RotaGrant — agent governance
Govern the action, not the model.
Model evaluations tell you how a system scores. They do not constrain what an agent may do on a Tuesday afternoon with a payment API in reach. RotaGrant states that in advance, enforces it before the action, and records what was decided — including every refusal.
Runs in your VPC, your data centre, or fully airgapped. No payload reaches us on any path.
Authority, stated before the action
A grant says what one named agent may do, up to what value, until when, and under what conditions — signed for by an accountable human. It is not a role and it is not an API key. Those say who someone is; a grant says what they may do, bounded and expiring.
Nothing unowned holds power
An agent without a named accountable owner cannot be granted anything. The refusal is the control — an agent nobody answers for cannot be given authority by accident.
observed →Delegation subdivides, never multiplies
A delegated grant cannot exceed its parent on scope, window, budget, conditions or enforcement. Spending against a child debits every ancestor, so a tree of grants cannot sum to more than its root.
observed →Revocation reaches the whole tree
Revoking a grant revokes everything delegated from it — and whether anything was allowed afterwards is a question the platform answers, rather than leaving you to trust that it wasn't.
observed →Your key, your signature
Hold the signing key yourself and sealing stops when you withdraw access. What a third party does with an exported artefact afterwards is not something a governance layer can warrant.
assertedobserved you can check this on the running demo or in the published specification — the link goes to the thing itself, not to a description of it. asserted we are telling you, and there is nothing here you can verify from outside. The product draws this line in every record it produces; it would be strange to abandon it on our own website.
One workload is under several regimes at once
A Singapore bank with European customers is under PDPA and GDPR and the AI Act simultaneously, possibly running on a Canadian host. One enum cannot express that, and the failure is silent: the platform believes the wrong law applies and produces a pack that is internally consistent and wrong.
Resolved per decision, narrowest wins
A market profile resolves from the decision, then the agent, then the workspace, then the organisation. Whichever level supplied it is recorded beside the answer, because a profile set on a workspace and one inherited from an organisation have very different blast radii.
observed →Sealed into the record
The resolved regime is sealed with the decision, so a pack states which laws this deployment believed applied at the moment it was made — rather than which are configured today.
observed →Scored against what your regime selects
Readiness counts only the instruments your profile names. The others are listed, scored for reference, and marked unselected — because whether one of them applies to you is your determination and your counsel's, not something this platform decides by hiding it.
observed →We attack our own controls and publish where they fail
A platform that detects personal identifiers is making a claim about an adversarial world, and we test our detectors is effort rather than evidence. Effort is what a vendor asserts about itself; evidence has a denominator.
A grid with a denominator
A quality-diversity search over every (identifier × mutation) cell the regime activates, run against our own detector. The current grid is 21 cells with 0 defects — and every red cell that remains is reachable only through a character the detector must refuse.
observed →The failures are on the page
Cells we fail are published, classified as defect or residual, and cited by GDPR Art. 32(1)(d) in the audit bundle. A pack reporting "adversarial testing: available" without them would have published the diligence and hidden the result.
observed →Measured, not asserted
Replacing a generic eleven-digit pattern with three checksummed national schemes took the false-positive rate on random strings from 100% to 2.1%. A test measures it, so a future scheme cannot quietly restore the old behaviour.
observed →The demo runs real agents
Not a video, and not seeded rows. Agents run daily, ask for authority, get refused, and the evidence is sealed and verifiable. Every record you see there was produced by something running — and when a grant runs down, a named person renews it, which is itself on the page.