Objective
The result the session is permitted to pursue.
CGM · Continuity Governance Mesh
CGM is the continuity governance layer for AI systems operating under institutional responsibility. It externalizes governed session state from the model, binds each session to an explicit contract, and separates continuity from authority.
Specification Interaction pressure Continuity governance Admissibility
01 · Governing state
A probabilistic model can preserve context, follow a trajectory, and produce a coherent next response. None of those abilities establishes the authority to cross into institutional consequence.
CGM keeps the governing state outside the model. The organization establishes a governance floor. The session operator may add stricter local constraints, but cannot weaken that floor. Rules remain attributed to the authority that established them.
The active contract
Every session is bound to a contract that defines what the model is pursuing, where it must stop, and what it may never convert into action.
The result the session is permitted to pursue.
The point beyond which the objective must not expand.
The subject matter and operational territory in force.
The required manner of communication and conduct.
What the model may advise, propose, or never decide.
The state changes that are forbidden or restricted.
Obligations created during the governed trajectory.
Established findings that remain part of governed state.
02 · Graduated intervention
The active posture determines what CGM does with a finding. Governance can begin as observation and rise to a release boundary without pretending that every use case requires the same intervention.
CGM watches and records each turn without intervening.
Drift is named and classified so the operator can see what moved.
CGM restates the governing contract and gives the agent one bounded opportunity to correct.
Output is withheld and further movement waits for human judgment.
Candidate output proceeds to The Pilcrow for release adjudication and a verifiable verdict.
03 · The full trajectory
A single response can look acceptable while the session moves toward concealment, capitulation, or unauthorized scope. CGM examines both the immediate candidate and the pattern created over time.
Candidate responses are examined against the active objective, constraints, commitments, and resolved facts.
Integrity failures are evaluated independently of contract drift, so apparent compliance does not conceal unreliable conduct.
CGM detects patterns that emerge across the session and across related sessions, where single turn review cannot see them.
04 · MCP action governance
CGM can freeze a consequential tool call before it leaves the agent’s workflow. It issues a hold ticket, records the event, and waits for a human grant or denial. An unanswered hold expires to denial.
CGM authorizes. It never executes. The caller’s own system acts only after a grant.
05 · The Pilcrow enforcement boundary
At Enforce, CGM submits candidate output to The Pilcrow for separate release adjudication. The resulting decision is verifiable and the path fails closed when adjudication cannot be completed.
06 · Custody
Every material governance event enters an ordered record. Completed sessions can be closed with a tamper evident signature generated by HMAC using SHA 256 over the contract and full governance ledger.
07 · Organizational governance
Organization baselines, governance floors, attributed roles, governed workspaces, API access, MCP integration, human holds, and custody exports operate as one architecture.
The result is not merely another model watching a model. CGM combines model assisted semantic evaluation with deterministic rules, intervention controls, and an ordered governance record.
ENTRUST AI
Request a private demonstration of CGM and its continuity, authorization, enforcement, and custody architecture.