--- title: ARF AI โ€“ Governance for Every AI Decision emoji: ๐Ÿง  colorFrom: blue colorTo: indigo sdk: static pinned: false license: other --- # ARF AI **Control plane for autonomous AI.** ARF sits between an agent's intent and its execution. Every proposed action is evaluated against deterministic policy before anything happens, and the decision is recorded before the action runs โ€” not after it succeeds. > ๐Ÿ”’ **ARF is commercial software and is not open source.** The core engine, > API control plane, gateway and enterprise extension are access-controlled. > Access is through the sandbox, a pilot, or an enterprise agreement. --- ## The problem An agent that can restart a service, delete a volume, move money or approve a claim is not a chatbot. It is an operator without a review process. The usual answer is to ask a model to check its own work. That produces a judgment which can differ between two identical requests โ€” so it cannot be audited, cannot be appealed, and cannot be shown to anyone as a rule. ARF's answer is that some decisions must not be delegated to judgment at all. --- ## What ARF does Every request returns one of three outcomes: - โœ… **APPROVE** โ€” within policy, and uncertainty is low enough to act. - โš ๏ธ **ESCALATE** โ€” the system could not establish that this is permitted. An input is missing, or the action is above the bar this policy clears alone. - โŒ **DENY** โ€” violates policy or exceeds risk tolerance. **ESCALATE is not a softer DENY.** Collapsing the two destroys the difference between *this is forbidden* and *this needs a person*, and that difference is the whole of what a reviewer needs in order to act. Every decision is: - **Deterministic** where it matters โ€” identical inputs, identical policy version, identical answer, every time. - **Explained** โ€” a refusal nobody can explain is not auditable, so a refusal without reasons is rejected rather than passed downstream. - **Recorded in a hash-chained audit log** โ€” each entry carries the hash of the entry before it, so modifying any past entry breaks every entry after it. Entries are additionally **Ed25519-signed when a signing key is configured**; without one they are still written and still chained, just unsigned. Chaining is integrity, not authorship โ€” the two are not the same claim and we do not merge them. Risk scoring is Bayesian and reports its own uncertainty, which is what drives escalation rather than a coin-flip at the threshold. --- ## Who this is for ARF is built first for teams where **an agent can already change production state and nobody owns governance yet**. A practical test: - Can one of your agents take an action a customer would notice, without a human in the loop? - If it did that wrongly at 3am, would you be able to show what was decided, by which rule, and on what inputs? - Is there a named owner for that question today? If the first two are *yes* and the third is *no*, that gap is what ARF closes. | Role | What they get | |------|---------------| | **Founder / CTO at an AI-native team** | Governance before the first incident, without a redesign or a compliance hire | | **Platform & SRE leads** | Deterministic gates on agent-initiated production change | | **Security & compliance leaders** | A tamper-evident record of what was decided and why | | **AI/ML teams** | A route to production that survives review | Larger and regulated deployments are served too โ€” through the enterprise tier, with SSO, multi-tenancy and an SLA โ€” but the sandbox and pilot are designed for small teams shipping agents now. --- ## Live demos Both run on mock data. They demonstrate the decision surface; they do not enforce anything. | Demo | What it shows | Status | |------|---------------|--------| | [Risk Dashboard](https://huggingface.co/spaces/ARF-AI/Agentic-Reliability-Framework-v4) | Adjust priors, watch scoring and escalation respond | Running | | [Sandbox API](https://huggingface.co/spaces/ARF-AI/ARF-Sandbox-API) โ€” [`/docs`](https://arf-ai-arf-sandbox-api.hf.space/docs) | Interactive OpenAPI endpoint | Running | Mock responses only. Real enforcement requires sandbox or pilot access. --- ## Public code | Repository | License | What it is | |------------|---------|------------| | [`arf-pattern-examples`](https://github.com/petter2025us/arf-pattern-examples) | Apache-2.0 | A runnable reference implementation of the **pattern** โ€” propose, decide deterministically, record, then execute. Three worked domains, hash-chained audit with a tampering test, and a fail-closed external-policy delegation. Contains none of ARF's engine. | That repository is independent reference code. It is not ARF, it does not contain ARF's risk engine, authority system or execution-admission protocol, and it is useful whether or not you ever talk to us. Everything else โ€” core engine, API control plane, gateway, enterprise extension โ€” is private and stays private. --- ## Access | Layer | Availability | Purpose | |-------|--------------|---------| | **Sandbox** | Free, 1,000 evaluations/month, simulation only | Evaluate the decision surface | | **Pilot** | Time-limited, free by review | Validate on your own use case | | **Enterprise** | Custom deployment | Production enforcement, SSO, multi-tenancy, SLA | Pilot pricing is outcome-based: you pay for verified risk reduction, not per API call. ๐Ÿ‘‰ **[Request pilot access โ†’](https://www.arf-ai.com/signup)** ยท [arf-ai.com](https://www.arf-ai.com/) When applying, include your organization, the use case, rough evaluation volume, and where it runs. --- ## Design principles 1. Deterministic where the decision must be reviewable; probabilistic only where the world genuinely is uncertain. 2. A decision must be explainable to someone who was not there. 3. Uncertainty routes to a person; it never silently becomes approval. 4. The record is written before the action, not after it succeeds. 5. An unreachable dependency is not a permissive one โ€” no control degrades quietly into no control. 6. Auditability is built in, not retrofitted. --- ## Trust & compliance ARF is **architected for SOC 2 readiness** and for review in regulated environments: tamper-evident audit trails, policy gates that cannot be silently bypassed, and explainable reasoning suitable for third-party audit. To be precise about what that does and does not mean: this describes how the system is designed. It is not a certification, not an attestation, and nothing here establishes your compliance with any framework. ARF is also **not** a functional-safety layer โ€” it governs decisions above certified safety systems and does not replace them. --- ## Legal - **Core engine, API control plane, gateway, enterprise extension** โ€” proprietary. No public access. - **`arf-pattern-examples`** โ€” Apache-2.0, and genuinely so. - **This page and ARF marketing materials** โ€” ยฉ ARF Foundation. Not to be copied, redistributed, reverse engineered, or used for AI training without written permission. --- *ยฉ ARF Foundation. All rights reserved.*