Policy-bound work
Designed to translate each task into explicit scope, permissions, constraints and authority.
Scope · policy · authorityAbout FRM Systems — the company behind Agent Assurance Core
← Return to Agent Assurance CoreModel-independent control for agentic systems
FRM Systems is developing a model-independent runtime control and assurance layer for AI agents—designed to govern what they can do, preserve evidence of what happened, support independent verification and route consequential decisions to people.
The shift
AI agents are moving beyond generating content and recommendations. They can plan work, use tools, change system state and carry out multi-step tasks.
Organisations therefore need to know what an agent was authorised to do, what actually happened, what evidence supports the outcome and what should happen when checks fail.
FRM Systems is developing a control layer for that gap. Coding agents are the first demonstrator because their actions and outputs are observable and testable; they are the starting point, not the boundary.
What objective and authority were assigned?
Which tools, data and systems were permitted?
What happened, and what evidence records it?
Should the outcome be accepted, recovered or escalated?
Target design principles
FRM Systems is developing a target architecture around six principles for governing agent work across models, tools and operational environments.
Designed to translate each task into explicit scope, permissions, constraints and authority.
Scope · policy · authorityDesigned to check requested agent actions against policy and authoritative work state.
Actions · permissions · stateDesigned to associate tool use, state changes, artefacts and decisions with the work that produced them.
Evidence · provenance · recordsThe target architecture separates completion claims from the checks used to assess them where risk warrants it.
Criteria · checks · separationDesigned to route failed checks, interruptions and uncertainty into defined return, recovery or human-decision paths.
Failure · recovery · judgementDesigned around model-, agent- and tool-independent interfaces. Portability remains a development objective.
Agents · models · environmentsTarget runtime architecture
In the target architecture, each unit of work moves through defined authority, observable execution, verification and an explicit accept, recover or escalate decision.
Capture the objective, constraints, risk and acceptance criteria.
Assign the tools, systems, permissions and limits required for the work.
Allow the agent to act through designated runtime control points.
Associate actions, state changes, artefacts and decisions with execution evidence.
Assess the outcome against defined criteria using separate checks where appropriate.
Accept work that satisfies defined checks, route failures into recovery and escalate unresolved judgement to a person.
Technical view
Reusable runtime infrastructure
FRM Systems is being developed as a reusable layer between agent objectives and the models, tools and systems used to carry them out.
The target architecture is designed to let different applications apply their own risk, permission, verification and recovery policies through shared control primitives.
Coding agents are the first demonstrator because their actions and outputs are concrete and inspectable. They are the starting point, not the boundary.
The initial demonstrator under development for task boundaries, execution evidence, verification and recovery around code-changing agents.
A prospective control boundary between agent applications and organisational tools, data and systems.
Target workflows where consequential actions require stronger checks, decision gates and recovery paths.
Potential contexts where traceability, policy enforcement and accountable human decisions matter.
Architecture and reference demonstrator
FRM Systems is developing the target architecture and a coding-agent reference demonstrator.
Current work focuses on interfaces, evidence structures, failure handling and evaluation methods. Conversations with research, security and technical organisations can inform that development.
The organisation
FRM Systems is an early-stage effort developing infrastructure for governable agent execution. Its target architecture draws on systems design, requirements engineering, software verification and technical programme delivery.
The work centres on bounded permissions, protected evidence, independent verification and recovery paths for consequential agent actions.
Context / relevant guidance
These independent public sources describe the wider operational and cyber-security problem that FRM Systems is addressing.
Context only. These organisations are not partners of FRM Systems, and inclusion does not imply affiliation or endorsement.
UK National Cyber Security Centre
Practical advice for securing autonomous AI deployments, including proportionate autonomy, layered safeguards, sandboxing, observability, human oversight and emergency shutdown.
UK Sovereign AI
An evidence-focused challenge addressing how organisations can assess and reduce the security and resilience risks of specific AI agents in specific contexts.
Research and technical conversations
FRM Systems welcomes conversations with organisations working on agent systems, assurance, security and verification. These discussions would inform the developing architecture and future evaluation methods.
Prefer email?
The work ahead
FRM Systems is developing a model-independent runtime layer for control, evidence, verification and recovery across AI-agent systems.
Discuss the target architecture