Applied R&D / independent effect control

Authorize the effect. Prove the outcome.

An AI agent with real credentials can change code, infrastructure, and data faster than anyone reviews it. When it goes beyond what you intended, your organization answers for the result. VIGIL is developing a separate control point that sits outside the agent. It is designed to check each consequential action routed through it against the authority you delegated, before the action runs, and to keep evidence of what happened. The work is applied R&D toward an independent effect-control and evidence plane for AI agents.

Delegation traceIllustrative sequence · not live telemetry
VIGIL / EXEC-00

One authorization · six consequential actions

You · one instruction“Close out OPS-1142 and ship the fix.”
Authorized?
  1. Reads company credentials
  2. Calls an outside service
  3. Creates its own sub-agent+3 actions of its own
  4. Changes cloud infrastructure
  5. Ships code to production
  6. Emails 4,000 customers

You authorized the objective.

Did you authorize every action?

Who verifies each consequential action stays inside delegated authority? That is the control point VIGIL is being built to hold.

In plain terms

Four questions decide whether delegation to an agent is defensible.

  1. 01Who authorized this agent, and what exact authority did it get?
  2. 02Was each consequential action inside that authority?
  3. 03Did the action that executed match the action that was approved?
  4. 04Can you show a reviewer who was not there what was authorized and what the target reported?

VIGIL is applied research into answering all four at the moment of execution, with evidence a third party can check.

01 / Why now

Autonomy transfers execution. It doesn't transfer accountability.

An agent can have valid access and still exceed its authority. When it does, your organization answers for the outcome.

AI systems are moving from recommendations to consequential changes across software, infrastructure, engineering, and scientific workflows. Monitoring can reconstruct what happened. Guardrails can classify content. A proxy can block a request without confirming what the target did. None of them checks each action against the authority you delegated, or confirms with the target what changed.

Public incidents

Systems with real credentials are already acting.

Autonomous systems with real credentials have publicly taken actions their operators never intended. They have modified production systems and deleted data beyond their delegated scope. Each case landed on the organization.

Policy attention

Policy now asks what automated systems did.

Emerging AI governance frameworks, from national-security directives to risk-management standards and new AI regulation, ask organizations to demonstrate control over what automated systems do in operation, beyond how they were approved before deployment. Policy is defining the question. The answer is still open.

Retained risk

The consequences never moved.

When an agent acts, the operational damage, the security exposure, and the regulatory answerability remain with the organization that deployed it. Delegating execution delegates nothing else.

A credential is not a mission.A prompt is not an enforcement boundary.A trace is not target proof.

Someone has to verify, independently and at runtime, that each consequential action is still inside the authority that was delegated. That is the boundary VIGIL is researching.

02 / The control model

Control the path to the target, not the conversation.

VIGIL's architecture separates planning from execution authority. The agent plans and proposes; authority over real systems stays outside it, on a separate control path that decides each consequential action, releases narrow capability, mediates execution, and reconciles the target-reported result. The design treats an agent as an untrusted planner connected to trusted actuators.

The model may plan; it does not hold authority.

Authority

Bind the mission

Connect a human or organizational delegation to one agent, task, environment, time window, and set of constraints. Standing policy binds an identity; a delegation binds this one task and expires with it, so an agent cannot carry yesterday's authority into today's work.

Decision

Declare the effect

Turn a high-impact request into a reviewable operation with an exact target, parameters, preconditions, and approval profile. Review binds to the exact change, rather than the agent's description of it.

Execution

Release narrow capability

Keep standing credentials out of the agent. A controlled executor receives one-use capability and performs only the authorized operation. A compromised or misdirected agent holds no standing credential to steal, replay, or escalate.

Outcome

Reconcile the result

Compare what the target reports with what was authorized, then produce a portable record with explicit trust assumptions. Reconciliation exists to catch a landed change that differs from what was approved.

Illustrative control pathResearch target · not live telemetry
VIGIL / EFFECT-01
The agentAsks to act

Each consequential action becomes an explicit request: one exact change to one exact system.

Independent control pointVIGIL

Checks the request against the authority you delegated

The resultOnly the approved operation is released to run

And the target system reports what actually changed.

  • ApprovedInside the authority you granted

    Update a protected system

    The change matches what you authorized. A single-use key releases it, and the system reports the result.

  • RefusedOutside the authority you granted

    Export a restricted dataset

    The agent asked for something you never authorized. No key is released. Nothing changes.

  • PausedConditions changed

    Change critical infrastructure

    The approval no longer holds. Work stops and a human reviews it.

The agent holds no standing access of its own. By design, the only path to your systems runs through the control point.

Assurance inputs

Sensing changes the control posture. Authority still comes only from the delegation.

Model, context, runtime, identity, and target-state signals can narrow the released capability, force escalation, or stop work. The approval profile fixes which cases the policy path decides alone and which escalate to a human approver the sponsor names. VIGIL's deterministic decision path remains the final boundary for the effects routed through it. The design fails closed: if the control path is unavailable, consequential work waits instead of falling back to a direct path.

03 / Working with VIGIL

Bring one consequential workflow. Leave with an evidence-backed finding.

VIGIL is seeking government mission sponsors, research institutions, and industry partners for bounded, customer-contained validation.

Each engagement starts with a named mission question, an explicit control point, authoritative target observation, and acceptance criteria defined before the test. The sponsor brings the environment, the agent route, and the engineering time to close direct credential paths; VIGIL brings the control point, a prototype assurance profile (the packaged control points, checks, and evidence format for one class of consequential change), and the measurement.

Where validation starts

A measurable proving ground.

The first proof environment is software and cloud change control: the code, CI, repository, infrastructure, cloud, and database changes coding agents already make in production today. Validation itself runs in a reversible test lane. These targets provide mature APIs, explicit credentials, and authoritative state to reconcile; illustrative surfaces include protected-branch ref transitions, cloud IAM role changes, and gated schema migrations. One profile is in build; the other lanes open as partners define them.

  • Software & cloud change controlInitial profile
  • Defense & agency workflowsPartner-defined
  • Scientific AI workflowsResearch lane
  • Cyber & infrastructure operationsPartner-defined
Government

Mission sponsor

Define a mission question and acceptance criteria for a bounded AI-enabled workflow, and scope a controlled evaluation.

Research

Institute or laboratory

Add an effect-control and validation work package to a funded program, testbed, or research proposal.

Industry

Prime or integrator

Evaluate a reusable assurance profile for an agent platform, program environment, or transition pathway.

Enterprise

Design partner

Evaluate effect control for an agent rollout touching your repositories, CI, cloud, or data, in a contained test lane.

A controlled validation defines

  • One sponsor-owned environment and data boundary
  • One agent or model route, the sponsor's own or an isolated research agent, and a small set of workflows
  • A small set of consequential effect types
  • Direct credential paths and bypass routes to close
  • Allow, deny, escalate, expire, revoke, and control-path-unavailable cases
  • A target observer and an acceptance suite that runs defined threat cases, including injected out-of-scope actions and bypass attempts
  • The measured outcomes: unauthorized effects reaching the target, bypass routes closed, reconciliation mismatches caught, legitimate operations wrongly blocked, and overhead added to allowed operations

The engagement is bounded: weeks in a reversible test lane, with one workflow owner on the partner side. Engagement terms are covered in the technical briefing.

The output

An evidence-backed control finding.

A validation returns a prototype assurance profile plus the record behind it: authority and effect map, threat and control cases, measured results, offline-verifiable records, explicit limitations, and a transition recommendation. A profile proved in one validation is designed to be reused for the same class of change in other environments. Publication of methods and results is agreed per engagement, inside the sponsor's data boundary.

Discuss a validation partnership Request a technical briefing

04 / Who we are

One team across the whole control path.

VIGIL is an independent applied-research initiative built by a single team.

The research covers both halves of the control problem. One half is model integrity: checking, within stated trust assumptions, that the model doing the work is the model the organization approved. The other is effect control: deciding, executing, and recording consequential actions, with evidence a third party can check. Effect control is the half in build today; model integrity is at an earlier research stage.

Holding both halves in one team gives a reviewer one architecture and one set of records for who approved the model, what the agent was allowed to do, and what the target reported.

Research collaborations and validation partnerships are open now. A technical briefing covers the full architecture, the team behind it, the claims boundaries, and contracting specifics.

Request a technical briefing

05 / Current posture

Where the work stands.

VIGIL is an applied R&D initiative. Claims remain bound to a specific profile, deployment, control point, target observer, and signer or administrative boundary.

Defined

Control architecture

Bound authority, exact-effect decisions, mediated execution, and target reconciliation, plus the rules for what evidence means and what may be claimed from it.

In build

Initial vertical slice

An isolated coding agent, an exact Git ref transition, credentials held by the connector (the controlled executor) rather than the agent, target observation, and offline verification.

Open

Validation partnerships

Customer-contained research and pilot environments using synthetic, public, or sponsor-approved unclassified data.

What VIGIL is designed to prove

  • The chosen effect passed through the defined control point
  • Released capability matched the authorized operation
  • The target-reported result reconciled with that authorization

Stated limits

The design covers the effects routed through the control point, under the profiles built for them, and only those. Model integrity checks operate within stated trust assumptions; nothing in the design makes an agent's reasoning safe. Evidence is built for offline verification, with no claim that it is tamper-proof, and the work carries no accreditation, FedRAMP, or cATO status.

Continue the conversation

Have a workflow where AI authority needs a real boundary?

We prioritize government mission sponsorship, funded research programs, design-partner evaluations, and validation partnerships with security and research organizations. If an agent rollout is touching your repositories, CI, or cloud, a design-partner conversation is welcome.

Contact VIGIL contact@vigilresearch.org