Every step was allowed. The end was not chosen.
Each action sits inside its own limit; together they cross a boundary nobody set out to cross.
Enforced today · cumulative ceilings that survive a restart, shared across the agents a boundary servesDiaCroma sits outside your agents. Before any action runs, it checks it against the rules you signed and everything your agents have already done. Then it lets it through, changes it, or stops it.
Runs at your boundary, in your network · see current platform evidence →
Two ways an agent fails
An agent can escape. Or it can stay inside and drift. The first makes the news. The second makes no noise.
A cage cannot see drift: the agent never tries to leave it. The industry is building the cage: on September 28, 2026, NVIDIA and more than 100 partners launched an open platform that decides what an agent can reach and watches it while it runs. DiaCroma is the complement: it decides how much the agent can do inside what was signed. One keeps the agent in. The other makes it behave.
Three ways an agent drifts
We would rather name them than blur them, because only two of the three are decided mechanically, before the action runs.
Each action sits inside its own limit; together they cross a boundary nobody set out to cross.
Enforced today · cumulative ceilings that survive a restart, shared across the agents a boundary servesA developer adds one more tool, because another team needed it. Nobody did anything wrong — and the approval no longer describes what is running.
Enforced today · three counts per agent: what its platform declares, what your people approved, what the boundary served. The unapproved tool does not passAcross a long conversation the agent abandons its instructions. On this one we publish evidence rather than make a production claim.
Not decided at runtime — deliberately · see the benchmark replay →A model reads and proposes. A person signs. At runtime, nothing is decided by a model. Every proposed limit reaches your approver with its citation; once it is signed, enforcement is mechanical — because a boundary that reasons is a boundary you cannot audit.
The failure no green dashboard shows
Four agents handle one customer across different systems. Each sees its own admissible action. None sees the business boundary they share.
Illustrative multi-agent case using a signed global concessions boundary.
Inside her $200 per-action cap.
$100Inside the current price book.
$150Inside his goodwill authority.
$175The customer sees one combined outcome.
$425 totalFour admissible actions. A $125 business-policy breach.
The shared trajectory names the boundary, blocks and escalates with evidence.
Illustrative logic, not a customer outcome.
Who it’s for


The enterprise buying committee
Add shared trajectory control while existing identity, registries, gateways and runtimes remain in place.
Architecture and deployment →Enforce cumulative limits across refunds, discounts, credits, purchases and commitments made by different agents.
Inspect the evidence →Decide before execution and name bypass routes explicitly instead of treating visibility as control.
Review the enforcement boundary →Produce a replayable record that supports review and defensibility without claiming automatic compliance.
Review claim boundaries →