Charter — the assurance kernel

Governed AI for high-stakes missions.

Charter is our assurance kernel — the governed layer between AI reasoning and consequential action. It lets concurrent AI teams execute high-stakes missions at machine speed, while evidence, roles, authority, and action remain structurally governed.

Governed multi-agent organization Concurrent
Agent 01Propose
Agent 02Review
Agent nPrepare
Charter kernelMission law · evidence · authority
Admit / refuse
Consequential actionOne governed result. Human authority retained.
Authorized
Roles & signatures Current evidence Replayable ledger
Concurrent agent organizations
Mission-specific domain law
Human-held authority
Proven kernel properties
Concurrent. Governed. Scalable.

Govern the organization, not just the model.

Specialized agents work in parallel under one mission-specific law. Charter keeps proposals untrusted, separates authority, and converges the work to one replayable result.

01

Concurrent roles

Many agents propose, review, and prepare work at the same time.

03

Governed mission state

Every interleaving reconverges; consequential authority remains human.

Reasoning is not assurance

A model can understand the rules and still fail to enforce them.

A prompt-only system caught obvious violations, then accepted a forged attestation and self-review. Charter puts assurance in the architecture—not in the model’s instructions.

From “the agent should not” to “the system cannot.”
Control
Typical stack
Charter
Tools
Broad, static menu
Only admissible actions are exposed
Evidence
Fluent text can become state
Typed, current, provenance-bound evidence
Authority
One loop can propose, approve, act
Roles and signatures split power
Assurance
Logs and behavioral tests
Replayable ledger and proven invariants
One kernel. Many missions.

Concurrent teams, governed by domain law.

The same proven engine governs 11–17 concurrent roles across four live missions.

Model-Based Engineering

An unaccredited result is refused; a changed specification expires prior work; a failing rerun keeps release blocked.

Non-negotiable gateAccredited, current evidence supports the verdict.

Critical-Infrastructure Defense

Physical process state is verified and stabilized while cyber containment proceeds in coordination with operations. Failover needs two signers.

Non-negotiable gateProcess safety is independently verified; failover has two signers.

Security Authorization

Unsupported readiness is refused. The AI never receives the authority to authorize; only the official signs.

Non-negotiable gateEvery control is evidence-bound; only the official authorizes.

Cyber Operations

No consequential action is reachable until authority, evidence, scope, and policy converge. The command cell, not one operator, decides.

Non-negotiable gateOperator, command, and legal authority remain separate.
Validity follows evidence

A verdict expires when its basis does.

A decision remains valid only while its evidence does; when its basis changes, it is no longer current.

01Evidence changes
02Dependent facts invalidate
03The verdict expires
04Affected work re-runs
Properties, not promises

Proven once. Enforced every run.

Every mission inherits the same kernel properties.

01
Untrusted proposals

Only an admitted transition can change state.

02
Human authority

Authorization rests with a designated human role; no AI role is granted it.

03
Structural governance

Transitions that violate the configured rules are refused on entry, not merely detected.

04
Tamper-evident replay

An append-only ledger recreates the exact decision path.

05
Convergent concurrency

Concurrent interleavings reconverge to one result.

06
Model independent

The proofs cover the kernel—not a particular model.

Check the proof. Do not trust the builder. Machine-checked in Lean, with a one-page trust base. The proofs cover the kernel invariants and transition semantics — not external tools, source data, models, or human judgments.
Machine-checked
Early access · design partners

Bring Charter to your hardest mission.

Six Gates is onboarding a small group of early adopters across defense, energy, and critical infrastructure. If your mission needs AI held within authority, evidence, and the rules, let’s talk — we’ll set up a briefing and a scoped pilot.

or email hello@sixgates.com

Model-Based Engineering

Governed structural substantiation under change

16 concurrent agents · multi-discipline qualification · DoD digital engineering

What it models

This benchmark models a model-based engineering organization substantiating a structural design: a Ti-6Al-4V engine-mount bracket intended for a flying aircraft. Sixteen concurrent agents work across systems, design, stress, V&V, configuration management, and technical authority roles on one shared governed ledger.

The point is not that AI agents can run analyses or write reports. The point is that no artifact becomes verified, released, baselined, or current unless the right authority, evidence, traceability, and configuration state exist in the world.

The digital thread

The digital thread is explicit. Every verification traces a fixed chain: requirement, load case, simulation model, run, quantity of interest, margin, and verification result. Each link points to a real versioned object. If geometry, material allowables, load case, idealization, solver settings, or accreditation basis changes, the affected verification self-revokes. A stale result cannot remain current just because it was once true.

A margin on a knife’s edge

The benchmark centers on a titanium bracket with one comfortable case and one fragile one. Under static loading, the reserve factor is about 1.80, leaving ample margin. But the combined environment is much tighter: steady load plus random vibration produces a reserve factor of roughly 1.03. That result is barely passing, and it depends directly on the vibration environment. Worse, an analyst initially marks it verified using a model accredited for static loads, not for the combined environment it is being used to certify.

Then the configuration changes. The random-vibration spectrum is tightened. The static case remains sound and does not need to be rerun. But the governing combined case does: its vibration term grows, the reserve factor drops from about 1.03 to about 0.95, and the part fails. Charter blocks release because the current evidence no longer supports the claimed verification.

Why it matters

The important failure is not the arithmetic. It is the governance failure that normally surrounds the arithmetic: a thin-margin result gets treated as settled, its basis changes, and the old verdict keeps traveling through the program as if nothing happened. Charter makes the verdict expire when its basis expires. It reopens exactly the affected verification path, enforces the required accreditation and review sequence, and prevents a confident number on an unsound basis from becoming a released part.

Authority & separation of duties

The same runtime governs authority. Engineers can create and propose, but they cannot approve or release their own work. The technical authority can accredit models, disposition review gates, and release controlled artifacts. The Configuration Control Board controls baseline changes. The author is never the approver, and a baseline cannot move without an admitted change decision.

Coupling, worked in order

It also governs coupling. If a downstream result depends on an upstream result, the downstream result cannot remain current when the upstream basis becomes stale. Change is worked through the chain in the right order: invalidate downstream first, re-verify upstream first. The runtime refuses out-of-order shortcuts instead of relying on process discipline after the fact.

What it demonstrates: Charter can coordinate a live multi-discipline engineering organization while preserving configuration control, digital-thread traceability, model accreditation, separation of duties, basis-of-verification currency, and release authority under change.
Grounded in: model-based systems engineering · DoD digital engineering practice · MMPDS material allowables · ASME V&V 10/20 · VV&A practice · ARP4754A-style assurance discipline · STEP AP242/AP209 digital-thread exchange · PLCS-style lifecycle state · configuration-control practice
Demonstrated by: 16 live agents, real checker tools, one governed ledger, no pre-seeded evidence, and a structural verification that stays valid only while the evidence beneath it remains valid.
Critical-Infrastructure Defense

Governed OT/ICS response under process-safety constraints

11 concurrent agents · municipal water utility · NIST SP 800-82r3 / ATT&CK for ICS

What it models

This benchmark models an attack on a municipal water utility’s control network. An attacker has compromised an engineering workstation and is reaching toward a chlorine-dosing controller. Eleven concurrent agents respond across incident command, SOC watch, cyber response, plant operations, process safety, forensics, continuous monitoring, utility authority, and remediation ownership.

The point is not that AI agents can detect an incident or recommend a containment step. The point is that every response action is admitted only if it preserves the plant’s safety, availability, authority model, and evidence basis.

The ordering — safety first

Charter models the plant itself: network segments, controllers, treatment stages, safety functions, dosing envelopes, live containment basis, and response roles. The ordering is structural: process safety first, then security action, then authority. A commander can authorize containment, eradication, recovery, and failover within the approved envelope. They cannot authorize an unsafe process state.

The first refusal — process limits outrank command

The central refusal is a harmful dosing change. A chlorine setpoint is admissible only inside the plant’s site-specific, regulator-approved operating envelope, defined over dose, residual, contact time, flow, pH, and temperature. Too much chemical is a hazard. Too little undermines disinfection. A setpoint outside that envelope cannot enter the world state, no matter who signs it. Process limits outrank the chain of command.

The second refusal — the safety layer

The second refusal protects the safety layer itself. No cyber-response action may modify, disable, or bypass a required safety-instrumented function. SIS monitoring remains read-only unless an approved safety procedure authorizes maintenance. The safety system is still monitored for cyber risk, but it is not sacrificed in the name of containment.

Governed, not scripted

The response is governed without being scripted. Process verification and stabilization begin immediately on the plant floor; they do not wait for network isolation. Cyber containment proceeds in coordination with operations, isolating affected paths as soon as doing so is operationally safe. A response action that would drop the process into an unsafe or unavailable state is refused.

Four separate states

Charter also keeps the lifecycle honest. “Safe,” “contained,” “verified,” and “authorized for service” are separate states. A controller is process-safe only when dosing is inside the approved envelope and the protective safety function is operational. It is cyber-contained only while live containment matches the current network basis. It is functionally verified only against calibrated instruments. It is authorized for service only after two-person failover and documented acceptance of any residual risk.

Self-revoking containment

When the adversary re-pivots, containment self-revokes. The old containment no longer matches the live network basis, so the incident cannot remain “contained” by label alone. The response team re-engages, analyzes the new path, isolates it on the fresh basis, and retires the stale containment. The system preserves continuity without pretending the old answer still applies.

Residual risk

Residual risk is governed as well. A controller carrying a CISA KEV-listed vulnerability cannot be returned to service merely because the plant is running. Return to service requires formal risk acceptance by the utility operations authority, with an owner and remediation milestone. Accepting cyber risk does not by itself make the process safe.

What it demonstrates: Charter can coordinate a live OT/ICS response while preserving process safety, service continuity, separation of duties, calibrated evidence, containment currency, two-person failover, and documented residual-risk acceptance.
Grounded in: NIST SP 800-82r3 · NIST SP 800-61r3 · MITRE ATT&CK for ICS · IEC 61511 · IEC 62443 · Purdue / ISA-95 segmentation · PPD-41 severity coordination · CISA KEV · EPA/AWWA disinfection practice
Demonstrated by: 11 live agents, one governed plant model, no scripted state, live self-revoking containment after an adversary re-pivot, and a return-to-service decision that requires safety, containment, verification, authority, and residual-risk discipline at the same time.
Security Authorization

AI-accelerated RMF, human-authorized ATO

17 governed roles · AI-accelerated RMF, human AO · NIST SP 800-37 / cATO

What it models

This benchmark models an AI-assisted RMF organization driving a defense system toward an Authorization to Operate. Seventeen governed roles work across control implementation, review, assessment, package assembly, continuous monitoring, and authorization on one shared ledger.

The point is not that AI can draft control narratives or accelerate assessment prep. The point is that AI can do the work at machine speed while the authority to authorize remains structurally human.

The one act the AI cannot do

The unit of work is a control-implementation determination: AC-2(j), AU-2(a), SC-7, CM-6, CP-9, RA-5. Each determination moves through a Charter-specific pre-assessment lifecycle: drafting, proposed, ready-for-assessment, or deficient. There is no “authorized” state for the AI to reach. The authorization act simply is not on any AI role’s menu.

Human attestation

A determination can become ready only when it has a complete narrative, filled parameters, cited evidence, fresh evidence, and a human reviewer’s attestation. The reviewer cannot be the engineer who implemented the control. Unreviewed AI output cannot flow into assessment just because it sounds complete.

Independent assessment

Assessment authority is separate. The Security Control Assessor renders Satisfied or Other-Than-Satisfied findings using real assessment methods: examine, interview, or test, against a defined object such as a specification, mechanism, activity, or individual. A bare “satisfied” is refused. An Other-Than-Satisfied result must produce a traced finding and can support authorization only through an open POA&M and documented residual-risk acceptance.

Authorization

The ATO requires all of the pieces at once: an assembled authorization package, independent assessment results, dispositioned findings, documented residual risk, and the designated human Authorizing Official. The AO accepts the risk and grants the authorization. The AI never does. A non-AO agent attempting to authorize is not merely blocked; the action is unavailable.

After the ATO — continuous authorization

The system also governs what happens after authorization. An ATO is not treated as permanent. When a control basis changes, the authorization’s currency lapses and requires AO action. For cATO eligibility, continuous monitoring, active cyber defense, and the approved DevSecOps reference design must remain in force. If a required pillar lapses, the system is no longer cATO-eligible and the AO must reaffirm, constrain, or de-authorize.

Package integrity

The package remains traceable through the authorization stack: catalog, profile, SSP, assessment plan, assessment results, and POA&M. Artifacts cannot float free of their source catalog, and derived artifacts cannot remain current when the upstream basis changes. The authorization record stays tied to the evidence beneath it.

What it demonstrates: Charter can coordinate an AI-accelerated RMF organization while preserving human authorization, assessor independence, evidence-gated determinations, POA&M-backed residual risk, continuous authorization currency, and end-to-end package integrity.
Grounded in: NIST SP 800-37 Rev. 2 · NIST SP 800-53A Rev. 5 · DoDI 8510.01 · FIPS 199 · DoD cATO guidance · OSCAL · RMF authorization practice
Demonstrated by: 17 governed roles, six control families, live AI-drafted determinations, human reviewer attestations, independent SCA findings, one accepted POA&M, AO-granted authorization, AO reaffirmation, cATO lapse, and human de-authorization on one governed ledger.
Cyber Operations

Governed multi-agent purple-team operations

11 concurrent agents · purple-team engagement · ATT&CK · SSVC · CISA KEV

What it models

This benchmark models a live purple-team cyber engagement with 11 concurrent agents: red-team operators advancing a host through the kill chain, blue-team responders driving incident response, and a command element governing consequential action.

The point is not that an AI agent can run a cyber tool. The point is that no consequential action becomes reachable unless the right authority, evidence, scope, and policy facts already exist in the shared state.

The gate — the trigger-puller who can’t load the gun

In the scenario, an operator reaches the point where an exploit would normally be authorized. Charter blocks unilateral action. The gate requires independently produced facts: reconnaissance, a governed scan, a source-cited CVE finding, commander approval, legal approval, CTI weaponization clearance, and continuity confirmation. The operator can execute only after the command cell has converged. The trigger-puller cannot load the gun.

Hard boundaries above the approval chain

The same runtime enforces hard boundaries above the approval chain. A protected or out-of-scope asset cannot be made consequential. A technique must be within the engagement’s rules of engagement. Collateral estimates must remain within the authored proportionality ceiling. Weaponization must be earned through evidence, not asserted from a severity score alone: KEV status, CVSS and EPSS thresholds, SSVC decisioning, exploitation evidence, and VEX status all shape what can enter the kill chain.

The defenders are governed too

The blue side is governed as well. Credentials, containment, isolation, and recovery are not static labels. A valid-accounts foothold self-revokes when the defender rotates the credential. A contained incident self-revokes when the adversary re-pivots command and control to a new channel. Recovery is admitted only when known-exploited findings are remediated or formally risk-accepted with an owner and milestone.

One shared ledger

The result is a live multi-agent cyber organization operating on one shared ledger: operators, commanders, legal reviewers, CTI analysts, incident responders, continuous monitoring, and authorizing officials all acting within bounded roles. Separation of duties is enforced by the runtime, not requested from a prompt. Protected targets remain untouchable. Authority, evidence, and policy determine what the system can admit.

What it demonstrates: Charter can coordinate concurrent AI agents in a high-stakes cyber workflow while preserving authority boundaries, evidence requirements, rules of engagement, modeled legal constraints, self-revoking state, and auditability.
Grounded in: MITRE ATT&CK · adversary emulation plans · SSVC · VEX · CVSS · EPSS · CISA KEV · NIST SP 800-40r4 · NIST SP 800-61r3 · modeled ROE / LOAC constraints