All projects
Project

Dana — Governed Agent Runtime

Contract-driven agent runtime rebuilt from an empty repository to two authorized staging deployments in five weeks, solo: 98,896 lines, 223 HTTP routes, 1,453 tests, 68 typed operator contracts behind a single policy-enforcing gateway, SSE streaming, and a human approval gate on every consequential write.

agentsproductioninfrastructurellm

Problem

Agent systems are easy to demo and hard to be accountable for. Once an agent can send an email, spend money, or write to a student's file, the question stops being "is the model good" and becomes "who authorized this, what exactly did it do, and can we prove it."

Solution

A three-layer authority model — 8 permission classes × 8 effect types resolved by a policy engine into 25 runtime capability flags — sitting under 68 JSON-Schema-validated operator contracts, a frozen versioned client contract (26 resources, 143 endpoints, 14 SSE event types, 26 named invariants), an append-only audit log enforced by database triggers, a per-request cost ledger, and human-in-the-loop action claims on every write. 41 SQL migrations, 1,370 tests green in 179 seconds, and a behavior-certification harness that gates releases on pre-declared numeric thresholds.

Impact

Two authorized staging rollouts, the second a coordinated seven-component release under a written gate. I held the final certification gate RED rather than pass it on machine evidence alone, because the human usability study behind it had not been run. Staging only — outbound side effects deliberately disabled.

Stack

PythonFastAPIPostgreSQLRedistelicSSEDockerGitLab CINext.jsLaravel

Dana — Governed Agent Runtime

98,896 lines, 272 Python files, 223 HTTP routes, 41 migrations and 1,453 tests, built alone between 10 July and 15 August 2026 — 683 commits across six repositories on twenty active days.

The thesis: the model may propose, but durable state and policy decide what happened. 68 typed operator contracts, JSON-Schema validated at registration, sit behind a single policy-enforcing gateway. A three-layer authority model resolves 8 permission classes against 8 effect types into 25 runtime capability flags. Every consequential write is claimed by a human through an approval gate. The audit log is append-only, enforced at the database layer by BEFORE UPDATE / BEFORE DELETE triggers that raise SQLSTATE 45000. Cost is reserved before a call, not reconciled after it.

Deployed to staging twice under written authorization — the second a coordinated seven-component rollout with migration rehearsal and rollback-by-image. Never production; outbound side effects were deliberately disabled throughout.

The thing I'd put on the record is the rejection. I built an adversarial review step into my own release process and gave it authority to block the release. On the Document Intelligence candidates it used that authority: it ran a negative test against my verifier — evidence hash zeroed, exit code 0 → 99, skipped 0 → 99, status left as passed — and the verifier accepted the forged report and printed TAMPERED_REPORT_ACCEPTED. The review came back REJECT.

I took the reject rather than overriding it: four numbered remediations, both release candidates regenerated under the corrected contract and re-reviewed, and REJECTED_RC_REVIEW.md left in the repository where anyone can find it. The review is signed by a Product Owner-authorized AI reviewer and says so in its own header — it deliberately does not claim a human credential. Full case study in progress.