Skip to content

Site search

Type to search Pages

Relying-party governor

Govern what your agents may rely on, without approving each one by hand.

Consent fatigue turns human-in-the-loop approval into reflexive sign-off. Signura lets you set which issuers and attestation types your agents may depend on — with scope, value thresholds and expiry enforced on every reliance.

Your control loop

How you keep reliance under real human control.

You configure the bounds once; agents work inside them and escalate outside them.

Admit issuers and types

Define which issuers and which attestation types your agents may depend on, so reliance is confined to sources you have judged admissible.

Set the limits

Attach scope, a value threshold and an expiry to each admissible type. These bounds are enforced on every reliance, not applied case by case.

Let agents proceed within bounds

Inside the limits you set, a relying agent verifies the signed proof at decision time and proceeds. Nothing material is committed on agent discretion alone.

Review the escalations

Anything ambiguous, above threshold or past expiry arrives as an escalation case for you to approve or refuse, so your attention lands where judgement is required.

Retrieve the record

When a past decision is questioned, pull the reliance record showing which attestations were verified, that they were unaltered, and who stood behind each.

What the console puts under your control.

Admissible issuers and types

Decide which issuers and attestation types your agents may rely on. Reliance outside your admitted set does not proceed.

Scope, thresholds and expiry

Configure the bounds of each reliance — its scope, the value it may support, and how long it stays admissible — enforced on every event.

Escalation on high-risk cases

Ambiguous and high-risk reliance is routed to a human rather than settled on discretion, so escalation concentrates on the decisions that matter.

Tamper-evident evidence ledger

Every reliance event is logged as a tamper-evident trail, capturing at decision time the evidence that used to be scattered and reconstructed afterwards.

Where accountability sits, and what it does not remove.

The control you have today, and why it erodes

Today your only real control over agent reliance decisions is human-in-the-loop approval. It holds until volume rises. Reviewers face more requests than they can weigh, sign-off becomes reflexive, and a control that reads as strong on paper turns nominal in practice.

Signura is built to keep the human decision meaningful by narrowing it. You configure, once, which issuers and which attestation types your agents may depend on, and under what scope, value threshold and expiry. Agents then act on their own only within those bounds. Anything ambiguous, above the value threshold, or past its expiry is routed to a governor as an escalation case rather than resolved on agent discretion. The aim is not to remove people from the loop; it is to spend their attention where a judgement is genuinely required.

What a named liable party actually gives you

A fair objection is that a reliance layer might move liability around rather than reduce it. Signura is explicit about this. Each attestation names the party that stands behind the claim and carries scoped liability terms and an expiry, so accountability is defined before any reliance occurs rather than argued after a dispute.

The exchange does not itself become the party you depend on. Its responsibility is the integrity of the cryptographic proof and the accuracy of freshness and revocation status — not the truth of the underlying fact, which remains with the issuer who signed it. When a decision is later questioned in a governance or liability review, you retrieve the reliance record from a tamper-evident ledger showing exactly which attestations were verified, that they were unaltered, and who was liable for each. Evidence that once had to be reconstructed after the fact becomes a first-class record captured at decision time.

Because the operator sits between the two sides and favours neither, its logs can serve either party in a dispute on equal footing. Human governors keep the consequential decisions; the AI colleagues that run the exchange do the recurring verification, propagation and record-keeping, under the limits you set.

Governor questions

What governors ask before admitting an issuer.

Can agent discretion really be bounded safely?

Agents proceed only within the scope, value threshold and expiry you configure. Anything outside those bounds is escalated to a human, and no material commitment is made on agent discretion alone.

Does this shift liability rather than remove it?

It makes liability explicit rather than removing it. Each attestation names a liable party and carries scoped terms and an expiry, so who stands behind a claim is defined before any reliance, not contested afterwards.

How do I know the exchange stays neutral?

The operator's responsibility is confined to the integrity of the proof and the accuracy of freshness and revocation status. It does not become a party you rely on for the truth of any underlying fact, which stays with the signing issuer.

When a decision is questioned, what can I show?

You retrieve the reliance record from a tamper-evident ledger, showing which attestations were verified, that they were unaltered, and who was liable — the evidence that underpinned the decision.

What stops escalations becoming another rubber stamp?

Routine reliance is handled within your configured limits, so only ambiguous and high-risk cases reach you. Narrowing the flow is what keeps each human decision a real one.

Bring one reliance decision your governors must stand behind.

Describe the reliance decisions you need to govern, and we will show how admissible issuers, limits and evidence would apply to them.