ARBITER Developer Surface

Build controlled actions—not blanket agent access.

ARBITER places a recognizable authority contract between AI intent and meaningful action. Providers, models, and adapters may change; the request, policy, approval, grant, execution, receipt, and revocation boundary remains inspectable.

REFERENCE CONTRACT

One control loop across tools and providers.

The current public gates are reference proofs. Production SDK distribution, credential custody, tenant isolation, and adapter admission remain separately governed release decisions.

01

Action request

Name the exact action, target, scope, requester, and intended result.

02

Policy decision

Evaluate deterministic rules before model preference or tool availability.

03

Human checkpoint

Require a named approver where risk, money, access, or customer impact demands it.

04

Scoped grant

Issue narrow, short-lived, purpose-bound authority instead of standing credentials.

05

Constrained adapter

Execute only the approved operation against the approved target.

06

Receipt and lifecycle

Return evidence, then record use, expiry, denial, revocation, or replay rejection.

AVAILABLE NOW

Inspect the behavior before integrating it.

Use the email, shell, file, remote-support, and network-change gates to inspect allow, deny, approval, one-use authority, constrained execution, receipts, and expiry.

INTEGRATION BOUNDARY

Admit one action path at a time.

A production integration starts with one action, one target model, explicit identity, deterministic policy, a human checkpoint where required, a constrained adapter, rollback, and evidence that failure modes close safely.