They can deploy code, change infrastructure, export data, trigger financial workflows, and modify security controls. The operational risk is shifting from what the model says to what the agent does.
AI Agent
SMERCRecoverability score
ALLOWTHROTTLEFREEZEDENYESCALATE
What SMERC Scores
Reversibility
Containment strength
Rollback latency
Evidence validity
Anomaly pressure
Impact scope
Why It Matters
Most controls can say whether an action is permitted. SMERC adds a runtime posture: allow, throttle, freeze, deny, or escalate before the agent creates side effects.
First Pilot
The first commercial wedge is a 90-day GitHub Actions pilot for AI-assisted code, deployment, and infrastructure workflows.
Copyable Product Narration
Use this as a concise product explainer for prospects, reviewers, and technical evaluators.
This is a product overview for SMERC runtime permission infrastructure.
SMERC helps companies govern AI agents before those agents take high-impact actions.
Most systems ask whether an action is allowed. SMERC asks what posture the system should take before action: allow, throttle, freeze, deny, or escalate.
That matters when agents deploy code, change cloud infrastructure, modify security workflows, export data, or trigger financial operations.
SMERC scores reversibility, containment strength, rollback latency, evidence validity, anomaly pressure, and impact scope.
It then computes replayable risk and confidence scores.
Instead of returning only allow or block, SMERC returns a replayable governance posture.
The important middle states are throttle, freeze, and escalate. Useful automation can continue with limits, or pause when evidence is weak.
The current product includes a working demo, validation suite, customer discovery kit, and 90-day GitHub Actions pilot package.
The next test is whether CISOs and security teams care enough about recoverability scoring to pilot it in real AI-agent workflows.