Governance in the request path

Trust is a runtime behavior.

A policy document cannot govern a system it cannot observe. PULSAR turns trust principles into explicit checks, boundaries and evidence throughout the runtime.

01

Authority follows identity

Access never exceeds the requesting identity.

02

Evidence travels with output

Sources, policy and model context remain visible.

03

Humans retain agency

High-consequence action requires explicit authority.

04

Components stay replaceable

Open boundaries reduce dependence on one model or stack.

Sovereign boundaryAdaptive routingPermission-aware contextHuman authority

01 / Trust chain

Five controls that travel with every request

Trust becomes real when it changes runtime behavior.

01

Identity before intelligence

No context or capability is selected before the requesting identity is resolved.

02

Permission-aware retrieval

Indexing never grants authority; source access rules are preserved.

03

Evidence travels forward

Sources, checks, route and uncertainty remain attached to important outcomes.

04

Bounded execution

Tools are allowlisted, time-limited, observable and gated before consequential change.

05

Human authority

Designated people can accept, challenge, reject or stop high-impact work.

02 / Observable decisions

The runtime must be able to answer

A fluent response is not enough. Important outcomes need an inspectable path.

  1. Who or what initiated the request?
  2. Which policy and data boundary applied?
  3. Which context, tools and capability path were used?
  4. What evidence, uncertainty or escalation was recorded?
  5. Who retained authority over the final consequence?

The thinking behind the system

Sovereignty by default

Sensitive information remains within approved processing and residency boundaries. Moving context across a boundary requires an explicit purpose, data classification, technical protection and accountable approval.

Permission-aware context

The runtime must not expand a user’s authority simply because information has been indexed. Retrieval inherits source permissions, filters results before context reaches a model and keeps authorization metadata attached to the request.

Observable decisions

For important outputs, the system should be able to answer:

  • Which identity and policy applied?
  • Which capability route and model version were used?
  • Which sources and tools contributed?
  • What validation or escalation occurred?
  • Where was human approval required?

Bounded agents

Tool use begins read-only and narrowly scoped. Agents operate with allowlisted tools, step and time limits, isolated execution and explicit approval before consequential writes or external actions.

Model and component governance

Every model or major component enters through a versioned inventory, license review, integrity verification, task-specific evaluation and controlled release. A newer model is not automatically a safer or better production model.

Human authority

PULSAR supports decisions; it does not erase accountability. High-consequence engineering, safety, financial or operational outcomes require a designated human authority with enough evidence to accept, challenge or reject the recommendation.

The goal is not to remove uncertainty. It is to make uncertainty, authority and evidence visible at the moment they matter.