{
  "control_plane": [
    {
      "capability": "Capture decisions, inputs, tool calls, approvals, artifacts, outcomes, and debug reports in an evidence trail.",
      "id": "record-every-step",
      "name": "Record every step"
    },
    {
      "capability": "Evaluate every covered action as allow, ask, or deny using mission scope, tool policy, owner authority, and connector state.",
      "id": "policy-enforcement",
      "name": "Enforce policy"
    },
    {
      "capability": "Suspend or quarantine agents when they drift from mission, hit denied tools, miss approvals, exceed limits, or use stale/revoked evidence.",
      "id": "stop-and-quarantine",
      "name": "Stop unsafe agents"
    },
    {
      "capability": "Require exact artifact, target, policy, budget, and expiry bindings before consequential actions are released.",
      "id": "owner-approval",
      "name": "Bind owners to decisions"
    },
    {
      "capability": "Inventory agents, templates, policies, connectors, memory scopes, model routes, versions, rollbacks, and kill switches across teams.",
      "id": "fleet-operations",
      "name": "Govern agent fleets"
    }
  ],
  "generated_at": "2026-10-05T22:21:39Z",
  "governed_loop": {
    "promise": "An agent is a worker inside a governed loop, not the owner of the business decision.",
    "required_contracts": [
      "mission contract",
      "owner binding",
      "input/output schema",
      "evidence and freshness rules",
      "policy and tool registry",
      "budget/time/retry limits",
      "outcome metric",
      "rollback plan"
    ],
    "stages": [
      "objective",
      "clean data and evidence",
      "bounded work",
      "authorized action",
      "outcome measurement",
      "reviewed improvement proposal"
    ]
  },
  "mass_adoption_model": [
    "Make agent creation fast, visual, and free enough for individuals and teams.",
    "Make AgentGuard the default upgrade when users need production trust, team control, compliance evidence, safe memory, and fleet operations.",
    "Let creators and teams share templates, but require AgentGuard trust review before marketplace publishing or live connector access."
  ],
  "memory_and_learning": {
    "memory_types": [
      {
        "approval": "policy scoped",
        "id": "session",
        "scope": "one run or conversation"
      },
      {
        "approval": "human review before replay",
        "id": "task",
        "scope": "learned workflow steps, selectors, expected signals, and variants"
      },
      {
        "approval": "data-owner governed",
        "id": "customer",
        "scope": "approved customer/account facts"
      },
      {
        "approval": "owner governed",
        "id": "team",
        "scope": "approved SOPs, preferences, playbooks, and domain rules"
      },
      {
        "approval": "release governed",
        "id": "model",
        "scope": "versioned model prompts, weights, routing policy, and eval results"
      }
    ],
    "safe_learning_path": [
      "observe",
      "reconcile",
      "propose",
      "test",
      "approve",
      "release",
      "monitor"
    ],
    "self_learning_rule": "Self-learning may improve drafts, routing, memory, or recommendations inside approved limits; production policy, credentials, budget, and permissions require explicit approval."
  },
  "positioning": {
    "free_boundary": "Users can build, export, and run as many agents as they want with local trial controls.",
    "headline": "Build unlimited agents; govern the operations that matter.",
    "non_claim": "AgentGuard does not read a model's private reasoning or guarantee model correctness; it governs covered actions, evidence, model routes, and outcomes.",
    "paid_boundary": "AgentGuard becomes valuable when teams need centralized policy, approvals, evidence, fleet visibility, audit exports, governed memory, and production controls."
  },
  "schema": "safecadence.agentguard.governed-ops.v1",
  "small_model_ops": {
    "deployment_modes": [
      {
        "id": "rules-only",
        "name": "Rules only",
        "route": "rules.evaluate",
        "use": "Strict workflows, deterministic checks, and zero model dependency."
      },
      {
        "id": "small-model",
        "name": "Small task model",
        "route": "model.small.classify/model.small.extract",
        "use": "Classifiers, extractors, ranking, routing, spam/scam detection, form parsing, and narrow intent recognition."
      },
      {
        "id": "local-llm",
        "name": "Local LLM",
        "route": "llm.local.call",
        "use": "Private drafting, summarization, and reasoning where data should stay local."
      },
      {
        "id": "hybrid",
        "name": "Hybrid routing",
        "route": "model.route",
        "use": "Sensitive work stays local; public model calls require explicit policy and approval."
      }
    ],
    "guardrails": [
      "no secrets in model-visible context",
      "memory scopes are tenant, user, task, and retention bounded",
      "models cannot grant themselves tools, budget, or production access",
      "model updates start as change proposals",
      "promotion requires test evidence and owner approval",
      "public model routes disclose destination and data class"
    ],
    "lifecycle": [
      "collect approved task examples",
      "redact and label training/eval data",
      "train, tune, prompt, or configure a narrow model",
      "run deterministic evals and regression checks",
      "bind model route to policy and owner approval",
      "deploy behind AgentGuard",
      "monitor outcomes, drift, and bad decisions",
      "rollback or propose a new version"
    ],
    "promise": "Help teams deploy small, task-specific models safely next to rules, local LLMs, public LLMs, or no-LLM workflows."
  },
  "stop_conditions": [
    "mission drift",
    "denied tool or forbidden argument",
    "missing or expired approval",
    "stale, revoked, or missing evidence",
    "budget, time, retry, or rate-limit breach",
    "unexpected side effect",
    "direct connector bypass attempt",
    "policy tamper or guardrail disable attempt",
    "model route violates data residency or sensitivity policy"
  ]
}