Skip to content


Manifesto · Intended · 2026

The Authority Layer for Autonomous Systems

Issued byIntendedNo.5EA1ED97

A thesis on why autonomous AI cannot scale without an independent layer that decides what an agent may do — and proves it.

Intended · 2026


The bottleneck moved

For thirty years, software's constraint was production. Writing the draft, building the feature, running the analysis — that was the slow part. Every management system, every review process, every org chart was built for a world where making the work took longer than checking it.

AI inverted that overnight. Execution collapsed toward zero. An agent can now produce in seconds what used to take a team a week.

But the layer that decides whether a given action should happen — and proves it did so correctly — never scaled. So the bottleneck didn't disappear. It moved. It moved to the human who now stares at a review queue that refills every thirty minutes. Managers became queues. "Delegate Monday, discuss Friday, decide next week" is an operating rhythm that no longer exists.

The reflex is to make review faster. That's the wrong fix. You do not scale autonomy by reviewing faster, or by adding more actors. You scale it by engineering which decisions no longer require escalation at all.

That engineering — encoding delegated authority, enforcing the constraints an action cannot cross, and producing the evidence that proves completion — is a distinct layer. It does not exist yet as infrastructure. That is what Intended is building.


Autonomy breaks for one reason

Whether the actor is a person or an agent, autonomy fails the same way: execution was delegated, but judgment was not designed.

An agent that returns for approval at every tactical step isn't autonomous — it's a slower human. An agent that acts without bounds isn't autonomous — it's a liability. Real autonomy requires that, before execution begins, the actor knows three things:

  • The outcome it owns.
  • The constraints it cannot cross.
  • The evidence required to prove it's done.

Those aren't project-management questions. They are the boundaries of delegated authority. And today, in nearly every enterprise deploying agents, they live nowhere durable — in a prompt, in a person's head, in a Slack thread. That is fine for a pilot. It is unacceptable for production. And enterprises are moving agents from pilots to production right now — which is exactly when they hit this wall.


Why the obvious answers don't work

Model-provider guardrails are the fox guarding the henhouse. An enterprise will not accept that the same vendor building the agent also decides — and attests — what that agent is allowed to do. Governance has value because it is independent. You did not want your payment processor to also be your auditor. You will not want your model provider to also be your authority layer.

Observability and evaluation tools detect. They tell you, after the fact, that something went wrong. Detection is not enforcement. An authority layer has to decide before the action executes, and refuse it if it's out of bounds — not surface it in a dashboard afterward.

Human-in-the-loop is the bottleneck that moved. It doesn't scale, by definition. The point is to remove the decisions that don't need a human, not to route more of them to one.

What's missing is a layer that is independent, enforcing, and provable — that sits between any agent and any system it acts on, decides in real time whether a proposed action is within delegated authority, and — only then — issues a cryptographic proof of authorization that the executing system can verify on its own.


The thesis

Every foundational shift in computing needed a trust layer that no single participant controlled.

  • The web needed to standardize identity in transit — and got TLS.
  • Applications needed to standardize delegated access — and got OAuth.
  • Commerce needed to standardize moving money — and got Stripe and the card networks.

Autonomous systems now need to standardize authority — the right to act — and there is no layer for it yet.

Intended is building that layer. When an agent proposes an action, Intended:

  1. Classifies the intent against a canonical taxonomy of what autonomous systems actually do — across digital and physical action.
  2. Evaluates it deterministically against the tenant's policy and the raw parameters of the action — independent of, and resistant to, a manipulated or misclassified request.
  3. Authorizes or refuses it — and, only on authorization, mints a short-lived, cryptographically-signed authority token that the executing system (a connector, a model gateway, a robot's edge controller) verifies offline, without having to trust Intended at the moment of action.

The invariant is simple and absolute: no token, no action. And the token proves itself — it verifies against a public key without a callback, so the layer doesn't have to be trusted or even online at the moment of enforcement.


Why this becomes infrastructure, not a feature

A feature governs one company's agents. Infrastructure governs the ecosystem. Four properties make Intended the latter:

  • Neutral by construction. It is not a model provider. Its entire value is that it is the independent authority — trusted because it doesn't build the agents it governs.
  • Cross-provider. It sits above OpenAI, Anthropic, open models, and in-house systems alike. Authority shouldn't fracture per vendor.
  • Offline-verifiable. The proof of authorization stands on its own cryptographically — which is what lets a physical robot, an air-gapped system, or a downstream service enforce it without a dependency on Intended's uptime.
  • Physical and digital. The same authority model that governs a database write governs a robot's motion. As agents move into the physical world, the layer that governs them cannot stop at the API boundary.

And underneath it all is a standard — a canonical taxonomy of autonomous action. Standards compound. The layer that names the actions becomes the layer everyone maps to.


This is real, not a slide

Most companies at this stage have a thesis and a mockup. We have shipped the layer.

  • A canonical taxonomy of autonomous action spanning digital and physical domains, with safety treated as a first-class category — published as an open standard.
  • A deterministic authority engine that evaluates intent and the raw action parameters, with an always-on floor that refuses catastrophic actions regardless of how they're phrased.
  • The authority-token model — per-tenant signing, offline verification, single-use, short-lived — live in production.
  • A platform that is independently security-assessed, with every external finding remediated and live — tenant isolation proven on live production, tamper-evident audit, and a public capability-truth standard that forbids the product from claiming more than it does.

We built the thing we're describing. The credibility of a governance company is its own honesty — so we made the product verifiably real before we told anyone the story.


Why now, why us, why not them

Why now: execution just compressed 100×, enterprises are pushing agents from pilots to production, and the authority layer is the exposed gap they're feeling this quarter — not hypothetically, but in the review queues their own leaders are writing about publicly.

Why us: we've spent this cycle building the deterministic engine, the taxonomy standard, and the cryptographic authority model — and hardening them to enterprise-security scrutiny — rather than talking about them. The hard part is done and real.

Why not OpenAI, Anthropic, Microsoft, or Google: because an authority layer is trusted precisely to the degree that it is independent of the systems it governs. A model company governing and attesting its own agents is a conflict enterprises will not underwrite. The neutral layer has to be neutral. That is a position an incumbent structurally cannot occupy — and a category a focused, independent company can own.


The vision

The agentic economy runs on delegation. Every autonomous action — a payment, a deployment, a chart amendment, a robot's move — is an act of delegated authority. Today that delegation is implicit, unenforced, and unprovable.

Intended makes it explicit, enforced, and provable. The authority layer for autonomous systems — neutral, verifiable, and standard.

The internet learned to trust identity, access, and money. It now has to learn to trust action. That's the layer we're building.

Patent Pending — U.S. provisional patent applications filed.