Authority
Who is allowed to do what? Policy gates, bounded capabilities, Judge6 decisions.
UphillSnowball wraps managed agents with policy gates, identity-bound receipts, bounded actions, recovery, and audit evidence, so security, legal, compliance, finance, and operations can approve the same system.
An agent that can talk is not an agent that can act. The gap is authority, identity, recovery, and evidence — the hydra of problems that appear the moment a demo becomes a deployed system.
UphillSnowball is the control plane for those problems. It produces evidence and controls that support compliance review. It does not claim a certification, insurance policy, or SLA it cannot show.
Who is allowed to do what? Policy gates, bounded capabilities, Judge6 decisions.
Which agent, model, revision, and operator acted? Identity-bound receipts and runtime readback.
Can prompts or tools escape the intended boundary? Capability isolation, secret separation, fail-closed validation.
What happens after a timeout, restart, or partial result? Durable resume, idempotency, replay and recovery.
Can the institution reconstruct what happened? Signed receipts, exact SHAs, traces, evidence lineage.
Can legal, finance, security, and operations review the same evidence? Shared control and evidence plane.
Can multiple managed agents coordinate safely? A2A-compatible, exactly bounded routing.
Can operators understand live behavior? Tracing, analytics, incident evidence and health surfaces.
Is context and model usage predictable? Model routing, context caching, task profiles and budgets.
Can the system be stopped or reversed? Canary promotion, prior revision rollback, effect boundaries.
Every handoff is a decision. Judge6 is a deterministic policy gate, not an autonomous agent.
Managed Agent A → Judge6 → conditional Managed Agent B → Judge6
A usable proof names the actor, the bound, the decision, the exact SHA, and how to replay it. That is the evidence security, legal, and operations can share.
Capability isolation and fail-closed tool bounds before an agent can act.
Identity-bound receipts that reconstruct who did what, with which revision.
Shared evidence that supports review. Not a claimed certification.
Task profiles and budgets so model spend is a controlled input, not a surprise.
Resume, rollback, and health surfaces after timeouts and partial results.
Timeouts, restarts, and partial results are expected. The system records them, resumes when it is safe, and can roll back a canary to a prior revision.
The trust center is the public place for security, privacy, and process. Legal drafts stay marked as drafts until counsel review.
Open the trust centerPublic Live Proof uses synthetic data. Operator consoles stay behind authentication.
Open Live ProofWork email only. Same material payload returns one synthetic receipt. No tenant is created and no card is charged.