Governed AI Agent Factory Architecture
Govern the environment, not the intelligence.A governed AI agent factory separates package source truth, runtime execution, evidence, qualification, and promotion authority so the factory can automate more work without allowing capability to become authority.
What is autonomous agent factory governance?
Autonomous agent factory governance is the system of contracts, permissions, identity, evaluation gates, runtime controls, and evidence that governs how AI agents and agent teams are built, qualified, deployed, operated, and improved.
In the WTK architecture, the governing package remains outside the model. A cognition provider may propose and coordinate work, but it does not become the source of authority, define its own success criteria, or silently promote a replacement.
This separation makes each runtime projection independently inspectable: authority is bounded before execution, consequential actions are mediated, claims remain tied to evidence, and changes return through qualification and explicit promotion.
The factory supplies candidates. A separate authority governs replacement.
Improvement candidates originate in the factory, but promotion authority remains outside the candidate and the component that produced it. Today that authority is human-operated. Over time, bounded promotion decisions may be delegated to a separate policy-governed plane with explicit evidence requirements, risk limits, rollback conditions, and human escalation.
- 01Factory executionCandidate plus retained evidence
- 02Evaluation and qualificationScoped verdict plus limitations
- 03Separate promotion authorityHuman-authorized today
- 04Release and operationMonitor, suspend, revoke, or roll back
Target-state pattern language
Research plates show proposed patterns, bounded observations, gaps, and falsification pressure.
Purpose and goals
Define the value sought, the boundaries that matter, and the conditions under which work must stop.
Governance contracts
Represent authority, permissions, delegation, escalation, and degraded behavior as inspectable structure.
Cognition and coordination
Allow models and agents to reason inside bounded roles without making the intelligence substrate the governing authority.
Evidence and evaluation
Bind claims to receipts, traces, deterministic checks, independent evaluation, and explicit uncertainty.
Qualification and promotion
Separate existence from readiness, semantic judgment from deterministic floors, and candidates from promoted assets.
Operation and learning
Observe outcomes, detect drift, degrade safely, and feed verified learning back into the architecture.
Six views of the same governed environment.
Each plate states the proposed pattern, bounded observations from an independent case study, what remains unproven, and which falsification challenge applies.
SOURCE-CONTROLLED ARCHITECTURE VIEW
Governed system context
Authority, package source truth, runtime execution, evidence, outcomes, and research remain distinct parts of the system.
Authority enters separately from cognition. The canonical package remains source truth while execution, evidence, outcomes, and research stay distinct.
- Factory controlGoverned construction
- Canonical packageContracts remain source truth
- Target projectionDerived for one execution form
- RuntimeOrchestration and cognition
- Evidence planeRun and qualification records
- ResearchBounded architecture learning
Governance supplies policy and promotion authority. Qualification returns a bounded verdict before projection.
Runtime exchanges bounded work with cognition, authorizes tools, and receives results and consequences.
Evidence reaches outcome stakeholders. Field evidence informs research, which may support, revise, narrow, or falsify guidance.
WTK separates goal intake, canonical packages, qualification, target projection, runtime activity, and evidence records.
Equivalent enforcement across intelligence substrates, runtime targets, and organizational boundaries has not been established.
Intelligence-substrate independence · Cross-harness equivalence
SOURCE-CONTROLLED ARCHITECTURE VIEW
Trust boundary map
Authority, Factory, runtime, external consequence, and evidence domains require separate controls and identities.
Each column is a separate trust domain. Crossing a column boundary changes which identity, authority, control, or evidence must be checked.
TRUST DOMAINFactory domain - Goal intake
- Builder and package source
- Protected evaluators and fixtures
- Projection compiler
TRUST DOMAINRuntime domain - Orchestration substrate
- Cognition artifact
- Governed context and memory
TRUST DOMAINExternal consequence - Tool or service
- External state
TRUST DOMAINEvidence and consumer - Receipts and attestations
- Independent consumer or verifier
- Outcome stakeholders
Each crossing changes the control or evidence obligation.
- IntentPrincipal -> goal intake
- Policy and evaluationGovernance -> builder -> protected evaluators
- Promotion and deploymentGovernance -> projection compiler -> substrate
- Identity and contextIdentity authorities and governed memory -> substrate
- AuthorizationAgent proposal -> substrate -> tool or service
- Receipt and verificationTool, substrate, and evaluator -> attestations -> independent verifier
WTK represents contracts, protected evaluation, projection, identity context, receipts, and consumer-facing evidence as separate governed artifacts.
Independent attestation, multi-operator boundaries, collusive-agent behavior, and external verifier interoperability remain open.
Delegation integrity · Evidence authenticity
SOURCE-CONTROLLED ARCHITECTURE VIEW
Consequential action authorization
Agents propose actions; an accountable substrate decides whether those actions may produce consequences.
The worker proposes a consequential action. The orchestration substrate owns the authorization decision and every outcome produces evidence.
- Principal
- Coordinator
- Orchestration substrate
- Worker workload
- Tool or target
- Evidence plane
- Narrow delegationThe substrate verifies parent authority, then binds workload identity, task, context, and delegated authority.
- Authorize actionThe worker proposes an action. Identity, delegation chain, policy, audience, expiry, nonce, and budget are checked.
Branches remain visible; no outcome is inferred from the primary path.
A signed scoped envelope reaches the target. The target verifies consequence semantics; the result, receipt, and ordered attestations return.
A bounded approval request reaches the principal. The signed approve-or-deny decision is recorded in evidence.
The denial or degradation outcome is recorded and the worker receives a structured safe-state result.
WTK defines narrowed role contracts, operator gates, structured denials, bounded handoffs, and attributable activity evidence.
Target-side identity, nonce and replay enforcement, expiry, budget controls, and consequence semantics are not uniformly enforced across adapters.
Evidence authenticity · Organizational acceptance
SOURCE-CONTROLLED ARCHITECTURE VIEW
Governed artifact lifecycle
Creation, qualification, promotion, projection, deployment, operation, rollback, quarantine, and retirement are different states.
Lifecycle states are not interchangeable. Readiness, promotion, projection, deployment, operation, and retirement each require distinct transitions.
- BuildPackage candidate -> evaluation ready after governed construction and structural readiness.
- QualifyRequired evidence either passes into qualified or routes to remediation.
- Project and deployTarget compilation creates a projection; target validation and authorization permit deployment.
- OperateThe deployed artifact operates until remediation, quarantine, rollback, retirement, or invalidation changes its state.
Failed or incomplete evaluation and operational findings create a new package candidate version.
A critical anomaly quarantines the artifact; quarantine may route to remediation or retirement.
A declared rollback restores a prior qualified version to operation.
Material source or policy change, evidence invalidation, or revoked promotion returns work to rebuild and requalification.
WTK separates candidate packages, evaluation readiness, qualification, promotion, deployment projection, invalidation, and remediation.
Long-duration drift detection, revocation propagation, fleet rollback, and policy migration require sustained operational trials.
Long-term drift · Human trust
SOURCE-CONTROLLED ARCHITECTURE VIEW
Evidence authenticity lifecycle
A trust claim is useful only when producer, authority, subject, scope, ordering, completeness, and threshold can be independently checked.
Evidence becomes usable only when its subject, producer, authority, ordering, storage, scope, completeness, and threshold can be checked independently.
- Evidence subjectArtifact, action, run, evaluation, or outcome
- Authorized producerProducer identity and authority are in scope
- Addressed statementContent is bound to its digest
- Identity bindingAuthority, time, and order are attached
- Evidence storeAppend-only or externally anchored
- Independent consumerChecks the record without trusting its producer
- Authentic producer?
- Authorized claim?
- Correct subject and scope?
- Complete expected record?
- Meets the declared threshold?
Branches remain visible; no outcome is inferred from the primary path.
The consumer emits only the conclusion supported by the checked scope and threshold.
Any failed check produces an incomplete, inconclusive, rejected, or invalidated result.
WTK emits structured run, audit, evaluator, tribunal, qualification, provenance, and digest-bound evidence records.
Tamper-resistant storage, external anchoring, replay defense, selective-omission detection, and third-party verification remain incomplete.
Evidence authenticity · Unknown unknowns
SOURCE-CONTROLLED ARCHITECTURE VIEW
Architecture learning loop
The architecture should change through bounded falsification evidence—not confidence, novelty, or silent self-promotion.
Architecture guidance changes through bounded falsification evidence. The implementation is an observation target, not the authority that decides what is true.
- Architecture claimState a falsifiable proposition
- Falsification challengeName how the claim could fail
- Bounded protocolDeclare conditions and measurements
- ImplementationWTK or another observation target
- All run evidencePreserve successes and failures
- Bounded conclusionStay inside the tested scope
Branches remain visible; no outcome is inferred from the primary path.
Current evidence supports keeping the bounded claim.
Evidence changes the conditions or permitted scope.
The claim does not survive the challenge.
WTK records falsification challenges and research cycles while separating remediation, qualification, and promotion decisions.
Governance self-qualification, long-running field evidence, unknown failure discovery, and safe promotion of governance changes remain open.
Governance independence · Unknown unknowns
Behavior is governed through structure.
Prompts may guide behavior, but durable authority lives in contracts, registries, policies, gates, receipts, and evidence. A model can propose an action; the surrounding system decides whether that action is permitted, attributable, and promotable.
What the governance architecture must answer.
Who can authorize an autonomous agent?
Authority begins with an accountable principal, narrows through explicit delegation, and is checked again when an action could create an external consequence.
How is an AI agent qualified?
Qualification binds a verdict to the exact package, target projection, model, tools, policies, tests, and observed evidence. A result from one execution form does not automatically transfer to another.
Can an agent factory improve itself safely?
Evidence may inform a new candidate, but the candidate cannot redefine success or promote itself. The accepted version remains recoverable until external authority approves a separately qualified replacement.