A sovereign model that only talks is inert. Give it the authority to act through national systems — and put a human approval gate on every consequential move.
Agency capability is exposed to the model as explicit tools, never as raw system access.
Each action — query a registry, draft a settlement instruction, file a supervisory notice — is a schema-defined tool with validated inputs and bounded effects.
A model holds only the tools its mandate requires. An agent built for tax correspondence cannot reach payment rails or amend a registry.
Where authorized, agents prepare atomic delivery-versus-payment instructions against the sovereign ledger — always as proposals staged for approval, never as self-executed transfers.
The default is not autonomy; it is a proposal a named official must sign.
The agent produces a fully specified action and its rationale. Nothing takes effect until a human with authority approves it.
Approval is a post-quantum signature (ML-DSA-65) binding the official's identity to the exact action, recorded so the decision cannot later be repudiated.
Low-risk reads may run unattended; anything moving value, changing a record, or issuing a legal instrument requires explicit sign-off, and high thresholds can require two.
Proposed actions are held in an inspectable queue where they can be edited, rejected, or expired before they ever touch a system of record.
Agent behavior is fully reconstructable — inputs, tool calls, approvals, and effects.
The prompt, retrieved context, each tool call and result, and the final effect are recorded as an ordered, tamper-evident trace.
Every committed action ties to both the agent version that proposed it and the official who approved it, closing the accountability loop.
A regulator can replay an agent's run against recorded inputs to determine exactly why it did what it did.
Autonomy is bounded by resource, scope, and time so a misbehaving agent cannot run away.
Tool calls execute in isolated environments with network and data egress confined to sanctioned sovereign systems.
Runs carry limits on steps, spend, and wall-clock time. Exceeding a bound halts the agent and escalates to a human.
An operator can revoke an agent's signing certificate to stop it everywhere at once and freeze its pending proposals for review.
Multi-step tasks are planned explicitly so oversight applies at every juncture, not just the end.
An agent commits to a stated plan before acting, letting a reviewer approve the approach before any tool runs.
Long tasks pause at defined checkpoints for review, so oversight is continuous rather than a single gate at the finish.
Where correctness is non-negotiable — an interest calculation, a settlement amount — the model calls a deterministic tool rather than computing the number itself.