Disclosed AI Product Overview

Runtime permission infrastructure for AI agents

This product explainer summarizes SMERC as runtime permission infrastructure for AI agents, automation workflows, and high-impact system actions.

Repository Evidence

The product claim is backed by a public technical artifact

The latest public repository includes the recoverability engine, authenticated tenant-scoped REST API, pilot audit persistence, immutable reviewer evidence, denominator-aware metrics, a browser review console, action-bound permits, signed control evidence, GitHub OIDC support, a permit-consuming deployment adapter, Python tests, console checks, Docker verification, authenticated remote GitHub Action evidence, financial governance profile, replay validation, and policy comparison.

The problem

AI agents are moving from chat to action.

They can deploy code, change infrastructure, export data, trigger financial workflows, and modify security controls. The operational risk is shifting from what the model says to what the agent does.

AI Agent
SMERC Recoverability score
ALLOW THROTTLE FREEZE DENY ESCALATE

What SMERC Scores

  • Reversibility
  • Containment strength
  • Rollback latency
  • Evidence validity
  • Anomaly pressure
  • Impact scope

Why It Matters

Most controls can say whether an action is permitted. SMERC adds a runtime posture: allow, throttle, freeze, deny, or escalate before the agent creates side effects.

First Pilot

The first commercial wedge is a 90-day GitHub Actions pilot for AI-assisted code, deployment, and infrastructure workflows.

Copyable Product Narration

Use this as a concise product explainer for prospects, reviewers, and technical evaluators.

This is a product overview for SMERC runtime permission infrastructure.

SMERC helps companies govern AI agents before those agents take high-impact actions.

Most systems ask whether an action is allowed. SMERC asks what posture the system should take before action: allow, throttle, freeze, deny, or escalate.

That matters when agents deploy code, change cloud infrastructure, modify security workflows, export data, or trigger financial operations.

SMERC scores reversibility, containment strength, rollback latency, evidence validity, anomaly pressure, and impact scope.

It then computes replayable risk and confidence scores.

Instead of returning only allow or block, SMERC returns a replayable governance posture.

The important middle states are throttle, freeze, and escalate. Useful automation can continue with limits, or pause when evidence is weak.

The current product includes a working demo, validation suite, customer discovery kit, and 90-day GitHub Actions pilot package.

The next test is whether CISOs and security teams care enough about recoverability scoring to pilot it in real AI-agent workflows.