Skip to content

Solario Zero Trust Principle

Agents are never
trusted by default.

The Solario Governance Harness constrains what agents can do, verifies what they produce, requires human authority at key moments and records every decision.

01 / The governance harness

Governance surrounds
the complete lifecycle.

Governance is not a review added after generation. It binds the Project before execution, controls every state transition and remains active from signed Intent through deployment.

01Intent
Gate
02Design
Gate
03Build
Gate
04Test
Gate
05Deploy

Governance Harness

Policy · deterministic controls · human checkpoints · full audit trail

02 / Policy before execution

Software architecture
becomes enforceable.

The factory does not ask an agent to remember how your organisation builds software. Rules are described, inherited by the Project and evaluated as part of the production system.

01Factory governance

The non-negotiable baseline.

Organisation-wide architecture rules, approved technical stacks, language-specific ADRs, code quality standards, security expectations and test policies define how the factory may operate.

ARCHITECTURE · STACKS · ADRS · QUALITY · TEST POLICY

02Project governance

Rules become workload-specific.

Each Project adds its delivery strategy, system boundaries, client practices, acceptance obligations and authorised exceptions. Workloads inherit these controls before execution begins.

BOUNDARIES · OBLIGATIONS · PRACTICES · EXCEPTIONS

03Human authority

Accountability stays explicit.

Named people retain authority at key lifecycle moments. Product Owners approve Intent; engineering and delivery authorities validate the decisions and outputs that require human judgement.

OWNERS · CHECKPOINTS · APPROVALS · VERDICTS

03 / No agent decides alone

Control the action.
Verify the result.

Generative work may be probabilistic. Whether an artifact satisfies its obligations is not left to agent confidence. Each step passes through explicit controls and authority.

  1. 01

    Constrain

    Give agents bounded tools, context, permissions and obligations.

  2. 02

    Execute

    Run work through the Orchestrator and explicit state machine.

  3. 03

    Verify

    Use deterministic controls to test artifacts and declared outcomes.

  4. 04

    Authorise

    Require accountable human approval where judgement cannot be delegated.

  5. 05

    Record

    Retain inputs, decisions, runs, findings, repairs, approvals and verdicts.

04 / Traceable at all times

The production record
is produced with the software.

Requirements, decisions and approvals do not have to be reconstructed for the next change or audit. They remain connected to the work that caused them and the verdict that released them.

Intent

Requirement approved

Business goal, requirement, acceptance basis and Product Owner authority.

Decision

Architecture recorded

Selected approach, constraints, alternatives, author and applicable policy.

Execution

Run observed

Models, tools, inputs, findings and repair loops exposed through OpenTelemetry.

Verdict

Release authorised

Deterministic checks, exceptions and human approvals retained with the output.

Your standards. Your perimeter.

Use the factory without surrendering control.

Run managed on AWS or inside your environment, including restricted on-premise deployments with local models. The code, documentation and production record remain yours.