Conformance
Four levels. Earned, never granted.
GOVENANT conformance measures an AI agent system against the standard's audit instrument — with the database as ground truth, never the logs' self-report. Levels are self-assessed and open to anyone's challenge, like WCAG A/AA/AAA: no authority hands out a stamp. Two rules keep a claim honest: the verdict is the minimum of the load-bearing pillars (no averaging away a dead gate), and every claim cites its probe log — a result that never survived a refutation attempt is asserted, not measured.
GOVENANT-1 · Logged
Every AI action is recorded — input, output, model cost, outcome — in one append-only record. The floor of accountability: you can always answer "what did the AI do?"
GOVENANT-2 · Gated
Authority is structural: an agent cannot act outside its charter — enforced in code, not requested in prompts — and every outbound artifact passes a validation gate that never fails open. You can answer "what stops it?" without pointing at a sentence.
GOVENANT-3 · Delivered + Covered
"Done" means a verified outcome exists in the database — and every responsibility sits on a duty roster diffed against reality daily, so silence itself raises an alarm. This is the level at which "performed autonomy" is prevented on covered actuation paths and caught by the audit instrument everywhere else.
GOVENANT-4 · Earned
Autonomy is granted per task on a proven track record, revoked on a single breach — and regulated actions are pinned to human approval forever, in code no configuration can defeat. The system predicts the effect of its decisions and is graded against reality: it knows its own hit-rate.
The summit is unclaimed
Nobody has topped this ladder yet. That's the point.
The lower rungs are running in production today — the reference implementation publishes its record nightly: five of nine tenants verified ALIVE, 21,000+ ledgered duty-runs at a 98.4% verified-delivery ratio, every miss on the record (live numbers in the registry). But GOVENANT-3's full-coverage bar — every responsibility mapped, every miss reasoned — has been met by no system yet, including ours. That's calibration, not weakness: a ladder anyone could top on day one wouldn't be worth climbing, and a level claim only means something because the bar doesn't bend — not even for the people who wrote it.
The first system to publish a COVERED probe log takes a distinction no one else can ever have. The registry holds its front-row seat.
Race us to the top →The badge program
Built on GOVENANT · self-declared, free
For products whose agent actions genuinely run through GOVENANT mechanisms — the record, the gates, outcome-verified completion. Usable today under four rules: real integration, steward disclosure, a link to the standard, and no implication of certification.
Badge policy & embed code →Level badges · registry-listed only
Reserved for a level claim that's published in the registry — each badge links to a registry entry citing its probe log, and is open to refutation by anyone. No product wears one yet, including ours. That discipline is what will make them worth wearing.
The registry →Where GOVENANT sits in the trust stack
Enterprise AI trust has two layers, and they don't substitute for each other. GOVENANT is deliberately one of them.
Safety & controls certifications
e.g., SOC 2-style AI standards such as AIUC-1
Audit your risk posture: policies, adversarial testing, data controls, access management. They answer "will this agent hurt us?" — essential, and not what GOVENANT does.
GOVENANT
The delivery & governance layer
Audits your operational record: verified delivery, per-duty coverage, graded predictions — continuously, from the system's own database. It answers "is this agent actually doing its job — and can anyone prove it?"
No controls framework detects performed autonomy — an agent that passes every safety check while shipping nothing leaves no trace a controls audit can see. And GOVENANT doesn't replace adversarial-robustness testing. Serious deployments carry both. "They certify the brakes; we certify the odometer."
How to use GOVENANT
As a buyer
Ask every AI agent vendor one question: "What GOVENANT level are you — and can I see the probe log?" It costs you nothing, it reprices every vendor conversation, and any vendor can be measured against the standard — it's open. If they can't answer, ask why their agents can't prove their work.
As a builder
Read the standard (free, CC BY), implement the three laws, wear the Built on GOVENANT badge when the integration is real, then measure your agents and climb the ladder. A published conformance claim, backed by its probe log, turns your enterprise security-questionnaire pain into a one-page attachment.
Ready to measure your agents?
Point the standard's audit instrument at your own system — free, open, and in your environment — and learn exactly what your AI does versus what it performs. Want a second pair of eyes? We offer a hands-on review: read-only, 1–2 weeks.