Evidence entering the boundary
- Normalized action intent
- Identity, capability, and device state
- Policy, approval, risk, and provenance
Technical order engine
Decide deterministically whether an AI or human command may reach a protected device.
Request a private briefingAn AI model can propose a useful action, but it should never become the authorization authority for a physical or operational system.
Ritqo separates intelligence from permission. It binds identity, workload, device capability, current state, policy, risk, approval, expiry, nonce, replay controls, and provenance before issuing a signed command envelope or an explainable denial.
device/chiller-07 → 18.5°COperational contract
Decide deterministically whether an AI or human command may reach a protected device.
Core capabilities
Normalize AI and human intent into a versioned action request.
Evaluate identity, capability, device state, policy, risk, approval, freshness, and provenance.
Issue a signed, bounded envelope when every required condition passes.
Return deterministic denial reasons when an action is stale, replayed, unsupported, or unapproved.
Operational value
Keep probabilistic intelligence outside the permission boundary.
Make every allowed or refused action attributable and reviewable.
Send only bounded commands to Action Shield for gateway enforcement.
Continue through the control loop
Next: Action Shield