Runtime Governance Layer • Patent AU 2026906017

Policy enforcement and evidence-grade receipts for autonomous AI.

WitnessOS is a runtime governance layer for autonomous systems. Every action is evaluated against policy, evidence receipts are produced for every decision, and violations trigger structured remediation - from advisory warnings to hard failsafe. Built for enterprise, regulated, and government-adjacent environments.

How governance works

Every autonomous action passes through a deterministic policy evaluation pipeline before execution. Nothing runs unchecked.

1
Action proposedAn agent, robot, or system proposes an action - deploy, execute, approve, or respond. The action includes context: target, parameters, scope, and asserted intent.
2
Policy evaluatedWitnessOS evaluates against configured policies (OPA Rego rules, allow/deny lists, risk thresholds, SOP mappings). The result: Allow, Deny, Conditional, or Escalate.
3
Evidence receipt generatedEvery evaluation produces a tamper-evident receipt: action hash, policy version, evaluation context, decision, timestamp, and chain-of-custody. SHA-256 signed.
4
Remediation triggered (if needed)Denied or Conditional actions trigger structured remediation at the appropriate RemediLevel - from advisory warnings (R1) through to hard system shutdown (R6).

RemediLevel R0–R6

A structured escalation framework for policy violations. Each level defines the severity, response, and notification requirements.

LevelLabelResponseUse case
R0CompliantNo action requiredAction passed all policy checks
R1AdvisoryNotification sent, action proceedsSoft policy flag, non-critical context change
R2WarningAction proceeds with logging + operator alertUnusual parameter, borderline risk score
R3EscalateAction paused, human approval requiredOut-of-scope target, high-value resource access
R4DenyAction blocked, full evidence trail recordedPolicy violation, unauthorised scope, SOP breach
R5RestrictSystem enters restricted mode, critical ops onlyRepeated violations, integrity concern
R6FailsafeHard system halt, full audit log generatedActive threat, regulatory breach, unrecoverable policy conflict

RemediLevel is deterministic and auditable. Every escalation is logged as an evidence-grade receipt with the full decision chain. Built for compliance review, internal audit, and regulatory submission.

Key capabilities

WitnessOS is a drop-in governance layer for any autonomous system - agents, robotics, pipelines, and decision engines.

Policy Engine

OPA-native policy evaluation

Write policies in Rego. WitnessOS evaluates every proposed action deterministically - Allow, Deny, Conditional, or Escalate. Policy-as-code ready for CI/CD.

Evidence Receipts

Tamper-evident audit trail

Every evaluation produces a SHA-256 signed evidence receipt: action hash, policy version, context, decision, and timestamp. E2 evidence-grade by design.

RemediLevel

Structured remediation

R0–R6 framework scales response from advisory notifications through to hard failsafe. Every escalation is logged, auditable, and deterministic.

Machine Binding

Hardware-anchored licensing

Licenses bound to machine identity (TPM, network fingerprint, disk serial). Anti-tamper, no floating sharing. Enterprise-managed via Admin Centre.

API-First

Integrate any system

REST API, WebSocket events, and client SDKs. Integrate WitnessOS into existing autonomous systems without architectural changes.

Multi-Layer

Policy tiers

System-wide defaults, environment-specific overrides, and action-level rules. Inheritance with clear precedence and full auditability.

Technical foundation

Deterministic, auditable, and built to stand up to regulatory scrutiny.

Architecture

WitnessOS Gateway (policy evaluation + evidence generation) + WitnessOS Agent (per-host enforcement). Deterministic engine - same inputs always produce the same decision. No LLM in the governance path.

Standards & Compliance

SHA-256 evidence receipts. SOP-aligned policy templates. Exportable audit bundles. Designed for ISO 27001, SOC 2, and government-grade compliance frameworks.

Ready to govern your autonomous systems?

Book a 30-minute technical assessment. We'll map your current stack to a WitnessOS deployment plan with clear scope and timeline.

Book an assessment