ES
Trajectory enforcement for AI agent systems

Every agent can follow its rules.
The system can still break yours.

DiaCroma sits outside your agents. Before any action runs, it checks it against the rules you signed and everything your agents have already done. Then it lets it through, changes it, or stops it.

Signed authorityShared trajectory stateCross-agent lineage Pre-execution decisionsRuns in your network

Runs at your boundary, in your network · see current platform evidence →

Two ways an agent fails

A cage keeps an agent in. It doesn’t make it behave.

An agent can escape. Or it can stay inside and drift. The first makes the news. The second makes no noise.

A light bulb inside a metal cage.
It escapes · containmentIt leaves its permissions: it touches networks, systems or credentials its task does not need. Containment stops it: isolate the agent and cut every exit that is not allowed.
An attentive dog, head tilted, waiting for the signal.
It drifts · behaviourIt never leaves its permissions. Each action fits; the sum, or the intent, does not. Bounding stops it: check every action against what was signed and what has already been spent.Not only weak models: in a peer-reviewed study, all four models evaluated — GPT-4o and Claude 3.5 Sonnet among them — showed some degree of goal drift. Arike et al., AIES 2025

A cage cannot see drift: the agent never tries to leave it. The industry is building the cage: on September 28, 2026, NVIDIA and more than 100 partners launched an open platform that decides what an agent can reach and watches it while it runs. DiaCroma is the complement: it decides how much the agent can do inside what was signed. One keeps the agent in. The other makes it behave.

Three ways an agent drifts

One word. Three different failures.
They are not caught in the same place.

We would rather name them than blur them, because only two of the three are decided mechanically, before the action runs.

01 · IT ACCUMULATES

Every step was allowed. The end was not chosen.

Each action sits inside its own limit; together they cross a boundary nobody set out to cross.

Enforced today · cumulative ceilings that survive a restart, shared across the agents a boundary serves
02 · ITS DEFINITION CHANGES

Approved in March. Different in June.

A developer adds one more tool, because another team needed it. Nobody did anything wrong — and the approval no longer describes what is running.

Enforced today · three counts per agent: what its platform declares, what your people approved, what the boundary served. The unapproved tool does not pass
03 · THE MODEL LOSES THE MISSION

Talked out of what it was told to do.

Across a long conversation the agent abandons its instructions. On this one we publish evidence rather than make a production claim.

Not decided at runtime — deliberately · see the benchmark replay →

A model reads and proposes. A person signs. At runtime, nothing is decided by a model. Every proposed limit reaches your approver with its citation; once it is signed, enforcement is mechanical — because a boundary that reasons is a boundary you cannot audit.

The failure no green dashboard shows

Every action is within policy.
The combined outcome is not.

Four agents handle one customer across different systems. Each sees its own admissible action. None sees the business boundary they share.

One customer · four admissible actions

Illustrative multi-agent case using a signed global concessions boundary.

GLOBAL LIMIT · $300
Billing

June approves a refund

Inside her $200 per-action cap.

$100
Orders

Martha applies a discount

Inside the current price book.

$150
Support

Theo offers a credit

Inside his goodwill authority.

$175
Case

The case is closed

The customer sees one combined outcome.

$425 total
PER-ACTION CONTROLSEverything stays green.

Four admissible actions. A $125 business-policy breach.

WITH DIACROMAThe last action cannot execute.

The shared trajectory names the boundary, blocks and escalates with evidence.

Illustrative logic, not a customer outcome.

Who it’s for

For the companies that build agents, and for the ones that run them.

A transparent padlock resting on a circuit board.
If you build agentsYour agents behave inside what each customer signs. What decides is not AI: a deterministic, auditable digital twin. You deploy without fear and compete on trust.
Brushes of every colour meeting on one palette.
If you run agentsYou buy agents from several vendors; the rules stay yours. Every action is checked against what you signed before it runs. You scale AI without fear.

The enterprise buying committee

One control layer.
Four reasons to approve it.

CIO · Chief AI Officer

Govern every agent without replatforming.

Add shared trajectory control while existing identity, registries, gateways and runtimes remain in place.

Architecture and deployment →
Finance · Operations

Bound total exposure, not only each transaction.

Enforce cumulative limits across refunds, discounts, credits, purchases and commitments made by different agents.

Inspect the evidence →
CISO · Security

Stop the governed action outside the model.

Decide before execution and name bypass routes explicitly instead of treating visibility as control.

Review the enforcement boundary →

Walk the six screens with one agent.

Get it on Microsoft Marketplace ↗ How you use it →