01
THE RUNTIME / CONSTRAINT BEFORE THE ACT
Runestack
Accountable agent issuance. Durable name. Short-lived proof. Attenuated grant. Policy check. Witness. Expiry. Then, and only then, a projection into whatever consumer asked.
- Delegation chains
- Authority flows from humans to agents through explicit, verifiable delegation. Scoped permissions, time-bounded access, revocable credentials.
- Signed receipts
- Every consequential action produces a cryptographic receipt. External verification means you don't trust the system; you verify it.
- Mutation containment
- Agents operate within declared boundaries. State changes are tracked, constrained, and reversible. No silent side effects, no undeclared writes.
- The stack
- Not “an AI gateway.” IAM as the umbrella, then the whole alphabet: IDM · IdP · SSO · federation · SCIM · CIAM · IGA · MFA · passwordless · AuthN · AuthZ · FGA · ReBAC · ABAC · PBAC · policy-as-code · PDP · PEP · PIP · PAP · PAM · JIT · least privilege · capability security · UCAN · ZCAP · PKI · CA · CLM · HSM · KMS · secrets management · mTLS · workload identity · SPIFFE · WIMSE · RATS · attestation · DID · VC · SSI · ZTNA · API gateway · MDM · RADIUS · NAC · SCM / checkout occupancy · SIEM · UEBA · audit trail · CT / transparency log · tamper-evident ledger · Merkle anchor · SLSA / in-toto · GRC / prove-it
- Status
- Building in the open. Core primitives under active development. Manifesto
RAVENHELM