- Action
- deploy.release
- Decision
- PERMIT
- Authority
- deploy-governance@v2
- Receipt
- verified
PERMIT · DENY · ESCALATE · SILENCE before irreversible execution
The risk is unauthorized execution - not the action class. Approved work proceeds with a receipt.
Financial services ESCALATE £5M Wire Outside Policy Intervention required before settlement
Governed Actions
- Payments
- Credit decisions
- Fraud actions
- Model execution
Protected Assets
- Customer funds
- Transaction systems
- Credit infrastructure
- Fraud decision engines
Authorization outcomes
- PERMIT
Invoice payment below policy threshold
- DENY
Transfer to an unauthorized account
- ESCALATE
£5M cross-border wire outside standing authority
- SILENCE
Missing authentication on treasury request
What this means
A wire is not inherently malicious. Policy decides whether it proceeds, stops, escalates, or withholds.
- Approved payments execute with a receipt.
- Out-of-policy transfers escalate or deny - they are not blocked because “payment” is bad.
Healthcare DENY PHI to Unapproved Destination Export blocked at the boundary
Governed Actions
- Diagnosis routing
- Patient data access
- Clinical automation
- Care pathway execution
Protected Assets
- Patient records
- PHI systems
- Clinical infrastructure
- Audit evidence stores
Authorization outcomes
- PERMIT
Clinician access to assigned patient chart
- DENY
PHI export to an unapproved destination
- ESCALATE
Bulk research export needing ethics review
- SILENCE
Missing role binding on clinical agent
What this means
Data access is not the problem. Unauthorized destination or missing authority is.
- Approved clinical workflows proceed with receipts.
- Boundary violations deny; ambiguous authority escalates or silences.
Autonomous systems ESCALATE Robot Enters Human Workspace Policy-required intervention before motion
Governed Actions
- Robotics actuation
- Agent tool execution
- Industrial control
- Autonomous navigation
Protected Assets
- Production lines
- Safety interlocks
- OT controllers
- Human proximity zones
Authorization outcomes
- PERMIT
Pick-and-place inside cleared cell envelope
- DENY
Actuation that breaches hard safety limits
- ESCALATE
Robot path enters occupied human workspace
- SILENCE
Missing mission authority on control command
What this means
Control commands are not blocked because robots move. They are authorized against envelope, mission, and proximity policy.
- In-envelope work proceeds autonomously.
- Human-space entry escalates; hard limit breaches deny.
Energy ESCALATE Grid Reconfiguration Request Operator authority required before OT commit
Governed Actions
- Grid commands
- Control changes
- Infrastructure operations
- OT actuation
Protected Assets
- Substations
- Control networks
- Operational systems
- SCADA interfaces
Authorization outcomes
- PERMIT
Scheduled breaker open within approved window
- DENY
Override that violates islanding policy
- ESCALATE
Grid reconfiguration outside normal authority
- SILENCE
Unsigned control packet from automation agent
What this means
Grid commands are high-impact - not automatically forbidden. Authority and window decide the outcome.
- In-window approved work proceeds with receipts.
- Out-of-authority reconfiguration escalates; policy breaches deny.
Government DENY Export to Restricted Jurisdiction Transfer blocked before leaving enclave
Governed Actions
- Classified data export
- Air-gapped deployment
- Defence programme operations
- Cross-domain transfer
Protected Assets
- Sovereign workloads
- National infrastructure
- Key material
- Air-gap boundaries
Authorization outcomes
- PERMIT
Cleared transfer within authorized domain pair
- DENY
Export to a restricted jurisdiction
- ESCALATE
Cross-domain release needing dual control
- SILENCE
Missing clearance attestation on request
What this means
Cross-boundary transfer is a governed surface - not a synonym for attack.
- Cleared paths permit with receipts.
- Restricted destinations deny; dual-control cases escalate.
Execution governance PERMIT Approved Production Deployment Release proceeds with receipt
Governed Actions
- Policy resolution
- Runtime enforcement
- Receipt verification
- Fail-closed control
Protected Assets
- Receipt chain
- Investigation workspace
- Authority registry
- Audit trail integrity
Authorization outcomes
- PERMIT
Approved production deployment under policy
- DENY
Unauthorized production deploy without authority
- ESCALATE
Hotfix outside change window
- SILENCE
Missing signed policy binding on release request
What this means
Deployment is not the risk. Unauthorized deployment is. Policy-authorized releases proceed.
- AI wants to deploy → TrigGuard evaluates → PERMIT → receipt → deploy runs.
- Same surface can DENY, ESCALATE, or SILENCE when authority is missing or out of window.