.

ALLOW THROTTLE FREEZE DENY ESCALATE

Start Here

Four reviewer lanes, then the proof path

SMERC is easiest to judge when the first click matches the reviewer. Start with one lane, then use the proof sequence below for posture judgment, performance, customer-owned metadata, and external reviewer response evidence.

Executive CISO review

Understand the problem, boundary, evidence, and pilot ask in 15 minutes.

Open review path
Technical Run the repo

Inspect the public code, CI, API, MCP proxy, GitHub Action, reports, and tests.

Open GitHub start here
Customer Run a metadata-only evaluation

Replace examples with 5 to 25 workflow actions and compare reviewer judgment against SMERC posture, controls, and evidence.

Open company evaluation
Financial Evaluate financial runtime

Use the SMERC-F path for payment, refund, treasury, stablecoin, tokenized-collateral, wallet-policy, limit, reserve-status, and external financial-risk signal evidence.

Open financial runtime path

Proof Sequence

Public proof to customer-owned evaluation

This is the serious reviewer path: run the public lifecycle proof, inspect the balanced posture ladder, check operational overhead, inspect the 132-scenario public-pattern runtime benchmark, request safe customer metadata, then assess whether the response is ready for a bounded pilot.

01 Run the lifecycle proof

Admission, pause, unlock, constrained route, permit verification, synthetic execution, and ledger evidence in one flow.

Lifecycle proof
02 Inspect posture judgment

See one ALLOW, one THROTTLE, one FREEZE, one DENY, and one ESCALATE result with routes and ledger evidence.

Balanced replay
03 Review performance metrics

Measure local decision/report overhead so reviewers can separate proof behavior from production latency claims.

Performance report
04 Request customer-owned metadata

Ask for safe, non-secret action metadata owned by the reviewer rather than private data or production access.

Metadata request
05 Assess the reviewer response

Classify whether the supplied metadata is ready, limited, unsafe, or too vague for a meaningful pilot.

Response assessment
06 Decide the pilot boundary

Proceed only if the review has bounded actions, claim limits, stop conditions, and useful disagreement signals.

Reviewer front door

Work / Result / Impact / Boundary

SMERC helps contain AI-driven action risk before execution.

SMERC is built around one practical control question: when an intelligent system can act, what level of action is actually defensible under current evidence, authority, recoverability, content risk, and fallback conditions?

Work Evaluate the action boundary

SMERC checks hard admission gates, trusted content evidence, recoverability, fallback state, execution routing, and decision lifecycle evidence before high-impact automation acts.

Result Return a replayable posture

The system returns ALLOW, THROTTLE, FREEZE, DENY, or ESCALATE with scores, reason codes, controls, Governance Routing Workbench output, and a ledger-backed decision record.

Impact Reduce irreversible exposure

People and organizations get a practical way to slow, constrain, stop, or review risky AI-driven actions before they create damage that is difficult or impossible to undo.

Boundary Complement existing controls

SMERC does not replace IAM, OPA, AI evals, gateways, SIEM, GRC, approval workflows, content scanners, legal review, or human accountability.

Where SMERC Fits

SMERC sits after detection and policy, but before execution.

It is a runtime checkpoint for action consequence: whether a high-impact automated action is admissible, recoverable, and properly routed before execution.

AI evals and observabilityMeasure model behavior, quality, and drift.
IAM, OPA, and policyAuthorize identity, access, and rules.
AI gatewaysBroker model traffic, prompts, providers, and usage controls.
SMERCGoverns whether the proposed action should proceed now, under these conditions, with this recovery path.
What is real now Public code, REST API, GitHub Action integration, MCP governance, Governance Routing Workbench evidence, Decision Lifecycle Ledger evidence, pilot reports, Docker support, and passing CI.
What is not claimed No production certification, compliance attestation, live customer incident reduction, or replacement of IAM, OPA, CI/CD controls, SIEM, GRC, or human accountability.
Best first test Run SMERC in shadow mode against GitHub Actions or MCP tool-call metadata, then compare postures against reviewer judgment.

Company Evaluation Path

Start with a 30-minute shadow-mode review.

A company does not need to hand over production access to understand SMERC. The first useful test is metadata-only: compare SMERC postures against how reviewers would handle real or synthetic workflow actions.

Provide 5 to 25 action examples

GitHub Actions, MCP tool calls, cloud changes, financial operations, code edits, approvals, or automation tasks. Metadata is enough.

Score Recoverability and fallback

SMERC evaluates authority, evidence, reversibility, containment, rollback latency, content risk, anomaly pressure, and impact scope.

Receive A replayable governance report

The output includes posture, reason codes, controls, Governance Routing Workbench output, latency notes, and Decision Lifecycle Ledger evidence.

Decide Whether a pilot is justified

The decision is based on reviewer agreement, false release concerns, false constraint burden, and whether recoverability changed judgment.

Contact / Review

Interested reviewers can leave a pilot or technical review request.

Use this path for CISO review, platform/security architecture review, GitHub Actions pilot interest, MCP tool-call governance feedback, financial runtime review, or credibility partner discussion.

Public review and non-production evaluation are allowed. Production deployment, commercial embedding, hosted use, resale, or revenue-generating use requires a separate written agreement.

Review Paths

Choose the shortest path to evaluate SMERC

Each lane has a narrow purpose. The homepage points reviewers to the right evidence instead of listing every artifact at once.

01

Technical Review

Inspect the public repository, passing CI, engine report, API surface, and evidence boundaries.

Open GitHub repo
02

CISO Review

Review the current maturity, what is real, what is not claimed, and whether a shadow-mode pilot is worth discussing.

Open 15-minute path
03

GitHub Actions Pilot

Start with one workflow, metadata-only inputs, observe mode, reviewer labels, and a day-30 go/no-go decision.

Open pilot path
04

Runtime Customer Evaluation

Copy a company metadata template, run the public examples from GitHub Actions, or replace them with 5 to 25 workflow actions.

Run public workflow
05

Strategic Review

Evaluate SMERC as a platform control pattern, acquisition-relevant technical asset, or strategic design-partner candidate.

Open strategic review
06

Financial Runtime Review

Evaluate payment, treasury, stablecoin, and tokenized-finance actions with source ingestion, context overlay, public replay, and a bounded pilot evidence packet.

Open financial evaluation
07

AWS Cloud Action Replay

Review AgentCore-style runtime and gateway actions, IAM, S3, CloudFormation, drift remediation, RDS, CloudWatch remediation, cost velocity, and cross-account delegation.

Open AWS replay
08

AWS Metadata Adapter

Test safe exported AWS-style summaries through a non-executing adapter that accepts valid rows, skips unsafe rows, and produces SMERC customer-evaluation evidence.

Open AWS adapter contract

What Exists

Current modules in the public build

SMERC is more than a document set: the public repository includes runnable code, examples, reports, tests, and bounded pilot materials.

Recoverability Engine Scores action metadata and returns ALLOW, THROTTLE, FREEZE, DENY, or ESCALATE before execution.
Runtime Evidence Trust Gate Separates trusted runtime metadata from an agent's self-described action context.
Content Evidence Adapter Consumes trusted scanner, eval, policy, and reviewer signals for code, SQL, email, DLP, prompt-injection, malware, secrets, and content-risk findings.
Fallback Policy Layer Fails safe when scanners, metadata, policies, adapters, review queues, rollback plans, or runtime dependencies are unavailable, stale, incomplete, conflicting, or timed out.
Execution Routing Turns posture into reviewable execution behavior: execute, constrain, pause, block, or route to review.
MCP Tool Governance Gateway Evaluates registry-defined MCP tool-call sessions with loop pressure, scope pressure, session-budget metering, proxy actions, and financial runtime tool profiles.
Decision Lifecycle Ledger Preserves request, evidence, recommendation, override, execution, outcome, and learning records.
Model and Agent Fitness Scores whether a candidate executor is suitable for the action, data, authority, and risk level.
Agent Handshake Lets an agent discover SMERC, declare authority, request a posture, and receive controls with replay evidence.

Financial Runtime Governance

Financial-action review without pretending to be a bank control

The financial runtime profile, internally called SMERC-F, covers payment, refund, treasury, stablecoin, tokenized-finance, and AI-assisted financial workflows. The first review remains metadata-only and shadow-mode: no live funds, no customer records, no wallet keys, no production enforcement.

Source ingestionDune-, BigQuery-, Chainabuse-, DefiLlama-, and Elliptic-shaped exported metadata.
Context overlayLegislation-inspired operational fields without legal or compliance conclusions.
Replay evidencePublic-data-shaped financial scenarios with posture changes, drivers, and controls.
External signalsAML/KYT-, wallet-screening-, Travel Rule-, fraud-, treasury-risk-, reserve-monitoring-, blockchain-analytics-, and smart-contract-risk-style outputs consumed as evidence.
Pilot packetGo/no-go criteria, reviewer questions, success metrics, stop conditions, and claim boundaries.

Action Request

Select a scenario or tune the signal profile before execution.

Decision

Runtime permission posture for high-impact action governance.

Awaiting request

Choose a scenario or submit a custom action request.

Irreversible exposure --
Reversible capacity --
Authorization score --

Reason Codes

    Controls

      Audit History

      Recent decisions from this demo session.

      Time Action Decision Report
      No decisions yet.