Ingress request
MCP or REST · agent + operator
Governance dossier
Pakkawork is designed to sit between agents and provider APIs. Today, five Google apps execute supported contracts through the same deterministic server-side enforcement used by MCP 2025-06-18 JSON-RPC and REST.
Provider-agnostic architecture · Google Workspace first · One server-side gate
Execution dossier · run_2481
Provider action request
Ingress request
MCP or REST · agent + operator
Contract binding
Version · content hash · description
Policy decision
Risk · arguments · approval state
Execution evidence
Provider result · ledger · optional checks
Product features
Enforcement evidence
Provider-agnostic · Deterministic · Enforced outside model prompts
Before supported execution, Pakkawork binds the request to an immutable contract and evaluates risk and policy. Every provider result is recorded. A read-back runs only on the 22 contracts with implemented post-conditions, and rollback requires contract-defined compensation.
Immutable contract
Version + content hash · description pinned
Policy decision
API shape + arguments · threshold pinned
Optional provider check
Contract-defined post-condition · 22 current contracts
Signed ledger entry
sha256 chain · Ed25519 signature
Example with implemented post-condition
JSONControl plane mechanisms
Discovery, policy, supported execution, and evidence share one provider-agnostic architecture. Google Workspace is the first provider family.
Pakkawork has 555 immutable, content-addressed contracts live. Versions and hashes are pinned, and description drift freezes execution instead of silently changing what an agent can call.
Risk is derived from the observed API shape and the real arguments. Deterministic policy runs on the server before the model and outside prompts, so a risky action returns pending approval without reaching the provider.
Per-tenant OAuth and least-privilege scopes combine with a host allowlist, SSRF containment, bounded jittered backoff, and quota and sending-cap preflight before a supported provider call runs.
Trigger heartbeats make silence observable, failed runs land in dead letters, and every event joins an append-only sha256 hash chain signed with Ed25519.
Provider-agnostic by design
Any agent or framework uses the same gate for supported contracts.
Deterministic server gate
MCP 2025-06-18 JSON-RPC and REST share one enforcement path.
Deterministic server gate
Tenant OAuth, least privilege, allowlists, and SSRF controls stay enforced.
Deterministic server gate
Records map to major governance controls without claiming certification.
Deterministic server gate
One control plane from request through signed result, with verification and rollback only where the contract defines them.
Govern your first agent