SCALARION

INDEPENDENT AGENT RELEASE AUTHORITY

Make every AI release earn production.

Scalarion binds the exact agent — its models, prompts, tools and permissions — to evidence, policy and an accountable human decision, then lets every pipeline, cloud and platform enforce the same signed authorization.

Build, check and see the verdict free — no account. Signing in is only to keep what you build.

ONE SUBJECT · ONE ENVIRONMENT · ONE EXPIRY · ONE CURRENT DECISION

Book a release-authority reviewBuild, check and see the verdict free — no account. Signing in is only to keep what you build.

RELEASE COMMAND SURFACE

  • SOURCE + CIGitHub · GitLab · Jenkins
  • AGENT FRAMEWORKLangGraph · CrewAI · vendor SDK
  • MODELS + ROUTINGAnthropic · Bedrock · Azure AI
  • TOOLS + PERMISSIONSMCP · APIs · data
  • EVIDENCEprovenance · evals · security

INTERACTIVE SAMPLE FRAGMENTED CREATION ESTATE

ADMIT

AUTHORIZED

SEQ 4106
RESTORE AUTHORITYsha256:c07b0ae8bdb152c3…8f736bf7
SAMPLEsha256:c07b0ae8bdb152c3…8f736bf7

sha256:c07b0ae8bdb152c3…8f736bf7

AUTHORITY

  • prod-eu-1K8s admission · EUADMIT
  • prod-us-2GitHub deploy gate
  • staging-eu-1Argo CD sync gate
CURRENT AUTHORITYAUTHORIZEDexit 0

One exact subject, one environment, one expiry. role:head-of-underwriting holds outcome authority; rollback owner named; quorum satisfied.

digest match

02 · THE MUTABLE APPROVAL GAP

Your approval is attached to a ticket. Production receives a different object.

The ticket is approved, the eval dashboard is green — and the release presented to production is no longer the release that was reviewed. Both lanes below are watching the same mutation you trigger above.

EXISTING WORKFLOW · TICKET → MUTABLE NAME

subject
"underwriting-triage"
ticket
RISK-4181 · approved 02 Jul
eval board
green
candidate
unchanged

STATUS · APPROVED ✓ · DEPLOY CONTINUES

Still green. The name did not change, so nothing here noticed that the release did. This approval now vouches for something it never reviewed.

SCALARION · AUTHORIZATION → IMMUTABLE DIGEST

subject
sha256:c07b0ae8bdb152c3…8f736bf7
bound to
prod-eu-1 · expiry · owner · quorum
candidate
sha256:c07b0ae8bdb152c3…8f736bf7

digest match · ADMIT · exit 0

The digest is the release. A changed candidate is a different subject, and no authorization exists for it. The old authorization remains historically valid — for the old subject only.

03 · WHERE SCALARION SITS

One authority plane across a heterogeneous agent estate.

Every system below owns a fragment — source, framework, model, tools, evidence, delivery. None of them answers whether this exact agent release may act in this environment, now. Scalarion owns only that relation. Provenance and attestations flow in as evidence; the authorization is a separate, revocable decision.

  1. 1 · CREATE

    Source, agent framework, model routing, tools and data. Many owners, all mutable.

  2. 2 · PROVE

    SLSA provenance, evals, security and policy checks — consumed as evidence, never as the authorization itself.

  3. 3 · DECIDE

    SCALARION

    Exact subject + policy + accountable human authority, sealed as a release-authorization predicate in an in-toto Statement, carried by a DSSE-compatible envelope.

  4. 4 · ENFORCE

    CI, GitOps, Kubernetes admission or platform pre-deploy hook verifies and admits or denies.

  5. 5 · OPERATE

    Change, drift and incident watchers suspend, revoke or narrow authority when facts change.

  6. 6 · VERIFY

    Audit, procurement, insurer or customer verifies the same envelope offline, without trusting Scalarion.

  • Generic CLI / API — any stackDESIGN PARTNER
  • GitHub Actions / deploy gateDESIGN PARTNER
  • GitLab · Azure DevOps · Jenkins · ArgoNEXT
  • Trust network · third-party verifiersEXPLORING

GitHub deployment protection rules are a GitHub public-preview feature; private and internal repositories require GitHub Enterprise. The generic CLI/API path works in any CI. Availability labels come from one claim registry — nothing renders AVAILABLE without proof.

04 · THE RELEASE DECISION ROOM

The people saying yes finally review the same release.

Security, risk, engineering and the outcome owner see one Decision Lens: the exact diff, the requested authority, the evidence state, and the scoped options. Under two minutes to a defensible decision.

DECISION LENS · underwriting-triage → prod-eu-1SAMPLE
diff
none — current authority
consequence
quotes ≤ $50k, no funds movement
evidence
evals ✓ · security ✓ · provenance ✓
outcome owner
head-of-underwriting
rollback owner
platform-lead
quorum
2 of: risk, security, business

A new subject and sequence. The prior decision is superseded in history — never edited.

WHY SCOPED AUTHORITY

A blanket yes to a payments-capable agent is not a decision, it is an abdication. Conditions make the yes exact: how much rollout, which holds, how long. The gate enforces the scope, not the sentiment.

WHAT THE APPROVER SIGNS

Not a ticket. A release-authorization predicate binding the exact digest, environment, conditions and expiry — sealed in a DSSE-compatible envelope under an ECDSA P-256 / SHA-256, AWS KMS-backed key. Their authority is in the object, not beside it.

Outcome: fewer days reconciling approvals, no approval silently following a changed release, and one audit reconstruction instead of bespoke evidence hunts per reviewer.

05 · ONE DECISION PROPAGATES EVERYWHERE

A decision the delivery system can act on.

The UI is not the enforcement point. It issues the artifact the enforcement points consume — the same state, sequence and reason code everywhere. All five surfaces below derive from the decision you made above.

CI JOB · generic CLI

$ scalarion admit --env prod-eu-1

ADMIT

AUTHORIZED · seq 4106

exit 0

GITHUB DEPLOYMENT GATE

scalarion / release-authority

AUTHORIZED

K8S ADMISSION · prod-eu-1

admission webhook · scalarion

ADMIT · seq 4106

ADMISSIONS LEDGER · SAMPLE

  1. #4105 AUTHORIZE role:head-of-underwriting
  2. #4106 ADMIT ci:github/deploy-prod

OFFLINE VERIFIER

✔ envelope · in-toto Statement

✔ sig · ECDSA P-256 / KMS

06 · CONTINUOUS REAUTHORIZATION

Authority expires when its facts stop being true.

Your earlier tool-scope expansion traced this exact path — only the affected dependencies re-open, not the whole audit:

  1. tool scopesecurity evidence: missing for payments
  2. policyquorum required: risk + security
  3. authorizationsuspended for the new subject
  4. re-decisionnew sequence · scoped conditions · old decision superseded

THE ONLY SLOW TRANSITION ON THIS PAGE

Evidence freshness decays gradually, so it is the one thing allowed to take time — a ~2s degradation to ACTION_REQUIRED. Every other transition — admit, deny, revoke, supersede — changes state on the frame it happens.

to watch authority decay rather than break.

07 · ORGANIZATIONAL RELEASE SYSTEM

From one protected release to the operating system for agent authority.

The portfolio answers four questions — and keeps authorization and deployment as independent axes. No composite risk score.

WHAT IS RUNNING?

14 agents · 6 environments

observed at the boundary, not self-reported

WHAT IS AUTHORIZED?

11 current authorizations

each bound to one digest, one environment

WHAT EXPIRES SOON?

3 within 7 days

expiry spends authority automatically

WHERE IS THE GATE MISSING?

2 running × revoked or ungated

the drift the category exists to catch

ILLUSTRATIVE PORTFOLIO · INTERACTIVE SAMPLE — NOT LIVE TELEMETRY

08 · PORTABLE TRUST

Verify the decision without trusting the dashboard — or Scalarion.

The authorization is a release-authorization predicate in an in-toto Statement, carried by a DSSE-compatible envelope, signed with an ECDSA P-256 / SHA-256 key backed by AWS KMS. Copy the sample — its subject digest is the one this page computed — and inspect it anywhere.

Raw prompts and traces need not be disclosed: hashes and scoped references are sufficient for third-party verification. SLSA provenance enters as evidence; it is never the authorization.

THE ARTIFACT · ISSUED BY THE AUTHORITY PLANE

INTERACTIVE SAMPLE

SEALED · SEQ 4106

SIGNATURE LAYERkms-ecdsa-p256 (sample — unsigned in this prototype)
PAYLOAD · SUBJECTsha256:c07b0ae8bdb152c3…8f736bf7
INTEGRITY LOSS
{
  "_comment": "INTERACTIVE SAMPLE — locally generated, unsigned",
  "payloadType": "application/vnd.in-toto+json",
  "payload": {
    "_type": "https://in-toto.io/Statement/v1",
    "subject": [
      {
        "name": "underwriting-triage",
        "digest": {
          "sha256": "c07b0ae8bdb152c3557af8a5d9fc20c4eef27f134aaf8c2d9b5a4a428f736bf7"
        }
      }
    ],
    "predicateType": "https://scalarion.dev/release-authorization/v1",
    "predicate": {
      "environment": "prod-eu-1",
      "approver": "role:head-of-underwriting",
      "conditions": [],
      "notAfter": "2026-09-14T00:00:00Z",
      "revocable": true,
      "decisionSequence": 4106
    }
  },
  "signatures": [
    {
      "keyid": "kms-ecdsa-p256 (sample — unsigned in this prototype)",
      "sig": null
    }
  ]
}

WHAT A VERIFIER CHECKS · SAMPLE · NO CLI SHIPS YET

1 · fetch /.well-known/scalarion-trust.json
  2 · match the envelope keyid to a published key
  3 · verify the signature against that key alone
  • · statement in-toto Statement v1
  • · predicate scalarion release-authorization
  • · signature ECDSA P-256 / SHA-256 · KMS-backed
  • · subject digest bound to this release
  • · revocation checked against cached CRL h=4106

AUTHORIZED · exit 0

09 · RELEASE AUTHORITY SPRINT

Protect one consequential release in a real delivery path.

One consequential agent. One protected production environment. One canonical release subject. One accountable decision workflow. One installed fail-closed gate. One demonstrated mismatch denial. Measured baseline and outcome. 30–45 days.

Not a fit if the agent has no consequential action, no named production boundary, or no decision authority who can participate. We would rather say so now.

Next step after this form: we map one release path and identify the enforceable boundary before proposing a sprint. No account creation, no generic demo.

QUALIFICATION · 90 SECONDS · NO ACCOUNT REQUIRED

YOUR DETAILS GO TO THE SCALARION TEAM. NO ACCOUNT IS CREATED, NOTHING IS SHARED ONWARD, AND YOU CAN ASK US TO DELETE THEM AT ANY TIME.

SCALARIONIndependent Agent Release AuthorityDECISION SEQ 4106FAIL-CLOSED

This page is an interactive sample. No live telemetry, no customer data, no third-party acceptance implied.