Fidacy Research · Technical contribution · v2.0

Enforceable authority boundaries for agentic AI.

A production-backed mapping of bounded mandates, runtime enforcement and independently verifiable evidence to Singapore's Model AI Governance Framework for Agentic AI v1.5.

Published 29 Aug 20266 component tests9 production checksAlignment, not certification
Submitted to Singapore's Model AI Governance Framework for Agentic AI consultation29 AUG 2026 · CASE STUDY UNDER CONSIDERATION · NO ENDORSEMENT CLAIMED
Download case study →
01 · Safety property

The action must carry authority the agent cannot create for itself.

A prompt can be forgotten, bypassed or reinterpreted. An enforceable boundary exists only when the protected side-effect path requires a valid authority artifact the agent cannot mint, widen or replay.

No valid and unredeemed request-bound grant means no release to the consequential side effect.
02 · Reference architecture

Authority before execution. Evidence after every decision.

01

Mandate

Subject, actions, resources, validity, budget and delegation.

02

Request

Exact action, resource and a hash of local context.

03

Decision

Signed ALLOW or DENY outside the model.

04

Redemption

A short-lived grant is accepted exactly once.

05

Evidence

Receipt, grant state, incident and coverage record.

03 · MGF v1.5 control mapping

From governance recommendation to executable control.

Framework provisionImplementationQualification
2.1.2 · Bound risks through limitsAction and resource allowlists, bounded validity, fixed budget, constrained delegation and revocation.The deployer remains responsible for policy adequacy.
2.2.2 · Meaningful human oversightHigh-impact requests can be held until an accountable party issues or narrows authority.The deployer selects approvers and thresholds.
2.3.1 · Deterministic safeguardsDecision and grant verification run outside the model. Redemption is required on the connected path.Unconnected tools remain outside the proven boundary.
2.3.3 · Continuous monitoringConnector signals, redemption, reconciliation, coverage gaps and signed reports.Outside-boundary actions are NOT_OBSERVABLE, never inferred.
04 · Observed assurance run

Attempted bypass, exact execution, independent evidence.

An isolated Enterprise technical tenant exercised the production authority service and Stripe test mode without customer data or live funds.

Out-of-scope exportDENY
USD 24 grant altered to USD 240REFUSED
Exact USD 24 refundEXECUTED
Redeemed grant presented againREFUSED
Incident Pack and digestSEALED
05 · Proposed assurance vocabulary

Four claims that should never be treated as equivalent.

01

Policy declared

A rule states what the agent should do.

02

Decision recorded

A signed allow or deny decision exists.

03

Boundary enforced

The executor requires and redeems authority.

04

Effect reconciled

Authority evidence meets the downstream receipt.

Primary sources

Do not trust the summary. Verify the sources.

This is a Fidacy-operated technical reference deployment submitted for consideration. It does not claim IMDA certification, endorsement, inclusion in the framework or an independent customer deployment.