Govern the pipes once. Govern every client.
This is the killer architecture. Put a governing gateway at the MCP or A2A boundary and every agent behind it inherits a ledger and ownership gates — no per-framework adapter, no SDK dependency. Govern the pipes once; govern every client. (The GOVENANT Audit itself ships as an MCP server.)
GOVENANT does not govern “Claude agents” or “OpenAI agents.” It governs the evidence trail of autonomous work. Keep the runner (the tool you audit from) separate from the system under audit (your agents):
An AI client you already use reads the open instrument and drives the read-only sweep. This is the runner — not the thing being judged.
Any agent system with an observable record of actions and outcomes — whatever built it. The agent never has to "support GOVENANT."
Ground truth: the database + actions + outcomes + duties + gates — the substrate, never the logs’ self-report.
Every agent that speaks the protocol inherits governance from the boundary — no per-framework adapter, no SDK dependency, no redeployment of the agents themselves.
Protocol boundaries are where tool calls and tasks already flow. A governing gateway makes that boundary an ownership gate and an append-only ledger — the two hardest substrate requirements, solved at the layer designed for interception.
Cross-vendor agent ecosystems only work if the work is provable across trust boundaries. A ledgered protocol boundary is how two organizations’ agents cooperate and both sides keep a record they trust.
A platform team standardizes 60 internal agents across five frameworks on MCP so any agent can reach any tool.
Governance would mean 60 bespoke integrations — one per agent — and it still wouldn’t cover the next team’s agents. Tool calls flow through the protocol, but nothing ledgers them or checks ownership at the boundary.
A governing MCP gateway ledgers every tool call and enforces ownership gates for every client at once. One integration, whole ecosystem: the record shows which agents call which tools, what verifiably resulted, and where an unowned call was stopped at the gate — framework-independent.
The substrate: The protocol boundary: every tool call and task already flows through it — the natural place for an append-only ledger and an ownership gate.
The path — Protocol chokepoint: Govern the pipe once (MCP/A2A gateway) and every agent behind it inherits a ledger and ownership gates — regardless of framework.
The full requirements live in the open standard (CC BY 4.0) — the substrate shapes, the acceptance tests, and the conformance ladder your record is measured against.
A governed protocol boundary lets every system behind it claim a real, inspectable ledger — and the gateway operator can publish its own conformance record to the registry with probe logs. As always: self-assessed, open to challenge, never “certified.”
Per-stack integration patterns for common ways to build MCP & agent protocols — each with its own natural hook into the substrate:
Building it a different way? Browse all integrations — or run the free audit from any MCP-capable tool.