Skip to main content

Multi-agent runtime safety · v1.2.0 enforcement baseline

Runtime safety
for multi-agent
AI systems

Constrain delegated authority, coordinate shared approvals, and trace cross-agent effects. The shipped v1.2.0 kernel remains the enforcement baseline; MAS guarantees are the active research program.

ActantOS gateway coordinating approval admission across multiple agents

Coordinate approval admission across agents

Test whether one shared approval admits at most one authorized execution when heterogeneous agents race, retry, crash, recover, or lose connectivity. The v1.2.0 kernel is the baseline, not proof of the MAS property.

Explore platform
ActantOS evidence graph linking decisions and effects across agents

Distinguish cross-agent effects from missing evidence

Link delegation, policy, approval, executor, and destination evidence while distinguishing attempted, accepted, committed, observed, and unknown outcomes. Omission-aware verification is a research target, not a broad novelty claim.

Read Documentation

Live enforcement

Watch the kernel decide

Every tool call is intercepted, evaluated against policy, and either blocked, paused for approval, or allowed — with evidence.

actantos kernel

Research direction

Coordinate,constrain,andverifymulti-agentactionsbeforetheyreachrealsystems.Runtimesafetyforagentsthatdelegate,race,andhandoffwork.

Now shipping · v1.2.0

Quiet Open-Core is the public baseline

ActantOS v1.2.0 is the truthful enforcement baseline: a policy firewall between agents and the systems they act on. The multi-agent program extends that baseline toward shared approval admission, delegation constraints, partial-failure safety, and cross-agent evidence. Those MAS properties remain bounded research hypotheses until independently verified.

  • v1.2.0 Quiet Open-Core: self-host Enforcement Kernel (Mode A public baseline)
  • Runtime enforcement: intercept → decide → execute or block → audit
  • Cedar policy, human approvals (web/Slack), Docker sandbox, local evidence export
  • Pi coding path primary · MCP gateway optional · frozen /v1 API
  • MAS coordination guarantees remain research hypotheses, not shipped v1.2.0 claims

The Challenge

Multi-agent coordination creates system-level risk

Per-agent controls do not settle shared approvals, delegation chains, concurrent races, partial failures, or missing effect evidence. ActantOS turns those gaps into testable runtime-safety properties.

Competing agents, one shared approval

Concurrent executors can race to consume the same authority, producing duplicate or ambiguous admissions unless the protocol makes the invariant explicit.

Illustration of multiple agents competing for shared authority

Delegation without constraint preservation

Agent handoffs can widen scope, change destination, or detach an action from the human and policy context that originally authorized it.

Illustration of an agent delegation chain across platforms

Partial failures split decision from effect

Timeouts, partitions, crashes, retries, and ambiguous destination outcomes can leave approval state and real-world effects out of sync.

Illustration of a multi-agent workflow under partial failure

Evidence can be incomplete

A successful log write does not prove an external effect committed, and a missing receipt does not prove nothing happened. Verification must represent unknown outcomes.

Illustration of cross-agent evidence and an unknown effect outcome

From enforcement kernel to multi-agent safety

ActantOS connects today's policy boundary to a research program for coordination safety under concurrency and partial failure.

Shared approval admission

Hypothesis C1: at most one successful authorization admission across heterogeneous executors under declared races, duplicates, crashes, recovery, and partitions.

Delegation constraints

Preserve principal, scope, destination, expiry, and workflow context as authority moves through agent handoffs.

Approval–decision–effect safety

Hypothesis C2: test the coupled invariant under a declared failure model, including ambiguous destination outcomes and bypass attempts.

Omission-aware effect evidence

Hypothesis C3: independently check causal evidence while representing attempted, accepted, committed, observed, and unknown states.

Policy EnforcementAudit LogsAgent IdentityRBACHuman in the loopProxy
ComplianceGuardrailsSecure VaultApproval WorkflowsMulti-Agent SystemsDelegation Safety
SOC2Access ControlData PrivacyLLM GovernanceCost LimitsTool Constraints

Govern the whole agent workflow.

Install the kernel, place each executor behind policy, and exercise delegation, competing-agent approvals, and failure cases as one coordinated system.

Agent IdentitySelf protectionLLM Governance
DiscoverabilityCost LimitsCompliance
RBACAudit LogsData Privacy

Test claims before you trust them.

Separate attempted, accepted, committed, observed, and unknown effects in every pilot.

Request demo
ActantOS

Verify Multi-Agent Workflows Before Effects Escape

Questions?

Find the answers to your questions about ActantOS. Contact us if you need further insights.

It tests three bounded runtime-safety hypotheses: shared approval admission under concurrency, coupled approval–decision–effect safety under declared failures, and omission-aware effect evidence. These are research targets built on the v1.2.0 enforcement baseline, not claims that broad MAS novelty or exactly-once external effects are already proven.
ActantOS sits between your AI agents and your internal/external tools. It acts as an intelligent proxy that intercepts tool calls, evaluates them against your defined policies, and either blocks, pauses for approval, or allows the action.
As agents become more autonomous and capable of taking actions (like writing to databases or calling external APIs), the risk of hallucinations or malicious prompts causing harm increases. ActantOS ensures agents stay within strict boundaries.
No. ActantOS is completely model-agnostic. It works with OpenAI, Anthropic, Gemini, or any open-source model. It sits at the application/tool layer, not the generation layer.
Follow the work guide: npm run quickstart on any computer with Node 22+, then Compose for team use — /blog/how-to-use-actantos-at-work. Mode A public baseline is Quiet Open-Core v1.2.0 (Stage 1 kernel). Stage 2 ops may be locally available; Stage 3 is not the public baseline. Also /v1, /docs, and /mvp.
Quiet Open-Core self-hosts with Docker Compose today (see docs/HOSTED.md). Full multi-tenant managed SaaS and Stage 3 isolation/WORM/SIEM packaging remain paid or conditional roadmap, not a partner gate.
When a policy flags an action for review, ActantOS returns approval_required and the guarded adapter pauses execution. An approver can decide in the web interface, optional Slack flow, or webhook channel decide path. Approved actions resume with a one-use token. Microsoft Teams remains optional future work.

Team

An expert team in AI governance, security engineering, and enterprise infrastructure.

PhD. Ngô Trung Kiên

PhD. Ngô Trung Kiên

AI & Platform Architecture

PhD. Nguyễn Văn Tràng

PhD. Nguyễn Văn Tràng

Governance Policy & Business

PhD. Nguyễn Thanh Quảng

PhD. Nguyễn Thanh Quảng

Reliability & Production Operations

Meet the team →