Agentic Terminal Talk to us

Money now moves automatically under written rules. A camera reads a plate and posts a toll. A transaction clears under scheme rules. A scam loss is split between two institutions under a regulator's framework. In each case a machine computes an amount under a document that runs to hundreds of pages and changes constantly. When the amount is wrong, somebody bears it.

These systems already decide. What they cannot do is show which version of which rule produced the answer. That is why industries that decide in real time still pay for retrospective audit, and why a wrong amount gets argued about instead of resolved.

A determination for the amount, checked against the written rules, before it posts.

We convert the governing rules clause by clause into something a system can check. We decide each charge before it posts: allow, refuse, or hold. Where the text does not settle it, we hold rather than guess. Every determination carries the rule that produced it, and any party can re-derive it independently.

For your security team Check every claim on this page against a published artifact

For the party that bears the cost when an automatically computed charge is wrong.

The Agentic Terminal console, Overview page, reading the Rio-Santos corpus. The headline reads 8,966 of 10,000 determined without a person, 2 contract readings still open. A chargeback exposure panel breaks 502 contested charges into 431 with no determination in front of them, 398 posted at the determined amount, 60 never posted and 44 held. A ring chart splits 10,000 evaluated passages into allow, refuse and hold.
A study on public BR-101 Rio-Santos free-flow documents, run on a synthetic corpus. The Overview page of our console, on the demonstration build. Of 10,000 synthetic passages, 8,966 were determined without a person and 1,034 were held because the contract can be read two ways and both readings are defensible. Of 502 contested charges, the ones with no determination in front of them post R$ 4.103,26 and refund R$ 3.373,01 of that at double; with a determination in front they post R$ 2.903,03. The corpus is authored for the demonstration, the run is a batch, and the records carry no signature. It is not a forecast, not a savings claim, and not any operator's book. Where we have done it says what has and has not been run elsewhere.
01 The problem, stated as the buyer experiences it

The rule is written down. Nothing can evaluate it.

The governing rules sit in a contract, a resolution, a circular, a statute: clauses nobody has made machine-evaluable. Every rules platform on the market assumes you arrive with your rules already modelled. Most institutions do not.

An institution has a written rule. It is approved, it is in force, and it exists as prose in an operating document: a concession contract, a transport regulator's resolution, a central bank circular, a supervisory guideline. Prose cannot be evaluated, cited by clause, or replayed against past cases. A decisioning platform can evaluate a rule only once someone has modelled it, and for this rule nobody has. So the amount gets computed anyway. What was charged is recorded; which clause it rested on, and whether the text settles the case at all, is not.

Every rules platform assumes that work is already done: that someone has turned the prose into conditions a machine can test. That is a property of the category, not of any one product, and for most institutions the assumption is false. The conversion is the work, and it is usually the work nobody has done.

Who bears the cost
  • A Brazilian concessionaire refunds a wrong toll charge at double within seven days.
  • A US turnpike authority forfeits the toll entirely if it bills late.
  • A card issuer carries the chargeback when a charge posts straight to a card.
  • A bank or a telco carries the loss under a shared-responsibility framework.

What is left is the question the arrangement was never designed to answer: which clause did this amount rest on, and does the text settle it at all?

02 What we do

A determination, and the clause it rests on, before the charge posts

We sit between the read and the posting. We do not post, and we do not stop a posting.

This section describes the product being delivered. The status section states what is built today, and where the two differ, the status section is right.

The read or transaction
A plate, a transaction, a claim or a notice, with its inputs.
Determination
The decision to allow, refuse or hold, with the rule that produced it.
The client's own system
Posts, refuses or holds.

We do not control the machine.

  • We convert the governing rules clause by clause into a register: the encoded clauses and the outcomes each one allows, in a form a system can check.
  • We decide each charge before it posts: allow, refuse, or hold.
  • We hold rather than guess where the text does not settle it. The same input always produces the same answer, so no two runs disagree.
  • We produce a record any party can re-derive independently, without taking our word for the encoding.
What "hold" means

A published rule sometimes sets a standard but gives no yes-or-no test a system can apply to an individual case without further facts or judgment. When that happens we record the clause as unsettled rather than guess. That is what hold means throughout this site.

03 Where we have done it

Six places, six different kinds of legal instrument

A national transport regulator's resolution, a US state statute, a municipal ordinance, a central bank circular, a supervisory guideline, and a regulated institution's own published notice.

What has been converted, and what has been run against it
Place Status Confirmed external figures
Brazil, Rio-Santos free-flow Converted and simulated 93 entries; 10,000 passages run
Singapore, MAS SRF Guidelines Converted and contributed 104 clauses, 30 ambiguities, 2 of them blocking; 7,396 of 42,188 constructed synthetic claims held
Singapore, a digital bank's published SRF notice Converted, de-identified 54 clauses, 18 ambiguities; clause counts only, no run figures
Mexico, Banxico Circular 34/2010 Converted and run 19 clauses: 10 decidable, 3 setting a standard with no test, 6 unsettled; 240 requests, 322 determinations over a constructed corpus
United States, NC Turnpike Converted, no runs 64 entries
United States, Chicago PDD Converted, synthetic trips 54 entries
United Kingdom, PSR 2017 and the APP regime Scanned No clause count, no run figures

Two layers, shown together: Singapore

A regulator's framework is the shared floor, with an institution's own published notice layered on top. Singapore is the only place we can show this rather than describe it in future tense. The MAS SRF Guidelines, the floor, are 104 clauses with 30 ambiguities, 2 of them blocking, run against 42,188 constructed synthetic claims, of which 7,396 were held. The digital bank's published notice, layered on top, is 54 clauses with 18 ambiguities. That is a clause count. This layer has not been run.

A layered register, not a layered study: only the floor layer carries a run.

Limits
  1. Every study here runs in batch, on constructed or synthetic populations. A live path awaits an engagement.
  2. A determination proves what the engine decided, not that the authority agrees with the encoding.
  3. A live determination needs inputs the public rule omits: rate tables, exemptions, account state, and the client's own posting rules.
  4. Records in these studies carry no signature.
  5. Counts describe each corpus, not real volume.
  6. Nothing here is a safety, savings, or new-regulation claim, and none of it describes any named client's operations.
04 Where the texts do not settle it

Three places a published text leaves the answer open

Every one of these is a real reading of a real document. None of them is resolved by reading harder.

01

North Carolina

The statute says the Authority "waives" rather than "may waive" collection of the toll, so we ruled the consequence automatic. Whether that waiver also bars a separate fee and penalty, the text names only "the toll", so we held that open.

02

Brazil

The contract leaves the order of a multiplier open between two recorded readings. Both are defensible. 936 passages wait on it.

03

Chicago

With no public permit terms, 7 of 8 trip-bearing entries stay held on every trip against public text alone. That is a limitation of the public record, and it is the reason an operator's own documents are the engagement.

An implementation that returns a number has to choose. Picking silently is what produced 1.3 million cancelled fines in Brazil alone.

05 Questions an enterprise buyer asks

The questions that decide whether this gets forwarded internally

Answered as they would be answered in diligence, including where the answer is not yet.

Who does the conversion work, and what do we have to supply?
We do, by hand, with our own harness. You supply the written policy as you operate it today, the regulation it implements if you can name it, and a person who can answer for the institution when the text leaves a reading open. Every conversion so far has been of public regulation, plus one rehearsal on a provider manual from a US state Medicaid managed care programme. There is no self-serve conversion tool, and we would rather say so.
What happens when our policy changes?
The register is versioned. A change to the rule is a new register version, never an edit to the old one, and every determination cites the version it was decided under. Running the new version against the same corpus before it goes live is the same work again. What is not built is noticing that your document changed: today you tell us, and the change is a conversion pass.
What happens to a term our own document uses but never defines?
It is recorded as ungrounded: a term the document decides outcomes with and supplies no meaning for. Nothing guesses at it. A clause that turns on it waits until the institution supplies the meaning, and a determination that rests on a supplied meaning says so in its result, not only in its provenance. A term defined elsewhere and cited is recorded differently from one with no pointer at all.
How do we know the encoded rule matches the rule as written?
By measurement, not assurance. The encoded register and the rule as written are evaluated over the same generated fact sets, and every disagreement is counted and classified by cause. That divergence report is the deliverable of the conversion, and it carries its own denominators. One such measurement is published: the conversion finding on Illinois Medicaid managed care.
Does a refused charge produce a record?
Yes, and that is deliberate. A refusal and a hold produce the same record as an allow, so the charges that did not post are evidenced as well as the ones that did. In the studies on this page those records carry no signature, which the limits under section 03 state.
Where does our data go? Does the vendor see it?
The service runs in your infrastructure. Your source documents, your rate tables and the inputs behind a charge stay there. What leaves is a determination and the clause it rests on, not the data the determination was reached over.
What security artifacts are available, and when?
No SOC 2 report today, and we are not yet in an observation window. We are not going to put a date on it here. The engine is self-hosted and runs on your inputs, so our internal controls are not the control there. Yours are. The one place we sit in the chain is the encoding: we converted the text, and a determination is only as good as that conversion. That is why the divergence report is the deliverable of a conversion and why any party can re-derive a determination from the same rule version without taking our word for it. In the meantime a design partner gets an MIT-licensed engine they can read, permanent published schemas, and contractual commitments.
How does this sit alongside the systems that compute and post the charge?
We do not connect to any of them, and there is no connector to any of them on our roadmap. Your system asks us for a determination and then does its own posting, and that exchange is the entire integration surface.
06 Verify it yourself

Do not take our word for any of this

The specification, the schemas and the engine are public and permanent. An engineer can check this page without talking to us.

Contest

Any party, a disputing customer, a regulator, or the institution posting the charge, can re-derive the same decision from the same rule version, without taking our word for the encoding. In the Brazil study, 20,707 of 20,707 records re-derived with 0 mismatches.

These are usable on their own, not only as evidence. The engine is MIT licensed and installable from npm as @observer-protocol/policy-engine, and the record model is a published schema at a permanent URL, so an implementer can adopt either without adopting us.

The record schema
v2.7 · current

The exact document a record validates against, at a stable URL that never changes. Every version stays served at its own URL; a change is a new URL, never an edit.

https://observerprotocol.org/schemas/delegation/v2.7.json
The specification
CC BY 4.0

What every field means, what is enforced, and what is not.

https://github.com/observer-protocol/aip
The engine
Repository

MIT licensed, published, with a cross-engine parity suite at packages/parity-harness.

https://github.com/observer-protocol/op-policy-engine
A signed determination record from one of these studies
not yet published

Signed over its own canonical bytes and re-derivable by anyone holding it, against a published key, with nothing from us. The records behind the studies named on this page carry no signature today, so one is not yet published and there is nothing here to link. We would rather name the gap than link a record that does not carry the property this section is about.

07 Status
Status · 16 September 2026
Where the launch surface stands
Built and tested Designed, not built Specified, not built
The conversion and determination core A live path. Every study named on this page ran in batch, over a constructed or synthetic population. Conversion as a harness. Conversion is a session and a human relaying: of its seven steps, two are instrumented, one partly, one for a single domain, and three are sessions.
Determination records, signed and verifiable from the file alone Simulation with a divergence report by clause. There is no historical case set, no client intake distribution and no replay corpus. A synthetic corpus generator and a restatement-against-encoding divergence instrument exist, and are not this.
The console in the figure at the top of this page. It serves converted corpora mirrored into its own build, it is access-gated, and it is not deployed for any client. A client deployment. The services that back the console have no access control and bind to loopback, and nothing runs in a client's estate.
The register format, its schema and validator, and one interpreter that reads a register and evaluates it: three registers as data, byte-identical to the hand-written evaluators over 120,052 records, with 24 of 99 clauses refused for lack of a declared result domain. It runs locally on one machine, there is no CI in either repository, and the hand-written evaluators remain the oracle.
A router that dispatches by clause disposition, running locally. Its person lane dispatches to nothing, because there is no person surface, and its agent and panel lanes are reachable only by a register that names them, which no register does today.
The published engine package, 1.0.0-rc.21, which latest and rc both resolve to. The interpreter, the registers and the router are not in it.

The console. The figure at the top of this page is a screenshot of a demonstration build, reading a corpus authored for the demonstration. It is access-gated and it is not deployed for any client. Nothing in it was read from a running client system, no figure in it measures anyone's operations, and the records behind it carry no signature.

Conversion, simulation and a live path. Conversion exists as a register format, a schema, a validator and an interpreter, and otherwise as a person: it is a session and a human relaying, not a harness. Simulation as we describe it is specified and not built: nothing replays a client's historical determinations, because no historical case set, no client intake distribution and no replay corpus exists. A live path has never run. Every study named on this page is a batch over a population we constructed.

Who we are working with. We are working with our first design partners. We have no production customers.

08 Talk to us

If this is your decision

If you have a decision like this, an amount computed automatically under written rules, where a wrong one costs you, we would start by looking at it with you. Which rules govern it, where those rules go quiet, and what a wrong one actually costs. That conversation tells us both whether there is something worth building.

A good thing to arrive with: the document the amount is computed under, and one charge somebody argued about.

These come to Boyd Cohen, co-founder, and he answers them. We reply from a person, not a sequence. Nothing here is added to a mailing list.