Your AI agent
Your policies, validation, controls and accountable executives travel through your internal governance.
ENSIGN makes autonomous agents prove who owns them, what they may do, whether they are validated, and which human remains accountable before they transact across institutions.
As AI agents begin acting across firms, each institution can govern its own system, but cannot see the validation, authority or human accountability behind the counterparty’s agent.
Your policies, validation, controls and accountable executives travel through your internal governance.
The name of the institution is familiar. The system acting in its name may not be.
Every bilateral agent transaction passes through four understandable control moments. The protocol completes before either institution is bound.
The external AI presents a signed credential naming its institution, identity, authority, validation and accountable human.
Your institution verifies the signature, expiry, transaction limit and validation freshness against its own policy.
Proceed, restrict the authority, require a human co-signature or block the transaction completely.
Both agents sign the exact transaction terms. Each institution stores the same receipt in its own tamper-evident chain.
ENSIGN does more than accept or reject. It lets institutions price governance differences operationally by changing how much autonomous authority they accept.
Identity verified, authority in bounds and validation current. Complete and record the transaction.
CONTROL RESPONSE · FULL AUTHORITYTest Proceed →The credential is valid but a control is aging. Lower the transaction authority until it is refreshed.
CONTROL RESPONSE · REDUCED AUTHORITYTest Restrict →The transaction exceeds autonomous authority or presents an anomaly. Require accountable human approval.
CONTROL RESPONSE · CO-SIGNATURETest Get Human →No passport, an expired credential or a failed signature. Stop and record the refusal.
CONTROL RESPONSE · NO ADMISSIONTest Block →Run six defensive simulations covering stolen credentials, impersonation, privilege escalation, replay, instruction tampering and signing-key compromise.
Verify live key possession, credential status, signed authority and transaction hashes before admission.
Block the session, freeze evidence and prevent a suspect request from becoming an institutional obligation.
Preserve the security finding, assign the responsible human and add it to the audit register.
Open Agent Security Operations →ENSIGN gives both institutions an identical, dual-signed receipt. If one ledger later changes, the other side can locate the precise break.
ENSIGN is a reference proposal for the institutions, infrastructure providers and oversight functions that will have to govern cross-firm autonomous action.
Extend existing governance to AI-mediated bilateral activity.
Create one interoperable credential and receipt pattern across participants.
Inspect who authorized an agent and which human remained responsible.
ENSIGN ports the logic of maritime flag-state doctrine to autonomous AI: an actor crossing jurisdictions carries its issuing institution’s governance, shows verifiable colors before engagement, and leaves a contemporaneous shared log.
The credential uses existing signing and hash-chain technology. ENSIGN proposes the governance content, verification duties, decision ladder and dispute doctrine, not a new cryptographic protocol.
Take the role of the receiving bank, test five governance conditions, and see exactly when ENSIGN proceeds, restricts, escalates or blocks.
No sign-up required · Synthetic institutions · Draft standard v0.2