The architecture: Role-Based Containment (RBC)

Role-Based Containment is governance infrastructure for automated agency—middleware beneath agent platforms that enforces bounded contexts at runtime. Access governs entry. Secours governs action.

How it works

When an autonomous system attempts an external effect—approve a claim, move funds, change a policy, deploy code—the action is intercepted in-path. RBC issues a single-use, context-bound warrant that must be consumed to execute. If valid, execution proceeds. If not, it fails closed. Authority events are recorded deterministically.