Now shipping: two layers of agent governance

Autonomy is the whole point of AI. It's also the whole risk.

Strentis gives autonomous AI a hard boundary on what it may do, and a machine-verifiable contract for what it must deliver, enforced outside the agent, not left to its own judgment.

The shift already happened

Agents don't just answer questions anymore. They write code, hold credentials, and act while you're not looking.

That's a feature. It's why autonomous AI is useful at all. But every extra bit of autonomy you grant an agent is also an extra bit of blast radius the moment that agent is compromised, confused, or simply wrong. Most tooling today asks you to choose between a leash so short the agent is useless, or trust so wide a single bad session can touch everything it can reach.

1 session

is usually all it takes for a mis-scoped agent to touch files, keys, or systems far outside the task it was actually given.

0 blast radius

is what a properly contained agent leaves behind, even when it's compromised — because containment was enforced by the kernel, not by the agent's own good behavior.

Our products

Two layers of a governed agent stack.

Layer one decides what an agent is allowed to do. Layer two decides whether it did what it agreed to. Both rely on real evidence: kernel enforcement, file contents, and exit codes. They never rely on an agent's own self-report.

Layer 1 — Authority
agent-immune
Runs Claude Code, Codex, or any coding agent inside a kernel-enforced authority boundary. Anything outside the session's granted scope requires human approval.
# give an agent a narrow, real authority ceiling
$ agent-immune init .
$ agent-immune run --session backend --write ./backend -- claude

# it asks, you decide
$ agent-immune pending
$ agent-immune approve <id>

# the moment a session's authority goes bad
$ agent-immune quarantine backend
→ that session, and every descendant, stopped instantly.
→ every other session keeps working, untouched.
working name: "anti-agentic" — a better one is coming
Layer 2 — Obligation
agent-contract
Machine-checkable agreements between agent-immune sessions. Define what a hired agent must deliver before it starts, then get a fulfilled or breached verdict based on real evidence. The agent never gets to grade its own work.
# say exactly what counts as done, before the agent starts
$ agent-contract propose --hirer orchestrator --hired worker \
    --write ./work --deadline 600 \
    --deliverable ./work/report.json --schema ./report.schema.json \
    --verify-script ./verify.py --verify-write ./verify_scratch \
    --reason "analyze the dataset"

# hire it, exactly as you'd run it yourself
$ agent-contract run <id> -- claude -p "analyze the dataset..."
→ status=needs_trust (a human still approves cross-session reads)

$ agent-immune approve-trust <id>
$ agent-contract verify <id>
→ status=fulfilled
requires agent-immune — every action goes through it, nothing is bypassed

How it works

Containment enforced by the kernel, not by convention.

agent-immune provides the enforcement layer underneath the stack. agent-contract builds on that same boundary, so contract execution and verification inherit the same containment and artifact-trust guarantees.

01

Authority ceiling

Every session starts with an explicit boundary set by a human. Landlock and bubblewrap enforce what the agent can access and modify at the OS level, outside the agent's own control.

02

Human approval when needed

An agent can ask for more authority, but it cannot grant that authority to itself. A human must approve the request, and the added authority only applies to the session's next execution.

03

One command to quarantine

Quarantine one compromised session and its entire authority branch is stopped with it. Descendants, pending requests, and unused grants are revoked while unrelated sessions keep running.

04

Artifact-bound trust

Code produced by a lower-authority agent does not automatically inherit the authority of whoever reads or runs it. Trust requires human approval and is bound to the artifact's exact contents and consumer session.

05

Fails closed

If a required protection cannot be verified, agent-immune refuses to launch the session. Missing kernel support or sandboxing never results in a silent downgrade.

06

No new infrastructure

No daemon, cloud service, or account. Install one local tool and run the coding agents you already use through it.

Why Strentis

The next decade of software is agentic by default. The systems that win won't be the ones that trust their agents the most. They'll be the ones that don't have to.

Pre-alpha
agent-immune

Authority. What is an agent allowed to do?

→
Pre-alpha
agent-contract

Obligation. What did it agree to do, and did it?