ACP-SPEC-001 · Apache-2.0

A credential is not authorisation.

Give an agent the keys and every document it reads holds the keys: an instruction hidden in an invoice or a web page can spend them. ACP moves the allow-or-refuse decision out of the AI and into a separate service the AI cannot reach. The model proposes. It never authorises.


The shape

Asks, and can do nothing else

The AI writes down what it wants done. It holds no keys and can reach nothing on its own.

The model
Works out how risky that is

From a rulebook the AI cannot see or edit - never from what the request claims.

Policy engine
Collects the human sign-offs

Where the rulebook demands them, named people sign this exact request, not a summary of it.

Approvers
Acts, or nothing happens

It acts only on a signed record that every check passed. One failed check and nothing happens.

Executor

An agent that has been fooled can ask for a dangerous action a thousand times and never once cause it. The rulebook sets the risk level, not the agent, and anything that cannot be undone waits for human signatures on that exact request.


Every number here replays on your machine

36proved, not just tested
covers every case
82/82ways to break it, tried
none of them worked
36/36remove a protection
the tests notice

A test tries some cases. A proof settles all of them. These settle questions like whether whoever runs the system can approve their own irreversible action, and whether an approval for one action can be reused for another. Both answers are no, permanently.

The 82 are every way we could think of to break it, written down and run. The last row answers the question that invites: are those tests real, or would they pass whatever the code did? Take any single protection out and the tests notice. All 36 times.

Check them rather than believing them:

git clone https://github.com/yacine-kellib/agent-control-plane
cd agent-control-plane
./tools/verify.sh --suites

What this does not claim