Skip to main content
All diligence

Working paper overview

Attested Governance: Runtime Integrity for Autonomous Systems

A research proposal for connecting policy references, measurements and retained decision records. Evaluate its architectural argument separately from the behavior of the published components.

Jack Brennan · Original working paper: June 2026 · Web overview revised October 3, 2026

RecordJune 2026 working paper on SSRN: published June 2026. The original document is preserved. Its proposals and descriptions may differ from the published implementation. For current capabilities and limits, see Trust and scope.

Web revision history

On October 3, 2026, this overview was revised to distinguish the paper's proposed architecture from established implementation properties. The single-root argument is identified as a proposal, historical benchmark figures no longer appear as headline product metrics, and standardization ideas are separated from external adoption. The paper, original publication month and page URL are retained.

The architectural question.

The paper calls its proposed pattern Attested Governance and connects identity references, runtime measurement, decision records and continuity under a shared trust model. It uses the term inseparability for its argument that these concerns should be designed together.

A shared trust root is a design proposal. The paper's framing is not a proof that every viable architecture must use one root. Review the consequences for key compromise, separation of responsibilities, independently retained evidence and rotation before adopting that design.

Separate the proposal from the implementation.

Identity and policy references
The expected key supports attribution to a signing key. It does not by itself identify a particular agent or user. The published proxy records its JSON policy hash; signed Policy Artifacts are a separate construction with their own key and lifecycle assumptions.
Runtime measurement
The published aga-mcp-server measures on request over caller-supplied content. It does not establish continuous independent observation of the running process. Scheduled measurement and other proposed runtime controls require separate implementation and qualification.
Retained evidence
The current evidence bundle supports a defined check of supplied signed decisions, receipt links, Merkle proofs and a checkpoint. It does not establish complete capture, fresh state or actual tool execution. Its synthetic reviewer case makes the artifact available for inspection.
Continuity and operations
Durable collection, restart behavior, key rotation and independently witnessed history must be qualified for the selected deployment. Cryptographic consistency of one export does not establish those operational properties.

The implementation mapping distinguishes implemented, partial and specified criteria. The security notes identify known limitations, including parser differences and refusal paths without receipts.

Read benchmarks in their original scope.

The paper reports measurements of particular operations and configurations. They do not establish the end-to-end latency, throughput or reliability of a current gateway deployment. A signing primitive's timing is not the cost of routing and recording an actual tool call.

Use the paper for the historical workload and results. For an integration decision, measure the selected configuration, workload, latency distribution, failures and retained evidence. The current public gateway's use of Ed25519 is separate from composite-signature reference work.

A proposal is an invitation to review.

The paper proposes category criteria and possible standardization directions. Those proposals do not establish standards-body adoption, interoperability, regulatory acceptance or independent validation. References to other sectors are part of its argument, not evidence that the published AGA components satisfy those sectors' requirements.

The next useful result is a recipient who can reproduce the artifact check and identify a real decision it helps them make. A selected runtime integration can then be qualified against that requirement.