Understand the problem, boundary, evidence, and pilot ask in 15 minutes.
Open review pathStart Here
Four reviewer lanes, then the proof path
SMERC is easiest to judge when the first click matches the reviewer. Start with one lane, then use the proof sequence below for posture judgment, performance, customer-owned metadata, and external reviewer response evidence.
Inspect the public code, CI, API, MCP proxy, GitHub Action, reports, and tests.
Open GitHub start hereReplace examples with 5 to 25 workflow actions and compare reviewer judgment against SMERC posture, controls, and evidence.
Open company evaluationUse the SMERC-F path for payment, refund, treasury, stablecoin, tokenized-collateral, wallet-policy, limit, reserve-status, and external financial-risk signal evidence.
Open financial runtime pathProof Sequence
Public proof to customer-owned evaluation
This is the serious reviewer path: run the public lifecycle proof, inspect the balanced posture ladder, check operational overhead, inspect the 132-scenario public-pattern runtime benchmark, request safe customer metadata, then assess whether the response is ready for a bounded pilot.
Admission, pause, unlock, constrained route, permit verification, synthetic execution, and ledger evidence in one flow.
Lifecycle proofSee one ALLOW, one THROTTLE, one FREEZE, one DENY, and one ESCALATE result with routes and ledger evidence.
Balanced replayMeasure local decision/report overhead so reviewers can separate proof behavior from production latency claims.
Performance reportAsk for safe, non-secret action metadata owned by the reviewer rather than private data or production access.
Metadata requestClassify whether the supplied metadata is ready, limited, unsafe, or too vague for a meaningful pilot.
Response assessmentProceed only if the review has bounded actions, claim limits, stop conditions, and useful disagreement signals.
Reviewer front doorWork / Result / Impact / Boundary
SMERC helps contain AI-driven action risk before execution.
SMERC is built around one practical control question: when an intelligent system can act, what level of action is actually defensible under current evidence, authority, recoverability, content risk, and fallback conditions?
SMERC checks hard admission gates, trusted content evidence, recoverability, fallback state, execution routing, and decision lifecycle evidence before high-impact automation acts.
The system returns ALLOW, THROTTLE, FREEZE, DENY, or ESCALATE with scores, reason codes, controls, Governance Routing Workbench output, and a ledger-backed decision record.
People and organizations get a practical way to slow, constrain, stop, or review risky AI-driven actions before they create damage that is difficult or impossible to undo.
SMERC does not replace IAM, OPA, AI evals, gateways, SIEM, GRC, approval workflows, content scanners, legal review, or human accountability.
Where SMERC Fits
SMERC sits after detection and policy, but before execution.
It is a runtime checkpoint for action consequence: whether a high-impact automated action is admissible, recoverable, and properly routed before execution.
Company Evaluation Path
Start with a 30-minute shadow-mode review.
A company does not need to hand over production access to understand SMERC. The first useful test is metadata-only: compare SMERC postures against how reviewers would handle real or synthetic workflow actions.
GitHub Actions, MCP tool calls, cloud changes, financial operations, code edits, approvals, or automation tasks. Metadata is enough.
SMERC evaluates authority, evidence, reversibility, containment, rollback latency, content risk, anomaly pressure, and impact scope.
The output includes posture, reason codes, controls, Governance Routing Workbench output, latency notes, and Decision Lifecycle Ledger evidence.
The decision is based on reviewer agreement, false release concerns, false constraint burden, and whether recoverability changed judgment.
Contact / Review
Interested reviewers can leave a pilot or technical review request.
Use this path for CISO review, platform/security architecture review, GitHub Actions pilot interest, MCP tool-call governance feedback, financial runtime review, or credibility partner discussion.
Public review and non-production evaluation are allowed. Production deployment, commercial embedding, hosted use, resale, or revenue-generating use requires a separate written agreement.
Review Paths
Choose the shortest path to evaluate SMERC
Each lane has a narrow purpose. The homepage points reviewers to the right evidence instead of listing every artifact at once.
Technical Review
Inspect the public repository, passing CI, engine report, API surface, and evidence boundaries.
Open GitHub repoCISO Review
Review the current maturity, what is real, what is not claimed, and whether a shadow-mode pilot is worth discussing.
Open 15-minute pathGitHub Actions Pilot
Start with one workflow, metadata-only inputs, observe mode, reviewer labels, and a day-30 go/no-go decision.
Open pilot pathRuntime Customer Evaluation
Copy a company metadata template, run the public examples from GitHub Actions, or replace them with 5 to 25 workflow actions.
Run public workflowStrategic Review
Evaluate SMERC as a platform control pattern, acquisition-relevant technical asset, or strategic design-partner candidate.
Open strategic reviewFinancial Runtime Review
Evaluate payment, treasury, stablecoin, and tokenized-finance actions with source ingestion, context overlay, public replay, and a bounded pilot evidence packet.
Open financial evaluationAWS Cloud Action Replay
Review AgentCore-style runtime and gateway actions, IAM, S3, CloudFormation, drift remediation, RDS, CloudWatch remediation, cost velocity, and cross-account delegation.
Open AWS replayAWS Metadata Adapter
Test safe exported AWS-style summaries through a non-executing adapter that accepts valid rows, skips unsafe rows, and produces SMERC customer-evaluation evidence.
Open AWS adapter contractWhat Exists
Current modules in the public build
SMERC is more than a document set: the public repository includes runnable code, examples, reports, tests, and bounded pilot materials.
Financial Runtime Governance
Financial-action review without pretending to be a bank control
The financial runtime profile, internally called SMERC-F, covers payment, refund, treasury, stablecoin, tokenized-finance, and AI-assisted financial workflows. The first review remains metadata-only and shadow-mode: no live funds, no customer records, no wallet keys, no production enforcement.
Decision
Runtime permission posture for high-impact action governance.
Choose a scenario or submit a custom action request.
Reason Codes
Controls
Audit History
Recent decisions from this demo session.
| Time | Action | Decision | Report |
|---|---|---|---|
| No decisions yet. | |||