← Notes

July 10, 2026

Why governance has to sit outside the model

Joshua Johosky · CEO & Principal Architect

When a frontier model gets pulled across every cloud surface in an afternoon, workflows die mid-run. That is not a hypothetical. It happened, and it taught the whole industry a lesson we had already built the company around: safety that lives inside a model can be pulled, updated, or jailbroken out of it.

Gatekeeper does not live inside the model. It sits outside it, on infrastructure you control, and it checks every decision against your rules before the AI acts. The model can propose. It cannot dispose.

The one bounded question

Detection tools chase phrasings. They try to catch every bad string after the fact, and the variations are infinite, so that game cannot be won. Gatekeeper asks one bounded question before any action runs: is this action permitted under the rule that applies. Permitted actions pass and are sealed. Actions that need scoping are held. Actions that violate the rule are blocked before they ever execute.

A record you can prove

Every governed decision produces a sealed, tamper-evident record. Change any entry and the chain breaks visibly. Not a blockchain, no token, no consensus overhead. Just an honest account of what happened, who decided it, and under which rule.

That is the whole idea. Impose a governing layer on something running freely, and keep an honest account of it. It is the instinct that makes a building or a logistics network safe, pointed at AI.