sanction
requisition in productionProof that the work happened.
A consequential act, by a person, a device, or an AI agent, becomes a signed record of who did it, under what rule, with which witnesses. Anyone can check it, without trusting the institution that produced it.
against the published key
the problem
One failure, in every institution that keeps its own records.
The party who benefits from the record being wrong is the party who controls the record. A sailor signs his own maintenance check. A guard logs his own rounds. An agency decides what its own release contains. An agent reports what it did. The rules requiring a second person already exist and are written down. They are attested by the institution being reviewed, in a form nobody outside can verify.
The Navy has a word for the result. Gundecking: signing off checks that were never performed. It is not laziness. It is what happens when the workload exceeds the time available and the record is the cheapest thing to fake.
how it works
One mechanism, configured per deployment.
The record is a byproduct of doing the work, not a form filled out afterward. Where paperwork costs more than the task, the paperwork gets skipped or falsified. So the proof is produced by the act itself.
Witness
Every approving act is a signed record carrying attributes someone can vouch for: identity, qualification, billet, presence at the equipment, time. A person, a device, a decoder, or an agent can each be a witness. They are not interchangeable.
Predicate
Each deployment declares, per class of action, what an independent second act means. The gate asks one question: does this witness set satisfy the rule in force? A rule nobody on the current roster could satisfy is refused when it is configured, with a reason, instead of at three in the morning.
Receipt
Every outcome, executed or refused, seals a receipt recording the rule, the witnesses, and the evaluation trace. A stranger can re-run the decision offline and reach the same verdict without asking permission.
The three rules the language enforces, what never loosens, and what the mechanism does not do are on the Sanction page.
four systems
Each stands alone. Composed, they are Sanction.
A customer running one part gets a real property, not a fragment. Which components a deployment takes is configuration, never a fork.
Requisition
authority of recordWitnesses, independence predicates, byte-bound approval re-verified at execution, and signed, chain-bound receipts a stranger verifies offline against a published, append-only key registry. An agent proposal is one input among several; strip the agent out and the mechanism is unchanged.
Ultraviolet
purple-team SOCA security operations center on the BEAM. Sensors, detection, replay, investigation, and human approval as a plain workflow. Its MCP tools read or propose; nothing executes. Complete on its own, with no authority plane in the picture.
Trinity
governed agentA personal AI agent that runs on your machine, remembers you, learns procedures, and acts through tools. Its authority is pluggable: under Requisition it can only propose, and every proposal is a governed act with a receipt.
beam_mcp
MCP server coreModel Context Protocol for the BEAM. It carries calls and holds no authority. No approvals, no receipts, no masking, by design. Whatever wraps it decides those.
beam_mcp_signer 0.2.1 signs beam_mcp's canonical call-graph bytes with Ed25519; the host holds the key.
Sanction OS
Where Sanction runs. Not a member of it. The platform is what makes it something an organization can operate: rules configured without writing code, a tenant boundary, the evaluation harness run against the deployed build, registry operators chosen per deployment, and a path to accreditation.
The default is maximal and configuration goes downward, because a system that starts permissive and adds controls has a moment in its history when it was permissive. Self-hosted Sanction and platform-hosted Sanction OS are two offers, not one offer at two prices.
Read more about Sanction OS · early access
evidence
Measured, not declared.
The benchmark, its frozen methodology and its per-trial results are public, so an assessor can examine the evidence before the system is installed.
The system under test is Requisition, measured under its working name at a private commit; it is not the open-source Trinity agent. v1 is frozen and describes a superseded build.
The papers, both benchmarks, ONE-Bench and the citation rules are on the Research page. The founder and the company are on the Company page.
programs
Two ways in for people who do not work here.
Red-team arena
comingA public arena where anyone can try to get an unapproved effect past Requisition. The judge is the receipt chain, not what a model says.
About the arenaBug bounty
comingA paid program for security findings. Until it opens, reports are welcome under the disclosure policy.
About the bountytiming
The requirement is regulatory.
OMB M-25-21
Federal agencies must identify and manage high-impact AI, and use cases that fail the minimum practices must be discontinued.
CISA and Five Eyes agentic AI guidance
Six national cyber agencies jointly name accountability gaps, meaning the inability to trace decisions, audit actions, or assign responsibility when agents act on their own, as one of five risk categories for agentic AI. They recommend governance policies and human oversight for autonomous agents.
Careful Adoption of Agentic AI Services, cisa.gov, April 2026
the foundation
Yes, the cats are real.
Script Kitty runs alongside rescue cats and open-source pet tech. The Script Kitty Foundation is the part of this that does that, and one day the platform gets a physical home where research and fostering share a room. Its site is scriptkittyfoundation.org.
Pilots, evaluations, and research.
Open to consulting and integration, research grants and early research access, and speaking engagements. The systems are specified for defense, healthcare and other high-sensitivity environments; the full specification and fielded scope are shared in a briefing.
The three layers are on the Sanction page.
The deployments are on the Requisition page.
The deployment posture is on the Requisition page.