confused, decision, man, doubt, anxiety, unsure, correct, wrong, question, decide, right, thinking, choice, making, negative, uncertain, opinion, trouble, answer, mark, option, problem, choose, solution, cartoon, confused, confused, decision, doubt, doubt, correct, wrong, wrong, wrong, wrong, wrong, question, question, question, decide, thinking, thinking, thinking, thinking, choice, opinion, answer, problem, problem

Allow, Transform, Escalate, Block: The Four Things That Can Happen to an Agent Action

When an AI coding agent proposes an action – running a command, editing a file, staging a commit – the governance layer in Ethosure must produce a response. That response is always one of exactly four options. Not “maybe” or “it depends.” Four options, each with a precise meaning, each producing a specific outcome for the agent and a specific record in the evidence log. This simplicity is intentional. A governance system with too many Read more

Fail-Closed by Default: Why “Block When Unsure” Is the Safe Choice

There is a classic security engineering question that reveals a lot about a system’s design philosophy: what does it do when something unexpected happens? When a system encounters ambiguity – a request it cannot fully parse, a condition it was not designed to handle, an edge case that falls between the rules – does it allow the action or block it? Systems that allow when unsure are called fail-open. Systems that block when unsure are Read more

Deterministic vs. Probabilistic: Why “The Same Answer Every Time” Matters

Imagine two versions of a fire suppression system. The first version, when it detects heat above a threshold, activates the sprinklers – every time, without exception. The second version analyzes the heat pattern, consults a learned model, and usually activates the sprinklers – but sometimes decides it was probably just someone cooking, so it waits. Which system would you trust with your building? This is the difference between deterministic and probabilistic decision-making, and it is Read more

Decide vs. Confine: The Control Plane and the Data Plane Explained

Security engineers often talk about “defense in depth” – the idea that no single control should be the only thing standing between an attacker and damage. coding-ethos and Ethosure apply this principle through a clean architectural separation between two layers with different jobs: the control plane decides whether an action should happen at all, and the data plane limits what an approved action can do once it runs. Understanding this separation helps explain why Ethosure’s Read more

What is CEL? The “Calculator” That Makes Agent Decisions Deterministic

One of the most important words in AI governance right now is “deterministic.” It means: given the same input, the system produces the same output, every time, without exception. A coin flip is not deterministic. A weather forecast is not deterministic. A fire suppression system is – and that is why you trust it. The enforcement layer behind Ethosure achieves determinism through a technology called CEL – the Common Expression Language. Understanding what CEL is Read more

Policy-as-Code: Turning Your Written Rules into Rules a Computer Enforces

Most organizations have no shortage of written rules. There are security policies, coding standards, compliance frameworks, architectural principles, and onboarding guides. The problem is that written rules are only as good as the people – or agents – reading them. When an AI coding agent writes a thousand lines of code in the time it takes a developer to drink a coffee, a PDF of best practices is functionally useless as an enforcement mechanism. Policy-as-code Read more

developer, programmer, technology, software, programming, coding, code, business, development, design, application, laptop, digital, monitor, program, professional, information, workplace, people, html, network, creative, language, yellow business, yellow computer, yellow technology, yellow laptop, yellow network, yellow digital, yellow design, yellow company, yellow information, yellow code, yellow language, yellow coding, yellow software, yellow creative, yellow programming, software, software, software, software, software, programming, coding, coding

What is coding-ethos? The Engine Behind Ethosure, in Plain English

Every company deploying AI coding agents faces the same uncomfortable question: how do you know what the agent actually did, whether it followed your rules, and whether the evidence would hold up to a regulator’s scrutiny? Ethosure’s answer rests on an open-source project called coding-ethos, built and owned by one of Ethosure’s founders, Patrick Audley. This article walks through what coding-ethos is, how it works at a conceptual level, and why its architecture choices matter Read more

Ethosure Design-Partner Pilot: A Scoped Plan for Your First Agent Deployment

This document describes a scoped six-to-eight-week design-partner pilot with Ethosure. The goal is to take one AI agent already running in your environment, instrument it with Ethosure’s enforcement layer, and produce an auditor-ready evidence pack. Three objectives drive the pilot: (1) validate technical fit – confirm the enforcement layer integrates with your agent infrastructure without disrupting legitimate work; (2) establish a compliance baseline – capture the agent’s current policy compliance posture so improvements are measurable; Read more

The Enforcement Core: We Own the Hardest Part and It Already Runs

The hardest part of AI agent governance is not writing a policy document. It is building infrastructure that enforces the policy – at runtime, deterministically, on every action, without being bypassable – and producing a tamper-evident record while doing it. Most organizations trying to solve the AI governance problem discover that this is the part they cannot easily build themselves. Ethosure’s enforcement core is built on a coding-ethos project.  It carries the OpenSSF Best Practices Read more

report, request, resources, agreement, documents, bank, business, businessman, assistant, ceo, claim, colleague, communication, company, consultant, consulting, contract, support, corporate, co-worker, deal, employee, employer, employment, entrepreneur, executive, finance, financial, formal, help, hiring, holding, insurance, investment, investor, job, leader, loan, looking, management, new offer, office, opening, owner, papers, paperwork, people, hand, planning, professional, project, resume, search, secretary, service, signature, sitting, staff, team, teamwork, blue business, blue office, blue paper, blue team, blue support, blue help, blue news, blue community, blue finance, blue communication, blue bank, blue leader, blue job, blue company, blue businessman, blue teamwork, blue plan, blue planning, blue document, blue entrepreneur, blue management, blue new, blue service, ceo, ceo, ceo, ceo, ceo, claim, claim, investor, investor, investor, owner, resume, resume, resume, resume

Who in the Enterprise Needs This: What Each Person in the Room Gets

Conversations about AI governance often stall because the people in the room have different jobs, different concerns, and different definitions of what a solution looks like. The CISO is thinking about access controls. The chief risk officer is thinking about bounded, demonstrable governance. The compliance officer is thinking about audit trails. The head of engineering is thinking about whether this slows the team down. The board is thinking about accountability. Ethosure does not ask these Read more

Subscribe to Ethosure's Newsletter to get monthly updates on AI Governance

We don’t spam! Read our privacy policy for more info.