Sign the authority.
Mission, tools, caps, budgets, resources, invariants and acceptable evidence become a versioned anchor.
DiaCroma evaluates every action routed through it against what the agent — and the agents around it — have already done. It adds durable, deterministic enforcement without replacing your agent platform, identity system, runtime or cloud.
Per-action controls ask, “Is this call allowed?” DiaCroma also asks, “Is it still allowed after everything already done?”
The control loop
The agent still reasons in its own runtime. DiaCroma governs the transition from proposed intent to business effect.
Mission, tools, caps, budgets, resources, invariants and acceptable evidence become a versioned anchor.
A tool call, delegation, message or other effect arrives at a boundary outside the model.
DiaCroma checks cumulative authority, sequence, lineage, shared constraints and evidence against durable state.
The structural decision does not depend on a language model.
The permit is consumed, the resulting effect is reconciled, and the evidence row is sealed for replay.
A permit is valid only against the live trajectory state that produced it. If that state moves first, the proposed effect is no longer authorized.
Adoption path
The first implementation proves one effecting route end to end: proposal, decision, execution, receipt, settlement and replay. Coverage expands only as additional routes are integrated and alternate paths are closed.
Call DiaCroma before the business effect, receive the decision contract and return the resulting receipt after execution.
Run the library or container in infrastructure you operate, with durable trajectory state backed by SQLite or Postgres.
Carry the same decision contract through MCP, HTTP or the DiaCroma A2A endpoint while platform validation remains explicit.
See the integration paths →Integration makes DiaCroma reachable. Route closure makes it enforceable. A route remains partial whenever the same business effect can bypass the boundary.
Product boundary
DiaCroma consumes identity, policy and tool context from the surrounding stack. It does not rebuild the layers enterprises already operate.
Multi-cloud deployment model
Agents and business tools stay where they run. DiaCroma places an execution boundary near the effecting route while the same signed authority, trajectory state and evidence follow the work across platforms.
A runtime connected through a validated adapter proposes an action. Platform validation is reported separately.
Builds context, reads the live trajectory and returns a permit, replan or block.
On a closed governed route, executes only with a valid permit and returns the receipt required for settlement.
The architecture is multi-cloud; validation is platform-specific. See what is running today, and what is coming next, on the Evidence page →
What the enterprise signs
Mission anchor, deployer credential, agent identity, allowed tools and the version of the authority being enforced.
Exact per-argument ceilings plus the authority that may be spent across the lifetime of a trajectory or delegation tree.
What agents read and write, which resources are coupled, and which operation classes cannot follow one another.
What each tool can prove, how fresh that evidence must be, and how the proposed action closes against the effect that actually occurred.
Product truth
It does not replace identity, registries, fleet lifecycle, orchestration or cloud administration.
Structural controls are deterministic; optional semantic signals are identified separately.
Coverage is graded explicitly. A reachable gateway is not an inevitable execution boundary.
The authority and trajectory model remain neutral even while platform integrations mature at different speeds.
Next: validate a governed route
Choose one agent, one business effect and one execution route. Validate allow, block, receipt, settlement and replay before expanding coverage.