Policy enforcement and evidence-grade receipts for autonomous AI.
WitnessOS is a runtime governance layer for autonomous systems. Every action is evaluated against policy, evidence receipts are produced for every decision, and violations trigger structured remediation - from advisory warnings to hard failsafe. Built for enterprise, regulated, and government-adjacent environments.
How governance works
Every autonomous action passes through a deterministic policy evaluation pipeline before execution. Nothing runs unchecked.
RemediLevel R0–R6
A structured escalation framework for policy violations. Each level defines the severity, response, and notification requirements.
| Level | Label | Response | Use case |
|---|---|---|---|
| R0 | Compliant | No action required | Action passed all policy checks |
| R1 | Advisory | Notification sent, action proceeds | Soft policy flag, non-critical context change |
| R2 | Warning | Action proceeds with logging + operator alert | Unusual parameter, borderline risk score |
| R3 | Escalate | Action paused, human approval required | Out-of-scope target, high-value resource access |
| R4 | Deny | Action blocked, full evidence trail recorded | Policy violation, unauthorised scope, SOP breach |
| R5 | Restrict | System enters restricted mode, critical ops only | Repeated violations, integrity concern |
| R6 | Failsafe | Hard system halt, full audit log generated | Active threat, regulatory breach, unrecoverable policy conflict |
RemediLevel is deterministic and auditable. Every escalation is logged as an evidence-grade receipt with the full decision chain. Built for compliance review, internal audit, and regulatory submission.
Key capabilities
WitnessOS is a drop-in governance layer for any autonomous system - agents, robotics, pipelines, and decision engines.
OPA-native policy evaluation
Write policies in Rego. WitnessOS evaluates every proposed action deterministically - Allow, Deny, Conditional, or Escalate. Policy-as-code ready for CI/CD.
Tamper-evident audit trail
Every evaluation produces a SHA-256 signed evidence receipt: action hash, policy version, context, decision, and timestamp. E2 evidence-grade by design.
Structured remediation
R0–R6 framework scales response from advisory notifications through to hard failsafe. Every escalation is logged, auditable, and deterministic.
Hardware-anchored licensing
Licenses bound to machine identity (TPM, network fingerprint, disk serial). Anti-tamper, no floating sharing. Enterprise-managed via Admin Centre.
Integrate any system
REST API, WebSocket events, and client SDKs. Integrate WitnessOS into existing autonomous systems without architectural changes.
Policy tiers
System-wide defaults, environment-specific overrides, and action-level rules. Inheritance with clear precedence and full auditability.
Technical foundation
Deterministic, auditable, and built to stand up to regulatory scrutiny.
WitnessOS Gateway (policy evaluation + evidence generation) + WitnessOS Agent (per-host enforcement). Deterministic engine - same inputs always produce the same decision. No LLM in the governance path.
SHA-256 evidence receipts. SOP-aligned policy templates. Exportable audit bundles. Designed for ISO 27001, SOC 2, and government-grade compliance frameworks.
Ready to govern your autonomous systems?
Book a 30-minute technical assessment. We'll map your current stack to a WitnessOS deployment plan with clear scope and timeline.