Agent Execution
Assurance.
Generation is commoditized. Permission to deploy is not.
The engine
Five acts. One hash. Nothing pre-recorded.
Three agent exports go through the gate ladder — one writes straight to the production database, one ships an AWS key, one is clean. The engine then runs a hundred more times while paths, timestamps, file ordering, locales and timezones are perturbed underneath it. Finally the deploy target is handed a tampered artifact and the token that used to fit it.
- Act 1—Policy gateprod DB write
- Act 2—Credential gatesecret in config
- Act 3—Token issuedall gates clear
- Act 4—Determinism100 runs
- Act 5—Admissionbinding enforced
Noetfield deterministic execution engine — ready.
Five acts. Two blocked deployments, one issued token, one hundred perturbed executions, and a deploy target that refuses an artifact the token is not bound to.
Every hash below is computed inside your request. Nothing is recorded or replayed.
$ ▋
The gate ladder is the product
Eight gates run over the canonical artifact. Any failure withholds the token. There is no ambient permission to deploy for an agent to reach for.
Sensitivity, not just repeatability
A function returning a constant would pass a hundred-run determinism test perfectly. Six controls each change one identity-bearing input and confirm the hash moves.
The binding is enforced, not asserted
Act 5 posts a one-byte-drifted artifact with a still-valid, unexpired token. The receiver re-derives the hash and refuses it. That endpoint is public.
- 8
- gates, G0–G7
- 100
- runs per proof
- 1
- verdict hash
- ~$0.002
- per build · measured
- 6
- negative controls
The architecture
How agent deploy replaces the merge button.
GitHub for code. Noetfield for agent execution. On the agent deploy path, three stages stand in for the pull request, the CI pipeline and the merge button. The artifact cannot run on your infrastructure unless the engine proved it passed — and proved the bytes never changed afterwards.
- 01
Intake
replaces the pull request
On the agent deploy path, code arrives as an artifact — a set of bytes with a canonical identity — not as a branch waiting for a reviewer's attention. Platform source still lives in GitHub; agents present what they built for permission to run.
- Artifact, not a branch
- No merge-queue bottleneck
- Humans keep GitHub for source
- 02
Verification
replaces CI/CD
Eight deterministic gates run over the canonical artifact. A failure returns an exit code and withholds the token. A pass mints an HMAC token bound to that artifact's exact hash, signed with a bound production key and scoped to one target (Cloudflare or Railway).
- G0–G7, exit codes not opinions
- Same input, same verdict, always
- Token signed, bound, target-scoped
- 03
Execution
replaces the merge button
The deploy target re-derives the artifact hash from the bytes presented and checks the token binds to it. No token, or a token bound to different bytes, and nothing deploys — the agent path's stand-in for merge permission.
- Cloudflare and Railway targets
- Binding checked at the edge
- One artifact, one token
The admission controller in stage 03 is a real endpoint at /api/deploy-receiver. It re-derives the artifact hash from the bytes posted to it rather than trusting the hash inside the token, so a token minted for one artifact cannot deploy another. Tokens are signed with a bound production key, scoped to one target (Cloudflare or Railway), and name the subject they were issued to.
This deployment states what it is at /api/attestation: the policy it enforces, that policy's hash recomputed at request time, the gate ladder, and whether a signing key is bound. The key itself never appears there.
Measured cost
Under a quarter per build.
First-party factory measurements — not a list price. Real automation builds on the Noetfield path land around two-tenths of a cent.
- ~$0.002
- typical automation build
- $0.00164–$0.00226
- measured examples
- 113 / $0.382
- 24h factory sample
The ladder
Eight gates, eight exit codes.
Every gate runs on every evaluation, so one call reports every violation. The exit code is the lowest-numbered failing gate's, which keeps it stable no matter how many others also failed.
The vision
We are building the AI-Native Enterprise Platform.
GitHub for code. Noetfield for agent execution — admit, verify, deploy, prove.
Humans still merge platform source on GitHub. Agents that want to publish present an artifact: gates run, a bound token is minted, and Cloudflare or Railway admit only those exact bytes.
The pipeline enterprises run today was built for humans committing code they wrote and understood. Agents break every assumption underneath it. Noetfield inverts that — the artifact is the unit, the verdict is a hash, and permission to deploy is earned, not ambient.