NBX / GOVERNED-ACTION ASSURANCE

Proof before action.

Prove what was proposed, permitted, attempted, and observed.

NBX is governed-action assurance infrastructure being built for systems that can affect the external world. It separates evidence from authority, characterizes what an action could affect, preserves boundary and outcome evidence, and binds the resulting chain for independent replay.

DECISION BOUNDARY

Proposed action intake

NBX-PUBLIC-INTAKE
PROPOSAL
EXTERNAL / UNTRUSTED
PROVENANCE
REQUIRED
AUTHORITY
NOT INFERRED
PRODUCTION
DISABLED
REPLAY
MANDATORY

PRODUCT CATEGORY

Governed-action assurance for consequential change.

NBX is a governed-action assurance system designed to preserve verifiable evidence of who or what proposed an action, what supported it, whether valid external authority existed, what the action could affect, what crossed into the external world, what actually occurred, and whether the complete chain can be independently replayed.

THE CONTROL GAP

Automation can generate an action faster than an organization can prove it was authorized.

NBX is being built to insert a deterministic boundary between intent and effect. The objective is not slower automation. It is attributable automation that cannot silently convert evidence, access, or momentum into permission.

ORDINARY AUTOMATION

Execution path

  1. Model or operator proposes a change
  2. Tool access is available
  3. Workflow continues
  4. Production effect occurs
  5. Investigation happens afterward
GOVERNED ACTION PROCESSING

NBX target path

  1. Proposal enters as untrusted
  2. Identity, intent, and evidence are bound
  3. Authority remains separate
  4. Potential impact and external crossing are distinguished
  5. Outcome evidence, receipt, replay, and state persist

PUBLIC ASSURANCE MODEL

From proposed action to independently reconstructable outcome.

A buyer-readable abstraction of the NBX assurance sequence.

  1. 01UNTRUSTED REQUEST

    Proposal

  2. 02ATTRIBUTION + PURPOSE

    Identity and Intent

  3. 03SUPPORT

    Bound Evidence

  4. 04INDEPENDENT AUTHORITY

    Separate Authority

  5. 05MUTATION + BLAST RADIUS

    Impact Classification

  6. 06ADAPTER + EFFECT

    External Boundary

  7. 07ATTEMPT + RESULT

    Effect and Outcome Evidence

  8. 08RECONSTRUCT

    Decision Receipt and Replay

NON-NEGOTIABLE BOUNDARIES

NBX is designed around what automation is not allowed to assume.

Each boundary prevents a different form of silent authority transfer.

01

Evidence is not authority.

Model output, scanner results, tests, approvals, and observations remain evidence unless a separate authority boundary is satisfied.

02

Access is not permission.

Credentials and tool access do not prove that a particular action is permitted for a particular object, purpose, or time.

03

Mutation is not promotion.

A changed object does not become production-ready merely because it exists, passes a tool, or can be deployed.

04

Automation cannot self-approve.

The system proposing or executing an action cannot create its own authority by asserting intent, success, or urgency.

PLANNED FIRST PILOT

NBX Governed Change Control

An AI coding tool, human operator, CI workflow, or automation system proposes a software, configuration, infrastructure, or policy change. NBX is intended to evaluate the proposal in read-only shadow mode and preserve a replayable decision package without performing the production mutation.

No autonomous mergeNo deploymentNo credential custodyNo production mutation
Examine the pilot boundary
01Proposed change
02Identity + intent
03Bound evidence
04Separate authority
05Impact classification
06External boundary
07Outcome evidence
08Receipt + replay

COMMERCIAL WEDGE

Governed change control first. Controlled expansion later.

The initial wedge covers consequential software, configuration, infrastructure, and policy changes proposed by AI tools, human operators, CI workflows, and automation systems before merge, promotion, deployment, or another production boundary.

01Initial wedge

AI and software production

Governed assurance for consequential code, configuration, policy, and release changes before merge, promotion, deployment, or another production boundary.

  • AI-proposed code and configuration changes
  • Human-operator and CI workflow changes
  • Evidence, authority, impact, and replay review before production boundaries
02Nearest expansion

Network, cloud, and infrastructure

Governed assurance for infrastructure and operational changes where authority, blast radius, boundary crossing, and replay matter.

  • Firewall and segmentation changes
  • Cloud IAM and resource changes
  • Infrastructure configuration promotion
03Future governed domains

Security, risk, compliance, financial, and public-sector workflows

Future domain applications of the same backbone. These are controlled expansion paths, not current deployment or product-readiness claims.

  • Security, audit, risk, and compliance evidence workflows
  • Financial and distributed-system actions
  • Administrative and public-sector decision workflows

PUBLIC BUILD STATUS

Claims are separated by implementation state.

Planned architecture, future applications, and unauthorized production effects cannot be mistaken for implemented capability.

01

Implemented foundation — authority and bounded-permission separation

NBX preserves the distinction between supporting evidence and externally established authority. This does not grant authority, issue permits, hold credentials, or enable production execution.

Implemented
02

Mutation-surface and blast-radius classification

NBX is actively hardening the stage that characterizes what a proposed action may change and the scope through which consequences could propagate.

Active Build
03

Adapter boundary and external-effect assurance

Later stages are intended to evaluate whether a governed action may approach a defined external adapter and to preserve evidence of what crossed that boundary and what occurred.

Planned Next
04

Governed Change Control pilot — planned, shadow mode

The pilot remains observational and read-only. It does not merge, deploy, promote, hold credentials, issue authority, or perform a production mutation.

Planned Next

BOUNDED PILOT CONVERSATION

Bring NBX one consequential action boundary.

Describe one action family, the initiating workflow, its evidence sources, the external authority boundary, the bounded change surface, and the receipt or replay outcome your organization must retain.