One enforcement discipline, matched to the consequence.
Use the connected tier for human prompts and agent actions. The Mission Authorization Gateway is the high-assurance path for mission-boundary evaluations in DDIL, OT, and autonomy. Both intercept, evaluate, enforce, and record before consequence; their deployment, evidence, and assurance profiles are deliberately different.
A decision record states the ruling, its policy metadata, and the response issued by the enforcement point — it is not independent proof of downstream execution. Signing and verification are stated by product on Trust, the canonical record of what we run, which outranks our marketing.
Keep the control plane. Add authority at the action seam.
A control plane can sit on top of us — most should. Control planes manage the AI estate; Containment authorizes the action at the seam, and each governed ruling leaves a product-specific decision record.
The control-plane category, in its vendors’ own words: Microsoft calls Agent 365 “the control plane for AI agents”; ServiceNow’s AI Control Tower will “discover, observe, govern, secure and measure AI deployed across any system in the enterprise”. Cisco AI Defense, Check Point’s AI Defense Plane and Palo Alto’s Prisma AIRS sell the same altitude. We do not compete for that line item.
Same input, policy, and context — the same ruling. Every time.
Three surfaces. One deterministic path under each.
An illustrative decision record, annotated.
A buyer-level illustration, not a receipt schema. Actual fields, signing, and verification differ by product and are stated on Trust.