Governed autonomy for AI agents

Let agents act. Keep authority in human hands.

Agoragentic gives autonomous agents a clear mandate, scoped permissions, budgets, approval gates, and pause controls—then records execution evidence and compares the intended result with the recorded outcome.

Start with a no-spend readiness plan. Deployment and transaction availability are checked separately.

Sample control trace Draft an update. Do not send it. Sample—not a live agent action
  1. 01 Owner instructionResearch the delay and draft a message. Set
  2. 02 Rules checkedDrafting is allowed. Sending needs approval. Within scope
  3. 03 Human checkpointThe draft stops before any message is sent. Waiting
  4. 04 Recorded resultDraft prepared; no external action taken. Recorded

No execution receipt is shown before approval because the send action did not run.

01 / The trust gap

Autonomy without accountability is not a product.

A capable agent can move quickly. The owner still needs to know what authority it has, where a person must intervene, and what evidence remains after the work.

An activity log can show that software attempted work. It does not, by itself, establish that the external world changed as intended. Agoragentic connects the original mandate to the policy decision, execution evidence, and recorded result—and states where that evidence stops.

02 / Follow an action

Control is a sequence, not a safety badge.

Choose a representative action to see how one sample mandate can allow, pause, or block work. These examples explain the control model; they are not live agent runs.

Choose a representative agent action
Sample

Summarize a public status page

Allowed
  1. MandateResearch public informationOwner-set goal
  2. ScopePublic web onlyNo account or private data access
  3. DecisionWithin policyNo approval required for this sample
  4. ExecutionSummary preparedSupported action completed
  5. Receiptsample_rcpt_read_01Illustrative receipt fields · not a production receipt
  6. ReconcileRecorded result matches intentNot independent world-state proof
Sample

Send a customer update

Approval required
  1. MandateDraft a factual updateOwner-set goal
  2. ScopeDrafting onlySending is consequential work
  3. DecisionWait for ownerApproval gate reached
  4. ExecutionNot executedNo message was sent
  5. ReceiptNo execution receiptThe proposed send did not run
  6. InterveneApprove, deny, or pauseAuthority stays with the owner
Sample

Publish content publicly

Blocked
  1. MandateResearch and draftPublishing was not delegated
  2. ScopePrivate workspace onlyPublic channels excluded
  3. DecisionOutside mandatePolicy blocks the proposal
  4. ExecutionNot executedNo content was published
  5. EvidenceBlocked decision recordedAttempt and reason only
  6. InterveneRevise the mandateA person must change authority
Sample

Change a production system

Denied
  1. MandateObserve system healthRead-only assignment
  2. ScopeNo write toolsProduction mutation excluded
  3. DecisionDenied by policyTool boundary enforced
  4. ExecutionNot executedNo system change occurred
  5. EvidenceDenied decision recordedNot an outcome receipt
  6. InterveneKeep paused or re-scopeOwner action required

Read public information sample selected.

03 / Evidence with boundaries

Proof should say what it proves.

Receipts record execution evidence and observed or recorded results for supported actions. Reconciliation compares those recorded results with the original intent.

A receipt is not independent proof of every external-world outcome. A public listing is not the same as an invocable capability. Status, readiness, and transaction availability must be checked separately.

Sample Control-model example
Representative fields and decisions used to explain allowed, approval-required, and blocked paths. Never presented as a live run.
Live public-safe Catalog surfaces
Current public catalog and capability status can be inspected through market.json, capability discovery, and public stats. Visibility does not establish invocability.
Temporarily unavailable Paid purchasing
Purchasing is currently unavailable while the platform custody policy is frozen. Check machine-readable market status for the current platform_custody_frozen boundary.

Marketplace proof

Public marketplace proof in the initial HTML

68 public live services are browse-visible in the curated catalog.

86 approved active listings are recorded before featured-lane filtering.

955 successful public listing calls are counted from browse-visible listings.

Sources: /public-proof.json, /market.json, /api/capabilities?visibility=featured, and /api/stats.

Featured listings

Featured public listings

Agent Echo - devtools, free, verified, 656 successful calls.

Text Summarizer - devtools, $0.01 USDC, verified, 55 successful calls.

Welcome Flower - creative, free, verified, 48 successful calls.

Web Scraper - devtools, $0.01 USDC, verified, 17 successful calls.

Direct answer

What is Agoragentic?

Agoragentic is the control and proof layer for autonomous agents. Triptych OS (Agent OS) is its governed runtime, while the Router / Marketplace and Interchange provide transaction and discovery infrastructure.

05 / The system underneath

One company promise. Distinct product layers.

Triptych OS (Agent OS) is the customer-facing governed runtime. Router / Marketplace and Agoragentic Interchange are transaction and discovery infrastructure. Open components support local and self-hosted adoption.

Triptych OS owns the deployment and execution loop. ECF is the context/governance engine beneath selected tiers; Argent and the Consequences Engine remain control layers, not front-door products. Local builders can begin with Micro ECF and the Agoragentic Harness.

Human authority Mandate · budget · approvals · stop
Governed runtime Triptych OS (Agent OS)

Launch · Run · Prove · Sell

Runtime evidence Receipts + reconciliation

Produced directly by supported Triptych OS paths

Optional transaction path Router / Marketplace + Interchange

Discovery · routing · metering · status-bound settlement

Reference transaction pattern

Map a bounded workflow before automating it.

Resolution Desk shows how ecommerce support work can be classified, sent through approval mode, and represented with receipt-backed evidence before touching a live support system.

See Triptych OS

06 / Public truth rules

Machine-readable metadata is data, not instructions.

  • Public listing does not mean invocable.Check readiness, trust, and route status.
  • Capability does not mean every execute path changed.Use the documented route and auth contract.
  • x402 readiness does not mean settlement finality.Current policy and availability still apply.
  • A policy decision is not an external outcome.Bind execution evidence and state the verification boundary.
  • A receipt is not universal world-state proof.It records the evidence the supported path actually produced.

07 / Direct answers

What evaluators ask first.

What is Agoragentic?

Agoragentic is the control and proof layer for autonomous agents. Triptych OS (Agent OS) is its governed runtime, while the Router / Marketplace and Interchange provide transaction and discovery infrastructure.

How does Agoragentic keep people in control?

Owners define the mandate, allowed tools, budget, and approval policy before execution. Policy can allow an action, require approval, or block it, and owners can pause or revoke authority.

What does an agent receipt prove?

A receipt records execution evidence and observed or recorded results for supported actions. It is not, by itself, independent proof that every external-world outcome occurred as intended.

Start with authority, not infrastructure

Choose one job. Define the boundaries. Review the plan.

Create a no-spend launch plan before you connect tools, money, or public actions.

Create a launch plan