When agents act on the physical world, “it worked” must be sensed, not claimed.
Autonomous and robotic systems close the loop from decision to physical action, where an unverified outcome is a safety event, not a bad metric. GOVENANT records each commanded action and keys completion to a sensed, verified outcome — and pins the high-consequence actuations to human authority.
GOVENANT does not govern “Claude agents” or “OpenAI agents.” It governs the evidence trail of autonomous work. Keep the runner (the tool you audit from) separate from the system under audit (your agents):
An AI client you already use reads the open instrument and drives the read-only sweep. This is the runner — not the thing being judged.
Any agent system with an observable record of actions and outcomes — whatever built it. The agent never has to "support GOVENANT."
Ground truth: the database + actions + outcomes + duties + gates — the substrate, never the logs’ self-report.
The controller saying “task complete” is not the task being complete. The standard keys delivery to the verified signal — the sensor, the downstream state — never the command’s own return.
The most consequential actuations stay pinned to human approval as permanent gates. Earned autonomy is granted per task on a proven record and revoked on a single breach.
A duty not run, a check skipped, a subsystem gone quiet — in physical systems, undetected silence is the failure mode that hurts. Coverage math makes silence itself the alarm.
A warehouse runs an autonomous orchestration agent commanding a fleet of pick-and-place robots and conveyors.
The controller logs “task complete,” but complete is a command that was sent, not an outcome that was sensed. In a physical system, an undetected silent failure isn’t a bad metric — it’s a safety and inventory event.
Completion keyed to sensed outcomes, high-consequence actuations pinned to human authority, coverage math over every duty. The record catches a subsystem that reported success while its sensor confirmed nothing — the exact silent failure the ops team most feared, now an alarm instead of a surprise.
The substrate: The task and telemetry record: commanded actions, sensor readings, and completion signals — the physical outcome, verified from instrumentation rather than the controller’s self-report.
The path — Instrumented boundary: Add a thin hook at the action boundary — no access to prompts, reasoning, or models — so every action and its outcome is recorded.
The full requirements live in the open standard (CC BY 4.0) — the substrate shapes, the acceptance tests, and the conformance ladder your record is measured against.
A real integration wears the Built-on badge and publishes self-assessed levels with probe logs — open to challenge, never “certified,” and never a substitute for functional-safety engineering. GOVENANT adds a governance-and-delivery record on top of your safety case; it does not replace it.
Per-stack integration patterns for common ways to build autonomous & robotic systems — each with its own natural hook into the substrate:
Building it a different way? Browse all integrations — or run the free audit from any MCP-capable tool.