Authority should follow impact.
A data change is not safe because an agent can write it. iGraph reads the organizational consequences, signs the exact authority, and proves whether the boundary was crossed.
engine
Give the control plane a proposed action.
Start with the agent’s request. Context, risk and authority are compiled after the proposal—not assumed before it.
What happens next
Schema, lineage, ownership, quality and usage signals are pulled into one snapshot.
Fanout, sensitive classifications, dashboards, ML assets and incomplete retrieval change the risk.
A signed, expiring Pact narrows the actions, targets and artifacts the executor may touch.
See the consequence before the side effect.
Downstream consequence map
Compile a Pact to render the source asset, downstream dependencies and the signals that changed its authority.
Impact Pact
—deploy_stagingstagingawaiting PactControl gates
Every decision leaves a trace.
The receipt separates preparation, denial, execution and verification so a reviewer can see exactly where authority stopped.
Generated evidence
Checks & write-back
Change Receipt
View raw receipt payload
{}