Runtime permissioning for AI agents and MCP tool calls
SMERC sits after detection, identity, and policy but before execution. It evaluates whether proposed AI-agent, MCP tool-call, security, cloud, GitHub Actions, and automation actions are recoverable enough to allow, throttle, freeze, deny, or escalate.
For CISO review, the public repository is the diligence surface. It contains the recoverability engine, Runtime Evidence Trust Gate, authenticated tenant-scoped API, immutable reviewer evidence, denominator-aware pilot metrics, GitHub PR Guardian, MCP tool governance, a browser review console, replayable examples, action-bound permits, signed control evidence, execution route-to-permit binding for GitHub deployment execution, Decision Lifecycle Ledger intelligence, Self-Governance Sandbox, Python tests, console model tests, Docker verification, authenticated remote GitHub Action evidence, SMERC-F materials, and reports. The current evidence supports pilot deployment review, not a claim of production certification.
SMERC-F gives financial-services reviewers a metadata-only shadow-mode path for automated payment, refund, treasury, stablecoin, tokenized-finance, and AI-assisted financial workflows. The first review compares SMERC-F posture with reviewer judgment and existing controls. It should not be presented as AML, fraud detection, custody, settlement, trading, payment execution, or production-certified financial control.
First scopeOne workflow family with normalized action metadata and reviewer labels.
First boundaryNo live funds, customer records, wallet keys, raw transaction payloads, or production enforcement.
First proofUseful restraint, false release candidates, false restraint candidates, metadata gaps, latency, and reviewer agreement.
Why A Security Team Might Test It
Potential CISO value
SMERC is designed to help security and platform teams reduce the blast radius of automated actions while still preserving useful automation. It creates a checkpoint where response actions, AI-assisted changes, tool calls, and deployments can be constrained, paused, denied, or escalated before side effects occur.
Less blunt controlUse `THROTTLE`, `FREEZE`, and `ESCALATE` instead of only allow or block.
Safer automation learningCompare SMERC posture with reviewer judgment before enforcement.
Clear stop gateStop if false release risk, false constraint rate, latency, or owner fit is poor.
First Visible Pilot Surface
SMERC comment on AI-assisted pull requests
GitHub PR Guardian renders a SMERC posture into a PR comment and decision certificate artifact. This gives security and platform reviewers a concrete place to inspect recoverability, required controls, reason codes, and replay evidence before merge or deployment.
Execution routing without pretending live vendor integrations exist
The Governance Routing Workbench provides a concrete route-and-review evidence path: posture routing, adapter conformance checks, signed route reports, GitHub route-to-permit execution binding, and vendor-neutral signed human-review request/response packages. In the reference implementation this layer is called SPARTa. This lets a reviewer inspect how an AI-agent action would be constrained, blocked, executed, or routed to accountable review before live Slack, Teams, Jira, ServiceNow, or cloud adapters are claimed.
The Decision Lifecycle Ledger records request, evidence, evaluation, human review, execution, outcome, and learning recommendation records. DLL Intelligence then summarizes multiple verified ledgers into near misses, override effectiveness, rollback performance, recurring missing evidence, recovery failures, drift signals, and a review-gated policy queue.
AI agents are moving closer to privileged workflows. Existing controls often decide whether an identity or policy allows an action. SMERC asks an additional runtime question: is this specific action recoverable, constrained, and defensible under uncertainty?
First Pilot
A 90-day GitHub Actions shadow-mode pilot for AI-assisted code, deployment, and infrastructure workflows. Existing approvals stay in place while SMERC writes decision reports for review.
What SMERC Is Not
Not a replacement for IAM, OPA, branch protection, code review, SIEM, or approval workflows.
Not a prompt-injection filter or LLM safety wrapper.
Not a production-certified security platform at this stage.
Not intended to block production workflows before shadow-mode calibration.
Not yet integrated with enterprise SSO, managed key lifecycle, independent native-control attestation, or horizontally scaled storage.
Data Handling
The first pilot should send action metadata, not sensitive payloads. SMERC should not need production secrets, customer PII, raw prompts, credentials, full source-code contents, or privileged cloud credentials.
Outputs
runtime posture
risk and confidence scores
reason codes
recommended constraints
replay ID and JSON decision report
Decision To Make
The first CISO decision is not whether to replace current controls. It is whether recoverability-aware runtime scoring is worth testing in shadow mode against real AI-assisted workflows.