Work completed, not questions answered.
The governed tier of hosting: one door in and three ways out, a vault that signs only what was permitted, and a write-once log whose sealed roots make the audit a recomputation.
Taifoon Attest is the governed tier of Taifoon hosting. Agents run in isolated, attested cells and operate a client’s workplace estate through scoped connectors. The unit of value is work completed, not questions answered, and a request leaves by the simplest route the policy allows: most resolve against a rule with no human decision, some need one judgement from the accountable owner, and a few are genuine exceptions for an expert. Whichever route it takes, the change is executed only through a signing vault that will not sign what was not permitted, and every step lands in a write-once log whose sealed roots make the record independently verifiable. The audit becomes a recomputation rather than an interview.
Observed, never trusted blindly: identity, device management, collaboration, business applications, the HR source, and, where relevant, the operator’s connectivity management.
Read scopes and write scopes separated from day one; tenant credentials held in the vault, never in an agent runtime.
Agent roles in isolated cells, EU region for EU clients, attested images published for enclaved workloads.
Four sensitivity levels. Each record carries blast radius, confidence, reversibility, expiry, approver identity, and an audit identifier. Auto stays off by default in production; enabling it per module is itself a logged decision.
Allowlisted operations, vault-signed, each signature bound to its approval record. No approval, no signature, no write.
The write-once log, sealed roots, scheduled evidence exports, and regulatory evidence packs a third party can recompute.
A person describes the problem where they already work. The route out is chosen by one question: whether a human judgement is required, and whose. Most requests do not need one, which is what separates completing work from routing it.
The policy already permits it. The system diagnoses, proposes the released plan, and asks only when it should happen. A person confirming what the rules already allow is theatre that trains them to click.
Clean up a device, a driver, a restart. Roll out released software. Activate a licence.
A business judgement is needed. The system finds who owns it and condenses the decision onto one card, carrying blast radius, reversibility and expiry. This is the approval ladder, and it is the route below.
Access to a collaboration site. Spend outside budget. Software off the standard list.
Outside the catalogue. The system escalates with the context, diagnosis and history it already gathered, rather than a ticket saying somebody is stuck. What the expert resolves becomes a candidate action.
Security incidents. Fault patterns nobody has seen. Cases with no registered action.
Attest does not replace the organisation’s governance. The policies, the owners and the approval chains stay the customer’s. What changes is that they are executed rather than looked up, remembered, or guessed at by whoever answers the ticket.
Language models are not deterministic, so they sit on the ingestion side and nowhere else. A model takes in the flow of information and hands on two things: structured facts, and a plan assembled from actions that already exist. It holds no permission and reaches no system, and its output is treated like any input from outside: untrusted.
The model may select from the catalogue of registered, tested, released actions. It may not compose a new one. An action nobody registered and tested cannot be reached from a prompt.
Not a system prompt and not a model instruction. Whether a plan is permitted, who must approve it, and what actually runs is never in the prompt.
The consequence is the point: the model is replaceable without the system’s behaviour changing, and a model that changes, hallucinates or fails cannot widen a permission, skip an approval, or reach a system. The execution engine is what holds that line, and the vault signs only what it permitted. The vault and the metal →
Off by default in production; enabling it per module is itself a logged decision.
Low blast radius, reversible: a person confirms with one tap, identity recorded.
High consequence: the approver types the confirmation; the record binds who, what, and until when.
The floor that never passes. Some operations are not automatable by policy.
The honest boundary ships with the product: sealing makes records tamper-evident, it does not make decisions correct. The approval ladder is the human-oversight mechanism that covers what the cryptography does not.
Proves what agents did inside an estate. Governed: nothing executes without approval.
Releases payment on what agents provably delivered between parties. The product →
Neither replaces the other, and both inherit the same sealed roots: the evidence plane is the shared floor. On the OS floor, agents run autonomous by design; under Attest, nothing executes without approval. Autonomous there, governed here, never blurred.
