Charter — the assurance kernel

AI you can trust when being wrong is not an option.

Charter is our assurance kernel — the governed layer between AI reasoning and consequential action. It lets concurrent AI teams execute high-stakes missions at machine speed, while evidence, roles, authority, and action remain structurally governed.

Governed multi-agent organization Concurrent
Agent 01Propose
Agent 02Review
Agent nPrepare
Charter kernelMission law · evidence · authority
Admit / refuse
Consequential actionOne governed result. Human authority retained.
Authorized
Roles & signatures Current evidence Replayable ledger
Concurrent agent organizations
Mission-specific domain law
Human-held authority
Proven kernel guarantees
Concurrent. Governed. Scalable.

Govern the organization, not just the model.

Specialized agents work in parallel under one mission-specific law. Charter keeps proposals untrusted, separates authority, and converges the work to one replayable result.

01

Concurrent roles

Many agents propose, review, and prepare work at the same time.

03

Governed mission state

Every interleaving reconverges; consequential authority remains human.

Reasoning is not assurance

A model can understand the rules and still fail to enforce them.

A prompt-only system caught obvious violations, then accepted a forged attestation and self-review. Charter puts assurance in the architecture—not in the model’s instructions.

From “the agent should not” to “the system cannot.”
Control
Typical stack
Charter
Tools
Broad, static menu
Only admissible actions are exposed
Evidence
Fluent text can become state
Typed, current, provenance-bound evidence
Authority
One loop can propose, approve, act
Roles and signatures split power
Assurance
Logs and behavioral tests
Replayable ledger and proven invariants
One kernel. Many missions.

Concurrent teams, governed by domain law.

The same proven engine governs 7–17 agents at once across four live missions.

16concurrent agents~92s

Engineering: stale evidence cannot ship.

An unaccredited result is refused; a changed specification expires prior work; a failing rerun keeps release blocked.

Non-negotiable gateAccredited, current evidence supports the verdict.
11concurrent agents~23s

OT / ICS: the unsafe sequence is unavailable.

Network isolation must precede floor checks, and failover requires two signatures. Safe order emerges from the refusals.

Non-negotiable gateActions occur in safe order; failover has two signers.
17concurrent agents~24s

Authorization: AI prepares; only a human authorizes.

Unsupported readiness is refused. The AI never receives the authority to authorize; only the official signs.

Non-negotiable gateEvery control is evidence-bound; only the official authorizes.
7concurrent agents~56s

Cyber: no unilateral exploit.

Separate operator, command, and legal authority are required. A commander’s denial means no exploit executes.

Non-negotiable gateOperator, command, and legal authority remain separate.
Validity follows evidence

The proof expires when its basis does.

A decision remains valid only while its evidence does. There is no stale approval left standing.

01Evidence changes
02Dependent facts invalidate
03The verdict withdraws
04Affected work re-runs
Properties, not promises

Proven once. Enforced every run.

Every mission inherits the same kernel guarantees.

01
Untrusted proposals

Only an admitted transition can change state.

02
Human authority

No AI role can authorize a consequential decision.

03
Structural governance

Illegal states are unreachable, not merely detected.

04
Tamper-evident replay

An append-only ledger recreates the exact decision path.

05
Safe concurrency

Concurrent interleavings reconverge to one result.

06
Model independent

The proofs cover the kernel—not a particular model.

Check the proof. Do not trust the builder. Machine-checked in Lean, with a one-page trust base.
Machine-checked
Early access · design partners

Bring Charter to your hardest mission.

Six Gates is onboarding a small group of early adopters across defense, energy, and critical infrastructure. If being wrong is not an option for your mission, let’s talk — we’ll set up a briefing and a scoped pilot.