About FRM Systems — the company behind Agent Assurance Core

← Return to Agent Assurance Core

Model-independent control for agentic systems

AI can do more of the work.Humans still need control of the outcome.

FRM Systems is developing a model-independent runtime control and assurance layer for AI agents—designed to govern what they can do, preserve evidence of what happened, support independent verification and route consequential decisions to people.

Bounded actionExecution evidenceControlled recovery
CONTROL RECORD / 001TARGET ARCHITECTURE
01
Human intentobjectives · constraints · acceptance
02
Runtime controlpolicy · authority · permissions
03
Agent actionmodels · tools · systems
04
Evidence + decisionrecords · checks · outcomes
DEFINED CHECKS METAccept
FAILURE OR JUDGEMENTRecover / escalate
In this target model, human intent enters a runtime control layer designed to bound agent action. Evidence supports a later decision to accept, recover or escalate.
01THE CONTROL GAP

The shift

Agent autonomy creates a runtime control problem.

AI agents are moving beyond generating content and recommendations. They can plan work, use tools, change system state and carry out multi-step tasks.

Organisations therefore need to know what an agent was authorised to do, what actually happened, what evidence supports the outcome and what should happen when checks fail.

FRM Systems is developing a control layer for that gap. Coding agents are the first demonstrator because their actions and outputs are observable and testable; they are the starting point, not the boundary.

ASSISTED USEHuman directs each step
  1. 01Human request
  2. 02Model response
  3. 03Human action
AGENTIC EXECUTIONNew runtime boundary
  1. 01Human objective
  2. 02Agent planning
  3. 03Tool and system action
  4. 04State change
  5. 05Verification
  6. 06Acceptance or recovery
01

What objective and authority were assigned?

02

Which tools, data and systems were permitted?

03

What happened, and what evidence records it?

04

Should the outcome be accepted, recovered or escalated?

02THE RUNTIME LAYER

Target design principles

Control before action. Evidence before acceptance. Recovery by design.

FRM Systems is developing a target architecture around six principles for governing agent work across models, tools and operational environments.

01

Policy-bound work

Designed to translate each task into explicit scope, permissions, constraints and authority.

Scope · policy · authority
02

Runtime mediation

Designed to check requested agent actions against policy and authoritative work state.

Actions · permissions · state
03

Evidence-linked execution

Designed to associate tool use, state changes, artefacts and decisions with the work that produced them.

Evidence · provenance · records
04

Independent verification

The target architecture separates completion claims from the checks used to assess them where risk warrants it.

Criteria · checks · separation
05

Recovery and escalation

Designed to route failed checks, interruptions and uncertainty into defined return, recovery or human-decision paths.

Failure · recovery · judgement
06

Portable integration

Designed around model-, agent- and tool-independent interfaces. Portability remains a development objective.

Agents · models · environments
03THE CONTROL MODEL

Target runtime architecture

From human intent to controlled outcome

In the target architecture, each unit of work moves through defined authority, observable execution, verification and an explicit accept, recover or escalate decision.

  1. 01

    Define

    Capture the objective, constraints, risk and acceptance criteria.

  2. 02

    Authorise

    Assign the tools, systems, permissions and limits required for the work.

  3. 03

    Execute

    Allow the agent to act through designated runtime control points.

  4. 04

    Record

    Associate actions, state changes, artefacts and decisions with execution evidence.

  5. 05

    Verify

    Assess the outcome against defined criteria using separate checks where appropriate.

  6. 06

    Decide and recover

    Accept work that satisfies defined checks, route failures into recovery and escalate unresolved judgement to a person.

This is a target control model, not a claim that agent work is inherently correct or secure. Acceptance means only that defined checks have been satisfied.

Technical view

How the target layers surround agent execution

TARGET SYSTEM ARCHITECTURECONTROL / ASSURANCE
INPUT
Human / policyIntent · constraints · risk · acceptance
BOUND
Runtime control planeWork state · policy · permissions · intervention
ACT
Execution environmentAgents · models · tools · systems
CHECK
Evidence and verificationRecords · artefacts · checks · decisions
AcceptDefined checks met
ReturnCorrection required
EscalateJudgement required
In this target architecture, human intent and policy flow into a runtime control plane, then an execution environment, then evidence and verification. Work can be accepted, recovered or escalated.
04MODEL-INDEPENDENT CONTROL

Reusable runtime infrastructure

One control layer. Many agent systems.

FRM Systems is being developed as a reusable layer between agent objectives and the models, tools and systems used to carry them out.

The target architecture is designed to let different applications apply their own risk, permission, verification and recovery policies through shared control primitives.

Coding agents are the first demonstrator because their actions and outputs are concrete and inspectable. They are the starting point, not the boundary.

01Coding agents
02Enterprise agents
03Operational agents
PROPOSED SHARED LAYERFRM runtime control
EXECUTION SURFACEAgents · models · tools · systems
Target view of multiple agent applications using a shared runtime control layer across models, tools and systems.

Potential applications where agent actions need to remain bounded, reviewable and recoverable.

01

Coding agents

The initial demonstrator under development for task boundaries, execution evidence, verification and recovery around code-changing agents.

02

Enterprise agent platforms

A prospective control boundary between agent applications and organisational tools, data and systems.

03

High-assurance operations

Target workflows where consequential actions require stronger checks, decision gates and recovery paths.

04

Public-sector and regulated systems

Potential contexts where traceability, policy enforcement and accountable human decisions matter.

05CURRENT FOCUS

Architecture and reference demonstrator

Developing the controls around agent execution.

FRM Systems is developing the target architecture and a coding-agent reference demonstrator.

Current work focuses on interfaces, evidence structures, failure handling and evaluation methods. Conversations with research, security and technical organisations can inform that development.

DEVELOPMENT REGISTERCURRENT SCOPE
  1. 01Coding-agent reference demonstratorIN SCOPE
  2. 02Runtime policy and authority boundariesIN SCOPE
  3. 03Model- and framework-independent interfacesIN SCOPE
  4. 04Authoritative work-state orchestrationIN SCOPE
  5. 05Evidence schemas and provenanceIN SCOPE
  6. 06Verification separationIN SCOPE
  7. 07Failure handling and recovery pathsIN SCOPE
  8. 08Human decision and escalation pointsIN SCOPE
  9. 09Threat modelling and evaluation designIN SCOPE
06ABOUT FRM SYSTEMS

The organisation

Built at the intersection of agent systems, runtime control and verification

FRM Systems is an early-stage effort developing infrastructure for governable agent execution. Its target architecture draws on systems design, requirements engineering, software verification and technical programme delivery.

CURRENT DEVELOPMENT FOCUS

Runtime controls that preserve human authority.

The work centres on bounded permissions, protected evidence, independent verification and recovery paths for consequential agent actions.

08DEVELOPMENT DIALOGUE

Research and technical conversations

Help shape how agent runtime control should be evaluated.

FRM Systems welcomes conversations with organisations working on agent systems, assurance, security and verification. These discussions would inform the developing architecture and future evaluation methods.

Prefer email?

ENQUIRY / 01

Start a conversation

Tell us briefly what you are working on and where a discussion could be useful.

Please do not include confidential information. Submissions are processed by FormSubmit.

The work ahead

Giving agents more capability is getting easier.Keeping their actions controlled and recoverable is the harder systems problem.

FRM Systems is developing a model-independent runtime layer for control, evidence, verification and recovery across AI-agent systems.

Discuss the target architecture