TaifoonTAIFOON
ATTEST — THE APPROVAL LADDER
[ ATTEST · THE APPROVAL LADDER ]

Work completed, not questions answered.

The governed tier of hosting: one door in and three ways out, a vault that signs only what was permitted, and a write-once log whose sealed roots make the audit a recomputation.

BUILDING · FIRST DELIVERY SCOPED
[ The product, in one paragraph ]

Taifoon Attest is the governed tier of Taifoon hosting. Agents run in isolated, attested cells and operate a client’s workplace estate through scoped connectors. The unit of value is work completed, not questions answered, and a request leaves by the simplest route the policy allows: most resolve against a rule with no human decision, some need one judgement from the accountable owner, and a few are genuine exceptions for an expert. Whichever route it takes, the change is executed only through a signing vault that will not sign what was not permitted, and every step lands in a write-once log whose sealed roots make the record independently verifiable. The audit becomes a recomputation rather than an interview.

[ What Attest consists of · six planes ]
PLANE 1
The customer estate

Observed, never trusted blindly: identity, device management, collaboration, business applications, the HR source, and, where relevant, the operator’s connectivity management.

PLANE 2
The connector plane

Read scopes and write scopes separated from day one; tenant credentials held in the vault, never in an agent runtime.

PLANE 3
The agent plane

Agent roles in isolated cells, EU region for EU clients, attested images published for enclaved workloads.

PLANE 4
The approval plane

Four sensitivity levels. Each record carries blast radius, confidence, reversibility, expiry, approver identity, and an audit identifier. Auto stays off by default in production; enabling it per module is itself a logged decision.

PLANE 5
The actuation plane

Allowlisted operations, vault-signed, each signature bound to its approval record. No approval, no signature, no write.

PLANE 6
The evidence plane

The write-once log, sealed roots, scheduled evidence exports, and regulatory evidence packs a third party can recompute.

The six-plane architecture, as run
[ One door in · three ways out ]

A person describes the problem where they already work. The route out is chosen by one question: whether a human judgement is required, and whose. Most requests do not need one, which is what separates completing work from routing it.

PATH 1RULE-BASED RESOLUTIONDECIDED BY THE POLICY, WRITTEN IN ADVANCE

The policy already permits it. The system diagnoses, proposes the released plan, and asks only when it should happen. A person confirming what the rules already allow is theatre that trains them to click.

Clean up a device, a driver, a restart. Roll out released software. Activate a licence.

PATH 2ONE DECISION, ONE CLICKDECIDED BY THE ACCOUNTABLE OWNER

A business judgement is needed. The system finds who owns it and condenses the decision onto one card, carrying blast radius, reversibility and expiry. This is the approval ladder, and it is the route below.

Access to a collaboration site. Spend outside budget. Software off the standard list.

PATH 3THE EXPERTDECIDED BY A NAMED EXPERT OR EXECUTIVE

Outside the catalogue. The system escalates with the context, diagnosis and history it already gathered, rather than a ticket saying somebody is stuck. What the expert resolves becomes a candidate action.

Security incidents. Fault patterns nobody has seen. Cases with no registered action.

Attest does not replace the organisation’s governance. The policies, the owners and the approval chains stay the customer’s. What changes is that they are executed rather than looked up, remembered, or guessed at by whoever answers the ticket.

[ The trust boundary · the model understands, code decides ]

Language models are not deterministic, so they sit on the ingestion side and nowhere else. A model takes in the flow of information and hands on two things: structured facts, and a plan assembled from actions that already exist. It holds no permission and reaches no system, and its output is treated like any input from outside: untrusted.

Choose, never invent

The model may select from the catalogue of registered, tested, released actions. It may not compose a new one. An action nobody registered and tested cannot be reached from a prompt.

The boundary is code

Not a system prompt and not a model instruction. Whether a plan is permitted, who must approve it, and what actually runs is never in the prompt.

The consequence is the point: the model is replaceable without the system’s behaviour changing, and a model that changes, hallucinates or fails cannot widen a permission, skip an approval, or reach a system. The execution engine is what holds that line, and the vault signs only what it permitted. The vault and the metal →

[ Path two in detail · the approval ladder, four rungs ]
AUTO

Off by default in production; enabling it per module is itself a logged decision.

ONE TAP

Low blast radius, reversible: a person confirms with one tap, identity recorded.

TYPED

High consequence: the approver types the confirmation; the record binds who, what, and until when.

BLOCKED

The floor that never passes. Some operations are not automatable by policy.

The honest boundary ships with the product: sealing makes records tamper-evident, it does not make decisions correct. The approval ladder is the human-oversight mechanism that covers what the cryptography does not.

[ Attest and Clear · one shared floor ]
ATTEST

Proves what agents did inside an estate. Governed: nothing executes without approval.

CLEAR

Releases payment on what agents provably delivered between parties. The product →

Neither replaces the other, and both inherit the same sealed roots: the evidence plane is the shared floor. On the OS floor, agents run autonomous by design; under Attest, nothing executes without approval. Autonomous there, governed here, never blurred.