AI Action Gate

Before AI does something real through an admitted path, ARBITER checks the action.

When integrated into a workflow, ARBITER Gate is the authority boundary between an AI request and an admitted consequential side effect. The Gate checks the exact action, current policy and risk state, authority scope, approval evidence, grant validity, and receipt requirements immediately before execution—without making the model provider the source of permission.

exact request → policy/state → approval if required → scoped grant → revalidation → constrained action → outcome receipt

The doctrine

Context is not permission.

Recommendation is not approval. Approval is evidence, not standing authority. Under the Gate contract, execution is admitted only when the exact action, current policy and risk state, and scoped grant all match. Consequential execution through that admitted path produces an Outcome Receipt.

Why the category matters

Providers change. The authority boundary should not.

Models can research, draft, reason, and propose. The Gate answers a different question: may this exact actor perform this exact action against this exact target under the current policy and authority state?

The control loop

Seven controls for sensitive actions.

  1. 01AI proposes an exact action
  2. 02ARBITER checks current policy and state
  3. 03A person approves the exact action if policy requires it
  4. 04A narrow, expiring grant is issued
  5. 05Execution revalidates the action and grant
  6. 06The constrained action runs
  7. 07The outcome is recorded and authority is consumed, expires, or is revoked
Working reference proofs

Start with the action you recognize.

Each public example leads with the work a client understands. The smaller ARBITER label identifies the control mechanism behind it. Every public demo result is synthetic and fixed in source; it is not evidence that an unrelated production adapter is qualified.

Powered by ARBITER Email Gate

Prepare and Send a Customer Follow-Up

See AI prepare a customer message, surface the risk, ask for approval, act once, and return proof without keeping permanent email access.

Powered by ARBITER System Action Gate

Run a System Action Safely

See one exact system action limited to one sandbox, one approved command, and one short execution window instead of opening an unrestricted terminal.

Powered by ARBITER File Action Gate

Update a File Without Losing Control

See one file change limited to the approved path, operation, size, and content while neighboring files and broad storage access remain out of bounds.

Powered by ARBITER Support Access Gate

Inspect a Customer Issue Without Taking Over

See a short, read-only support session limited to one site and device group while configuration changes and permanent access remain blocked.

Powered by ARBITER Network Change Gate

Make a Controlled Network Change

See one network change bound to the exact site, devices, validation check, and rollback plan before any adapter is allowed to act.

Where this helps

One permission pattern. Many business workflows.

Start with one workflow where a mistake would cost time, money, trust, or access. Each implementation still has to qualify its own identity, adapter, credentials, policy, approval, one-time authority, evidence, rollback, and incident path; the provider can change without changing that contract.

  • customer messages
  • exact system actions
  • file updates and publication
  • remote support sessions
  • network changes
  • customer follow-up
  • payment-intent creation
  • connected API actions
Recurring governed capacity

Governed Workflow Add-On — $149/month.

Add one named ARBITER-controlled workflow to an eligible Centaur workspace. The recurring license covers the rules and approval boundary, limited permissions, receipts, expiry, revocation, and maintained operating contract. Provider-specific adapter work or implementation is separately scoped and qualified before activation.

Workflow license includes

  • one named action and target
  • deterministic policy and current-state checks
  • human approval path when required
  • short-lived scoped grant
  • execution-time revalidation
  • constrained adapter boundary
  • allow, deny, hold, expiry, revocation, replay, and outcome evidence
  • operator receipt and emergency-stop runbook

For business owners

Use AI to reduce busywork while keeping configured consequential actions behind explicit authority boundaries rather than permanent model permission.

Scope the first workflow

For technical teams and integrators

Add a reusable approval, scoped-authority, and receipt contract around admitted actions that touch systems, providers, network devices, support workflows, or internal records.

Review developer contract