The mental model
Grant
A bounded authority a named human signed for: what this agent may do, up
to what value, until when, under what conditions. Not a service account.
Gate
Nine checks in a fixed order. Cheap structural ones first, so an action
refused at gate 1 never reaches policy evaluation.
Record
Every decision, allowed or refused, sequenced and sealed. The refusals are
the half that proves the control operated.
What it is not
It does not evaluate models. Evaluation tells you how a system scores on a benchmark. This states what an agent may do. Most teams need both, and they are different products. See how this differs. It does not make you compliant. It assembles evidence, maps it to clauses, computes what it can, and names what it could not find. Whether that satisfies your obligations is regulatory interpretation and it rests with you and your counsel. That disclaimer sits inside the signed payload of every evidence pack, so removing it invalidates the signature. It does not call an LLM. Not for summaries, not for classification, not anywhere. A test fails the build if a model provider appears in the dependency graph.Where it runs
Single-tenant, in your environment: your cloud, your data centre, or airgapped. No payload reaches Rotascale on any code path, and the deployment refuses to start if a setting selects a service outside your network. It also tells you which evidence property you gave up by disconnecting it.Where to go next
Quickstart
Three lines in your agent’s own code, and a refusal you can see.
The nine gates
What each one asks, in the order they run, and why the order matters.
Enforcement ladder
Observe, shadow, canary, enforce. Nothing refuses until you say so.
Live demo
A running deployment, not a recording. Real agents, real refusals.

