The stack
One layer between your systems and your agents.
Read it top to bottom. Everything above EOS stays untouched. Everything below it inherits provenance. Execution returns to the systems of record, where it always lived.
Green tiers are the verified spine: 403 conformance cases at 0 failures, 45/45 tenant isolation, 9/9 write-path checks with no write method present. The agent gateway that serves this state to a model is design; the spine beneath it is not.
The contract
Nine labels. Every figure an agent receives carries one.
The failure mode of enterprise AI is not wrong answers, it is confident answers of unknown standing. Here, standing is explicit, and a model may not promote a figure from one label to another.
The boundary
What the automation may do here, and what it may not.
Visibility is not authorization. The automation here is dynamic calculation over governed data, not an agent: it never gains a permission because information appears in its context, and it never infers one from what it can render.
May, without asking
- Retrieve canonical state and the evidence behind any figure in it.
- Correlate, classify, summarize and explain across every connected source.
- Simulate and forecast, with outputs labeled scenario.
- Draft and recommend, with outputs labeled recommendation.
- Trace any disagreement to the dated records that produced it.
May not, ever
- Change an authoritative record. No write method exists to call.
- Approve a transaction or create a binding commitment.
- Bypass a permission, or act across a tenant boundary.
- Represent a hypothetical action as a completed one.
- Conceal a contradiction, or fabricate evidence for a conclusion.
Independence
Why the trust layer cannot live inside a system of record.
Every vendor in the stack above will eventually offer an AI that explains its own data. None of them can referee a disagreement they are a party to: an ERP reconciling its own figures is grading its own exam.
The layer that decides what is true across systems has to be independent of every system it reads, or the answer is marketing.
EOS is that independence made structural: read-only toward everything, authoritative over nothing, replaceable without loss because the evidence packs verify offline without us. Your agents get one version of enterprise reality with the receipts attached, and no vendor, including this one, sits inside the loop deciding what they see.
Status, plainly
What exists today, and what is design.
| Layer | State | Evidence |
|---|---|---|
| Read-only spine | Verified, independently executed | 403 cases, 0 failed; 9/9 write path; 45/45 isolation. Run it yourself. |
| Canonical state and reconciliation | Verified against fixtures | Conformance suites per connector. The pilot is the proving engagement; the investor page prices from that starting line. |
| Provenance and evidence packs | Verified | Receipts re-derived exactly; packs verify offline. Open one. |
| Model-provider connections | Declared, not active | Provider-neutral by recorded decision. Mirrored in /facts.json. |
| Agent gateway and authorization workflow | Design | Specified against the labels and boundary above. Ships with the pilot engagement. |
The next step
Hand your agents something worth trusting.
Name two systems that disagree. The scoping conversation is thirty minutes and free, and the first artifact you get is a contested figure with its evidence attached, which is exactly what your agents are missing.