API not checked
iGraph / context before action

Authority should follow impact.

A data change is not safe because an agent can write it. iGraph reads the organizational consequences, signs the exact authority, and proves whether the boundary was crossed.

iGauthority
engine
contextDataHub
pactsigned
boundaryarmed
pre-action authority online
Context sourceAwaiting snapshot
Policy version2026.08
Write-backOpt-in / off
Decision principleSame request ≠ same authority
01
Change command

Give the control plane a proposed action.

Start with the agent’s request. Context, risk and authority are compiled after the proposal—not assumed before it.

proposed change

Schema mutation request

INPUT / 01
Agent request
rename_column(orders.customer_id → account_id)
Reviewable artifacts only. Production deployment is always outside the default scope.
operator brief

What happens next

deterministic flow
01
Read context

Schema, lineage, ownership, quality and usage signals are pulled into one snapshot.

02
Score consequence

Fanout, sensitive classifications, dashboards, ML assets and incomplete retrieval change the risk.

03
Issue authority

A signed, expiring Pact narrows the actions, targets and artifacts the executor may touch.

The agent can propose the change. It cannot widen the authority.
02
Impact graph

See the consequence before the side effect.

no Pact issued
context topology

Downstream consequence map

sourcedownstreamsensitive
No context snapshot yet

Compile a Pact to render the source asset, downstream dependencies and the signals that changed its authority.

Try the pre-filled orders → account_id scenario
signed authority

Impact Pact

not issued
P
igp_—
policy expires
Context fingerprint
Allowed actions0
Awaiting Pact
×Blocked actions0
Awaiting Pact
enforcement rehearsalTest the boundary
reversible simulator
actiondeploy_staging
targetstaging
artifactawaiting Pact
Compile a Pact before crossing the enforcement point.
enforcement path

Control gates

PROOF / 03
01
Context snapshotDataHub / Agent Context Kit retrieval
waiting
02
Consequence scoreFanout, governance and usage signals
waiting
03
Pact signatureExpiry, scope and artifact hashes bound
waiting
04
Enforcement pointTarget and artifact checked before executor
waiting
05
Change ReceiptEvidence of what was—or was not—invoked
waiting
03
Evidence ledger

Every decision leaves a trace.

The receipt separates preparation, denial, execution and verification so a reviewer can see exactly where authority stopped.

review artifacts

Generated evidence

0 artifacts
Artifacts appear once the proposed action has been compiled.
validation state

Checks & write-back

AUDIT / 04
Schema, lineage and postcondition checks are waiting.
DataHub write-backoff
No receipt properties or Decision document emitted.
machine-readable proof

Change Receipt

receipt pending
Waiting for a proposed changeRun an analysis to create the receipt.
View raw receipt payload
{}