It clicked, it typed — but did the thing actually happen?
Computer-use and browser agents act by driving real apps: filling forms, clicking buttons, moving data between systems with no API in sight. That makes their claims the hardest to trust — and the most important to verify. GOVENANT records the action at the boundary and checks the downstream effect in the system of record.
GOVENANT does not govern “Claude agents” or “OpenAI agents.” It governs the evidence trail of autonomous work. Keep the runner (the tool you audit from) separate from the system under audit (your agents):
An AI client you already use reads the open instrument and drives the read-only sweep. This is the runner — not the thing being judged.
Any agent system with an observable record of actions and outcomes — whatever built it. The agent never has to "support GOVENANT."
Ground truth: the database + actions + outcomes + duties + gates — the substrate, never the logs’ self-report.
UI automation has no clean return value — a click can “succeed” and change nothing. The standard ignores the click and checks the record: did the row appear, did the status change, did the effect land?
GOVENANT operates at the action boundary and does not need the agent’s prompts, reasoning, or model — only an observable outcome. That’s exactly what makes it work for screen-driving agents no framework can hook.
Computer-use agents can touch anything a human can. Register the consequential targets as levers with named owners; unowned or unexpected actions stop at the gate before they reach production.
An operations team runs a computer-use agent to move data between two systems that have no API — it drives the browser, fills the forms, clicks submit.
The agent reports every step “succeeded,” but a click can succeed and change nothing. There’s no return value to trust and no way to know, from the agent’s own logs, whether the record actually landed in the target system.
GOVENANT ignores the click and checks the effect: did the row appear in the target system, did the status change? The record shows a 6% silent-failure rate — forms that submitted “successfully” but wrote nothing — that no screenshot log would ever have caught.
The substrate: The downstream systems the agent touches: the record it created, the form it submitted, the value it changed — the effect, verified where it lands, not the screenshot of the click.
The path — Instrumented boundary: Add a thin hook at the action boundary — no access to prompts, reasoning, or models — so every action and its outcome is recorded.
The full requirements live in the open standard (CC BY 4.0) — the substrate shapes, the acceptance tests, and the conformance ladder your record is measured against.
A real integration wears the Built-on badge and publishes self-assessed levels with probe logs — open to challenge, never “certified.” For computer-use agents, a record that keys “done” to verified downstream effect is the difference between an impressive demo and a trustworthy operator.
Per-stack integration patterns for common ways to build browser & computer-use agents — each with its own natural hook into the substrate:
Building it a different way? Browse all integrations — or run the free audit from any MCP-capable tool.