Governance dossier

Every supported action, governed before execution.

Pakkawork is designed to sit between agents and provider APIs. Today, five Google apps execute supported contracts through the same deterministic server-side enforcement used by MCP 2025-06-18 JSON-RPC and REST.

Provider-agnostic architecture · Google Workspace first · One server-side gate

Execution dossier · run_2481

Provider action request

Gate active
01

Ingress request

MCP or REST · agent + operator

02

Contract binding

Version · content hash · description

03

Policy decision

Risk · arguments · approval state

04

Execution evidence

Provider result · ledger · optional checks

One action, one connected governance trail

Product features

Enforcement evidence

Provider-agnostic · Deterministic · Enforced outside model prompts

One gate. Explicit outcome support.

Before supported execution, Pakkawork binds the request to an immutable contract and evaluates risk and policy. Every provider result is recorded. A read-back runs only on the 22 contracts with implemented post-conditions, and rollback requires contract-defined compensation.

  • Risk derived from observed API shape and real arguments
  • Risky supported actions return pending approval without executing
  • Post-conditions and compensation are contract-specific, not catalogue-wide
execution-record.jsonVerified-contract example

Immutable contract

Version + content hash · description pinned

Policy decision

API shape + arguments · threshold pinned

Optional provider check

Contract-defined post-condition · 22 current contracts

Signed ledger entry

sha256 chain · Ed25519 signature

Example with implemented post-condition

JSON

Control plane mechanisms

Four layers. One enforcement path.

Discovery, policy, supported execution, and evidence share one provider-agnostic architecture. Google Workspace is the first provider family.

Contracts & discovery

Immutable contracts, progressive discovery

Pakkawork has 555 immutable, content-addressed contracts live. Versions and hashes are pinned, and description drift freezes execution instead of silently changing what an agent can call.

  • 555 content-addressed contracts live today
  • Discovery and OpenAPI ingest is built to scale past 2,000 APIs (roadmap)
  • 8 progressive-disclosure MCP tools keep discovery bounded
  • Every schema change produces a new contract version and hash
Policy & approval

Risk-aware policy before execution

Risk is derived from the observed API shape and the real arguments. Deterministic policy runs on the server before the model and outside prompts, so a risky action returns pending approval without reaching the provider.

  • Critical actions require 2 distinct approvers
  • The approval threshold is pinned while a request is in flight
  • Pending approval means the upstream action did not execute
Execution safety

Contained execution, contract-specific outcomes

Per-tenant OAuth and least-privilege scopes combine with a host allowlist, SSRF containment, bounded jittered backoff, and quota and sending-cap preflight before a supported provider call runs.

  • 22 contracts implement post-condition reads; a mismatch returns failure
  • Rollback exists only where a contract declares and captures compensation
  • Model-free deterministic replay sends supported steps through the gate
Evidence & resilience

Signed evidence and operational recovery

Trigger heartbeats make silence observable, failed runs land in dead letters, and every event joins an append-only sha256 hash chain signed with Ed25519.

  • AES-256-GCM envelope encryption protects stored secrets
  • API keys are shown once and stored hash-only
  • Evidence maps to EU AI Act, NIST AI RMF, and ISO/IEC 42001 controls—not certification

Provider-agnostic by design

Built as a provider-agnostic boundary, with Google Workspace first.

The Pakkawork boundarySame gate everywhere

Agent-neutral

Any agent or framework uses the same gate for supported contracts.

Deterministic server gate

Protocol parity

MCP 2025-06-18 JSON-RPC and REST share one enforcement path.

Deterministic server gate

Provider-contained

Tenant OAuth, least privilege, allowlists, and SSRF controls stay enforced.

Deterministic server gate

Evidence-mapped

Records map to major governance controls without claiming certification.

Deterministic server gate

One control plane from request through signed result, with verification and rollback only where the contract defines them.

Govern your first agent