Where It Fits
SMERC sits between permission and consequence
Large platforms already have IAM, policy engines, approvals, logs, and monitoring. SMERC does not replace those controls. It adds a runtime action checkpoint that evaluates recoverability, evidence provenance, intent integrity, consequence horizon, autonomy budget, and right to continue.
AI agentsTool calls, data movement, code edits, workflow triggers, and autonomous retries.
MCP toolsPre-forwarding governance for tool-call sessions and session budgets.
GitHub ActionsObserve-mode scoring for AI-assisted code, deployment, and infrastructure workflows.
Cloud automationRecoverability checks before IAM, database, Kubernetes, networking, and deployment changes.
Financial actionsMetadata-only SMERC-F review for treasury, stablecoin, payment, and tokenized-finance workflows.
Security automationConstrained response routing before quarantine, deletion, credential revocation, or remediation actions.