INDEPENDENT AGENT RELEASE AUTHORITY
Make every AI release earn production.
Scalarion binds the exact agent — its models, prompts, tools and permissions — to evidence, policy and an accountable human decision, then lets every pipeline, cloud and platform enforce the same signed authorization.
Build, check and see the verdict free — no account. Signing in is only to keep what you build.
ONE SUBJECT · ONE ENVIRONMENT · ONE EXPIRY · ONE CURRENT DECISION
RELEASE COMMAND SURFACE
- SOURCE + CIGitHub · GitLab · Jenkins
- AGENT FRAMEWORKLangGraph · CrewAI · vendor SDK
- MODELS + ROUTINGAnthropic · Bedrock · Azure AI
- TOOLS + PERMISSIONSMCP · APIs · data
- EVIDENCEprovenance · evals · security
INTERACTIVE SAMPLE FRAGMENTED CREATION ESTATE
ADMIT
AUTHORIZED
SEQ 4106sha256:c07b0ae8bdb152c3…8f736bf7sha256:c07b0ae8bdb152c3…8f736bf7sha256:c07b0ae8bdb152c3…8f736bf7
AUTHORITY
- prod-eu-1K8s admission · EUADMIT
- prod-us-2GitHub deploy gate
- staging-eu-1Argo CD sync gate
One exact subject, one environment, one expiry. role:head-of-underwriting holds outcome authority; rollback owner named; quorum satisfied.
digest match
02 · THE MUTABLE APPROVAL GAP
Your approval is attached to a ticket. Production receives a different object.
The ticket is approved, the eval dashboard is green — and the release presented to production is no longer the release that was reviewed. Both lanes below are watching the same mutation you trigger above.
EXISTING WORKFLOW · TICKET → MUTABLE NAME
- subject
- "underwriting-triage"
- ticket
- RISK-4181 · approved 02 Jul
- eval board
- green
- candidate
- unchanged
STATUS · APPROVED ✓ · DEPLOY CONTINUES
Still green. The name did not change, so nothing here noticed that the release did. This approval now vouches for something it never reviewed.
SCALARION · AUTHORIZATION → IMMUTABLE DIGEST
- subject
- sha256:c07b0ae8bdb152c3…8f736bf7
- bound to
- prod-eu-1 · expiry · owner · quorum
- candidate
- sha256:c07b0ae8bdb152c3…8f736bf7
digest match · ADMIT · exit 0
The digest is the release. A changed candidate is a different subject, and no authorization exists for it. The old authorization remains historically valid — for the old subject only.
03 · WHERE SCALARION SITS
One authority plane across a heterogeneous agent estate.
Every system below owns a fragment — source, framework, model, tools, evidence, delivery. None of them answers whether this exact agent release may act in this environment, now. Scalarion owns only that relation. Provenance and attestations flow in as evidence; the authorization is a separate, revocable decision.
1 · CREATE
Source, agent framework, model routing, tools and data. Many owners, all mutable.
2 · PROVE
SLSA provenance, evals, security and policy checks — consumed as evidence, never as the authorization itself.
3 · DECIDE
SCALARION
Exact subject + policy + accountable human authority, sealed as a release-authorization predicate in an in-toto Statement, carried by a DSSE-compatible envelope.
4 · ENFORCE
CI, GitOps, Kubernetes admission or platform pre-deploy hook verifies and admits or denies.
5 · OPERATE
Change, drift and incident watchers suspend, revoke or narrow authority when facts change.
6 · VERIFY
Audit, procurement, insurer or customer verifies the same envelope offline, without trusting Scalarion.
- Generic CLI / API — any stackDESIGN PARTNER
- GitHub Actions / deploy gateDESIGN PARTNER
- GitLab · Azure DevOps · Jenkins · ArgoNEXT
- Trust network · third-party verifiersEXPLORING
GitHub deployment protection rules are a GitHub public-preview feature; private and internal repositories require GitHub Enterprise. The generic CLI/API path works in any CI. Availability labels come from one claim registry — nothing renders AVAILABLE without proof.
04 · THE RELEASE DECISION ROOM
The people saying yes finally review the same release.
Security, risk, engineering and the outcome owner see one Decision Lens: the exact diff, the requested authority, the evidence state, and the scoped options. Under two minutes to a defensible decision.
- diff
- none — current authority
- consequence
- quotes ≤ $50k, no funds movement
- evidence
- evals ✓ · security ✓ · provenance ✓
- outcome owner
- head-of-underwriting
- rollback owner
- platform-lead
- quorum
- 2 of: risk, security, business
A new subject and sequence. The prior decision is superseded in history — never edited.
WHY SCOPED AUTHORITY
A blanket yes to a payments-capable agent is not a decision, it is an abdication. Conditions make the yes exact: how much rollout, which holds, how long. The gate enforces the scope, not the sentiment.
WHAT THE APPROVER SIGNS
Not a ticket. A release-authorization predicate binding the exact digest, environment, conditions and expiry — sealed in a DSSE-compatible envelope under an ECDSA P-256 / SHA-256, AWS KMS-backed key. Their authority is in the object, not beside it.
Outcome: fewer days reconciling approvals, no approval silently following a changed release, and one audit reconstruction instead of bespoke evidence hunts per reviewer.
05 · ONE DECISION PROPAGATES EVERYWHERE
A decision the delivery system can act on.
The UI is not the enforcement point. It issues the artifact the enforcement points consume — the same state, sequence and reason code everywhere. All five surfaces below derive from the decision you made above.
CI JOB · generic CLI
$ scalarion admit --env prod-eu-1
ADMIT
AUTHORIZED · seq 4106
exit 0
GITHUB DEPLOYMENT GATE
scalarion / release-authority
AUTHORIZED
K8S ADMISSION · prod-eu-1
admission webhook · scalarion
ADMIT · seq 4106
ADMISSIONS LEDGER · SAMPLE
- #4105 AUTHORIZE role:head-of-underwriting
- #4106 ADMIT ci:github/deploy-prod
OFFLINE VERIFIER
✔ envelope · in-toto Statement
✔ sig · ECDSA P-256 / KMS
06 · CONTINUOUS REAUTHORIZATION
Authority expires when its facts stop being true.
Your earlier tool-scope expansion traced this exact path — only the affected dependencies re-open, not the whole audit:
- tool scopesecurity evidence: missing for payments
- policyquorum required: risk + security
- authorizationsuspended for the new subject
- re-decisionnew sequence · scoped conditions · old decision superseded
THE ONLY SLOW TRANSITION ON THIS PAGE
Evidence freshness decays gradually, so it is the one thing allowed to take time — a ~2s degradation to ACTION_REQUIRED. Every other transition — admit, deny, revoke, supersede — changes state on the frame it happens.
to watch authority decay rather than break.
07 · ORGANIZATIONAL RELEASE SYSTEM
From one protected release to the operating system for agent authority.
The portfolio answers four questions — and keeps authorization and deployment as independent axes. No composite risk score.
WHAT IS RUNNING?
14 agents · 6 environments
observed at the boundary, not self-reported
WHAT IS AUTHORIZED?
11 current authorizations
each bound to one digest, one environment
WHAT EXPIRES SOON?
3 within 7 days
expiry spends authority automatically
WHERE IS THE GATE MISSING?
2 running × revoked or ungated
the drift the category exists to catch
ILLUSTRATIVE PORTFOLIO · INTERACTIVE SAMPLE — NOT LIVE TELEMETRY
08 · PORTABLE TRUST
Verify the decision without trusting the dashboard — or Scalarion.
The authorization is a release-authorization predicate in an in-toto Statement, carried by a DSSE-compatible envelope, signed with an ECDSA P-256 / SHA-256 key backed by AWS KMS. Copy the sample — its subject digest is the one this page computed — and inspect it anywhere.
Raw prompts and traces need not be disclosed: hashes and scoped references are sufficient for third-party verification. SLSA provenance enters as evidence; it is never the authorization.
THE ARTIFACT · ISSUED BY THE AUTHORITY PLANE
INTERACTIVE SAMPLESEALED · SEQ 4106
{
"_comment": "INTERACTIVE SAMPLE — locally generated, unsigned",
"payloadType": "application/vnd.in-toto+json",
"payload": {
"_type": "https://in-toto.io/Statement/v1",
"subject": [
{
"name": "underwriting-triage",
"digest": {
"sha256": "c07b0ae8bdb152c3557af8a5d9fc20c4eef27f134aaf8c2d9b5a4a428f736bf7"
}
}
],
"predicateType": "https://scalarion.dev/release-authorization/v1",
"predicate": {
"environment": "prod-eu-1",
"approver": "role:head-of-underwriting",
"conditions": [],
"notAfter": "2026-09-14T00:00:00Z",
"revocable": true,
"decisionSequence": 4106
}
},
"signatures": [
{
"keyid": "kms-ecdsa-p256 (sample — unsigned in this prototype)",
"sig": null
}
]
}WHAT A VERIFIER CHECKS · SAMPLE · NO CLI SHIPS YET
1 · fetch /.well-known/scalarion-trust.json 2 · match the envelope keyid to a published key 3 · verify the signature against that key alone
- · statement in-toto Statement v1
- · predicate scalarion release-authorization
- · signature ECDSA P-256 / SHA-256 · KMS-backed
- · subject digest bound to this release
- · revocation checked against cached CRL h=4106
AUTHORIZED · exit 0
09 · RELEASE AUTHORITY SPRINT
Protect one consequential release in a real delivery path.
One consequential agent. One protected production environment. One canonical release subject. One accountable decision workflow. One installed fail-closed gate. One demonstrated mismatch denial. Measured baseline and outcome. 30–45 days.
Not a fit if the agent has no consequential action, no named production boundary, or no decision authority who can participate. We would rather say so now.
Next step after this form: we map one release path and identify the enforceable boundary before proposing a sprint. No account creation, no generic demo.
QUALIFICATION · 90 SECONDS · NO ACCOUNT REQUIRED
YOUR DETAILS GO TO THE SCALARION TEAM. NO ACCOUNT IS CREATED, NOTHING IS SHARED ONWARD, AND YOU CAN ASK US TO DELETE THEM AT ANY TIME.