Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Faramesh: A Protocol-Agnostic Execution Control Plane for Autonomous Agent Systems

About

Autonomous agent systems increasingly trigger real-world side effects: deploying infrastructure, modifying databases, moving money, and executing workflows. Yet most agent stacks provide no mandatory execution checkpoint where organizations can deterministically permit, deny, or defer an action before it changes reality. This paper introduces Faramesh, a protocol-agnostic execution control plane that enforces execution-time authorization for agent-driven actions via a non-bypassable Action Authorization Boundary (AAB). Faramesh canonicalizes agent intent into a Canonical Action Representation (CAR), evaluates actions deterministically against policy and state, and issues a decision artifact (PERMIT/DEFER/DENY) that executors must validate prior to execution. The system is designed to be framework- and model-agnostic, supports multi-agent and multi-tenant deployments, and remains independent of transport protocols (e.g., MCP). Faramesh further provides decision-centric, append-only provenance logging keyed by canonical action hashes, enabling auditability, verification, and deterministic replay without re-running agent reasoning. We show how these primitives yield enforceable, predictable governance for autonomous execution while avoiding hidden coupling to orchestration layers or observability-only approaches.

Amjad Fatmi• 2026

Related benchmarks

TaskDatasetResultRank
Secure LLM Agent Task CompletionAgentDojo
Benign Utility60.82
9
Agent SecurityASB n=2000
ASR0.00e+0
5
Data Leakage PreventionAgentLeak n=496
Any Leak Prevention Rate93.95
5
Agent Utility EvaluationASB 5 direct prompt-injection styles
Utility (%)3.7
2
Showing 4 of 4 rows

Other info

Follow for update