Evidence entering the boundary
- Ritqo signed envelope
- Cached policy and trust material
- Gateway and destination context
Gateway enforcement
Re-verify authorization at the edge before a command enters a protected MQTT or device path.
Request a private briefingA valid decision made centrally is not enough. The gateway must confirm that the command is still fresh, intended for this device, and valid under the policy available at the physical boundary.
Action Shield is the enforcement boundary close to the device. It verifies the signed envelope, policy version, expiry, nonce, replay state, and destination constraints before forwarding a supported command to an unchanged legacy device.
Operational contract
Re-verify authorization at the edge before a command enters a protected MQTT or device path.
Core capabilities
Re-verify signatures, expiry, nonce, replay state, destination, and policy binding at the gateway.
Enforce bounded commands on supported MQTT and controlled edge paths without granting the model direct access.
Fail closed when the envelope, policy, device state, or local enforcement context is invalid.
Return enforcement telemetry and refusal evidence to the control plane and Vaqri Proof.
Operational value
Place the final authorization check close to the protected device path.
Modernize supported legacy environments without making the AI system a device credential holder.
Close the loop with evidence for monitoring, review, pause, and rollback.
Continue through the control loop
Next: Vaqri Atlas