Back to Solution BriefsReal-Time Execution Governance

Govern every agent action as it happens

Trust Runtime sits between your certified agents and every business action they take — validating outputs, scoring confidence, assessing risk, and making governance decisions in real time.

5
Specialized engines per execution
4
Decision outcomes: approve, block, escalate, retry
<10ms
Added latency with sidecar deployment
What You Get

A governance layer between your agents and real consequences

Every output validated. Every risk scored. Every decision enforced — before it executes.

✅
Outputs validated before execution
Schema, evidence, tool trust, contradiction, and consistency checks — every call, every time.
📈
Confidence scored with 7 signals
Not a single model score — a weighted composite of execution quality, tool reliability, and historical agent performance.
⚠️
Business risk quantified automatically
Converts AI confidence into business risk based on transaction value, operational impact, and exposure.
🚦
Decisions enforced by policy
Auto-approve, block, escalate for human review, or request additional evidence — enforced in-process, not post-hoc.
🔒
Policy and compliance enforced live
Active policy packs, data protection controls, and enterprise guardrails run against every output, not just on audit.
⚡
One decorator, zero code change
Add @harness to any function or use auto-instrumentation to wrap existing agents with no refactoring.
Explore the Platform

Related solutions and resources

Trust Runtime operates between Trust Certify (pre-production) and Trust Audit (post-execution).

Solution
Trust Certify
Certify agents before they ever run in production through security, reliability, compliance, and guardrail testing.
Explore Trust Certify →
Solution
Trust Audit
Enterprise audit trails, explainability, and compliance reporting from every runtime decision Trust Runtime makes.
Explore Trust Audit →
Reference Guide
AgentTrust Edge — SDK & API Reference
Full SDK integration patterns, gateway pipeline, pricing tiers, auth configuration, and deployment options.
Open Reference Guide →
How It Works

The Trust Runtime Architecture

Five engines run on every agent execution to validate, score, assess risk, decide, and enforce governance — before any business action fires.

📋
Validation Engine
Runs six deterministic checks on every agent output: schema validation, evidence grounding, tool trust verification, contradiction detection, internal consistency, and active policy compliance. All deterministic — no probabilistic guessing.
🎯
Confidence Engine
Calculates a composite confidence score from 7 weighted signals: schema score, evidence score, tool trust, contradiction score, consistency score, historical reliability, and LLM judge score. Produces a final confidence ∈ [0, 1] with full breakdown.
📊
Risk Engine
Converts AI confidence into business risk based on validation flags, confidence score, transaction value, and operational exposure. Returns a risk score ∈ [0, 1] and a risk tier: low, medium, high, or critical.
⚖️
Decision Engine
Produces one of five outcomes evaluated against your active policy version: approve (passes all checks), block (fails policy or risk threshold), escalate (push to human review queue), request_evidence (ask agent to provide sources), or retry (transient confidence issue). The decision is returned to the SDK before any downstream action executes.
🛡️
Governance Engine
Enforces policy packs, compliance requirements, data protection controls, and enterprise guardrails against every execution. Policies are versioned, testable, and auditable. Guardrails run independent of the model — they cannot be overridden by agent instructions or prompt injection.
Decision Outcomes

Every execution ends in one of four outcomes

✓
Approve
Passes all validation and risk checks. SDK returns agent result unchanged. Execution proceeds.
✕
Block
Fails policy or exceeds risk threshold. SDK raises BlockedError if configured. Execution stops before the business action fires.
↗
Escalate
Pushed to human review queue. Workflow continues by default unless block_on_review=True is set.
?
Request Evidence
Agent is asked to provide verifiable sources. Pushed to review queue pending substantiation.
Execution Pipeline

Agent → AgentTrust Runtime → Business Action

Every agent output passes through all five engines before reaching the system it was meant to affect.

SOURCEAgentVALIDATION6-Check EngineSchema · Evidence · ToolsCONFIDENCE7-Signal ScoreComposite ∈ [0, 1]RISKBusiness Risk EngineLow · Med · High · CriticalDECISIONPolicy VerdictApprove / Block / EscalateOUTPUTBusiness ActionExecuted only on Approve
Figure 1 — Trust Runtime execution pipeline: every agent output passes through Validation → Confidence → Risk → Decision before any downstream business action is allowed to execute.
Integration & Deployment

Deploy how your infrastructure demands

One line to integrate, any deployment topology to run it.

SDK Integration Patterns

@harness decoratorAuto-instrumentDirect clientLangGraph nodeCrewAI callbackQueue mode (offline)

Deployment Modes

Docker ComposeKubernetes / HelmSidecar (pod-local)Embedded (SQLite)VM / Linux / WindowsAir-Gapped
Edge-First Architecture

No data leaves your network. Ever.

Trust Runtime runs inside your environment — as a Docker container, Kubernetes sidecar, or standalone process. No agent outputs, no confidence scores, no business decisions leave your perimeter. Near-zero latency with sidecar deployment. Designed for banking, insurance, healthcare, and government from day one.

🏦 Banking🏥 Healthcare🛡️ Insurance🏛️ Government💼 Financial Services⚖️ Legal & Compliance
Ready to Govern Your Agents at Runtime?

Every agent action governed. Every decision defensible.

Add Trust Runtime to your certified agents and close the gap between AI output and business consequence.

Deploy Trust Runtime Free →
Solution Briefs ↗

More from the platform

Explore the other products and deep-dive capability briefs that complete the AgentTrust OS trust layer.

The Three-Layer Trust Platform

Core Products


Capability Deep-Dives

What the platform eliminates

Adversarial Attack Defense

Stop Adversarial Prompts Before They Reach Your Agents

Two-layer semantic defense — confidence gate first, LLM judge second — catches adversarial payloads before any action executes, without relying on pattern lists that attackers already know how to evade.

Explore →
Deterministic Enforcement

Make Every Governance Decision Outside the Model

Four injection-proof, model-free deterministic gates evaluate every request before an LLM ever sees the payload — the decision is made and enforced entirely outside the model.

Explore →
Framing Attack Prevention

Defeat Framing Attacks That Keyword Filters Miss

Intent-based, pre-execution defense scores confidence first then runs semantic intent evaluation — catches framing attacks without keyword lists that attackers trivially bypass.

Explore →
Behavioral Intelligence

See Salami Campaigns Across the Full Conversation

Behavioral drift tracking compares each agent's history and fleet baselines across turns — salami campaign injections that look innocuous message-by-message become visible as a pattern.

Explore →
Architecture Hardening

Remove the Model from Your Enforcement Path

Deterministic-first architecture puts four gates in front of every request — the async LLM judge enriches the audit record after the fact, but it never touches the verdict.

Explore →