Architecture Notes
How OSuite primitives turn agent activity into governed runtime structure.
Architecture
How OSuite governs agent actions: PCAA, CAVA, BAF, and AREG.
The product path behind OSuite is simple to explain and strict to execute: final authority, canonical action analysis, bounded approval leases, runtime exposure maps, and proof that survives audit.
Benchmark Report
We tested 6,000 agent actions. Runtime labels were not enough.
OSuite Runtime Boundary Benchmark tests whether an agent action is still inside the boundary that was approved, across 19 runtime surfaces, 38 risk families, 6 locales, and 10 obfuscation styles.
Architecture
Auto mode changes the governance object.
As coding agents move toward longer-running autonomous work, the enterprise control point shifts from whether a model may call a tool to whether the runtime action stays inside an approved boundary.
Architecture
A governed agent action was independently recomputed outside OSuite.
OSuite and Baby Blue / invinoveritas ran a concrete external-verifier composition: a CAVA action artifact, a partner-signed verdict, and a proof packet that can be checked without trusting either party's internal log.
Security Architecture
Runtime Exposure Management is where AI governance becomes operational.
AI governance should not stop at policy language or model posture. For agentic systems, the buyer needs to see what can act, what it can reach, where approval is bounded, and whether exposure is improving.
Architecture
Why approval must bind to the action, not the text.
A human approval means nothing if a wrapper can rewrite the request after the click. Here is how OSuite makes approval enforceable.
Architecture Note
Runtime Coverage is not a parser percentage.
CAVA gives OSuite a stable action language. Runtime Coverage explains how each real agent runtime is mapped into that language.
Reproducibility Note
Making the CAVA benchmark claim computable.
A public replication survey initially marked CAVA's benchmark claim as not released. We published the missing reproducibility artifact, and the record was updated to COMPUTABLE after an independent rerun.
Explainer
Harness is not runtime governance.
AI agent harnesses help models plan, call tools, and run longer workflows. Enterprise runtime governance answers a different question: what action was approved, what actually executed, and can the proof survive audit?