NOETFIELDLive AlphaRun the proof →
Evidence Lab · running live

Agent Execution
Assurance.

Generation is commoditized. Permission to deploy is not.

The engine

Five acts. One hash. Nothing pre-recorded.

Three agent exports go through the gate ladder — one writes straight to the production database, one ships an AWS key, one is clean. The engine then runs a hundred more times while paths, timestamps, file ordering, locales and timezones are perturbed underneath it. Finally the deploy target is handed a tampered artifact and the token that used to fit it.

noetfield engine — determinism proofidle
  1. Act 1—
    Policy gate
    prod DB write
  2. Act 2—
    Credential gate
    secret in config
  3. Act 3—
    Token issued
    all gates clear
  4. Act 4—
    Determinism
    100 runs
  5. Act 5—
    Admission
    binding enforced

Noetfield deterministic execution engine — ready.

Five acts. Two blocked deployments, one issued token, one hundred perturbed executions, and a deploy target that refuses an artifact the token is not bound to.

Every hash below is computed inside your request. Nothing is recorded or replayed.

$ ▋

live execution · ~12s · nothing pre-recorded

The gate ladder is the product

Eight gates run over the canonical artifact. Any failure withholds the token. There is no ambient permission to deploy for an agent to reach for.

Sensitivity, not just repeatability

A function returning a constant would pass a hundred-run determinism test perfectly. Six controls each change one identity-bearing input and confirm the hash moves.

The binding is enforced, not asserted

Act 5 posts a one-byte-drifted artifact with a still-valid, unexpired token. The receiver re-derives the hash and refuses it. That endpoint is public.

8
gates, G0–G7
100
runs per proof
1
verdict hash
~$0.002
per build · measured
6
negative controls

The architecture

How agent deploy replaces the merge button.

GitHub for code. Noetfield for agent execution. On the agent deploy path, three stages stand in for the pull request, the CI pipeline and the merge button. The artifact cannot run on your infrastructure unless the engine proved it passed — and proved the bytes never changed afterwards.

  1. 01

    Intake

    replaces the pull request

    On the agent deploy path, code arrives as an artifact — a set of bytes with a canonical identity — not as a branch waiting for a reviewer's attention. Platform source still lives in GitHub; agents present what they built for permission to run.

    • Artifact, not a branch
    • No merge-queue bottleneck
    • Humans keep GitHub for source
  2. 02

    Verification

    replaces CI/CD

    Eight deterministic gates run over the canonical artifact. A failure returns an exit code and withholds the token. A pass mints an HMAC token bound to that artifact's exact hash, signed with a bound production key and scoped to one target (Cloudflare or Railway).

    • G0–G7, exit codes not opinions
    • Same input, same verdict, always
    • Token signed, bound, target-scoped
  3. 03

    Execution

    replaces the merge button

    The deploy target re-derives the artifact hash from the bytes presented and checks the token binds to it. No token, or a token bound to different bytes, and nothing deploys — the agent path's stand-in for merge permission.

    • Cloudflare and Railway targets
    • Binding checked at the edge
    • One artifact, one token

The admission controller in stage 03 is a real endpoint at /api/deploy-receiver. It re-derives the artifact hash from the bytes posted to it rather than trusting the hash inside the token, so a token minted for one artifact cannot deploy another. Tokens are signed with a bound production key, scoped to one target (Cloudflare or Railway), and name the subject they were issued to.

This deployment states what it is at /api/attestation: the policy it enforces, that policy's hash recomputed at request time, the gate ladder, and whether a signing key is bound. The key itself never appears there.

Measured cost

Under a quarter per build.

First-party factory measurements — not a list price. Real automation builds on the Noetfield path land around two-tenths of a cent.

~$0.002
typical automation build
$0.00164–$0.00226
measured examples
113 / $0.382
24h factory sample

The ladder

Eight gates, eight exit codes.

Every gate runs on every evaluation, so one call reports every violation. The exit code is the lowest-numbered failing gate's, which keeps it stable no matter how many others also failed.

G0
Artifact intake
canonical form is unambiguous
exit 10
G1
Governance-path lock
no agent writes to laws, ledgers or receipt schemas
exit 11
G2
Approval-language lock
agents produce evidence, never approvals
exit 12
G3
Sweep lock
nothing staged outside the dispatch's allowed paths
exit 13
G4
Policy gate
no direct-to-production side effects
exit 20
G5
Credential gate
no secret material in the artifact
exit 40
G6
Transform fidelity
evidence rows survive every format conversion
exit 30
G7
Policy immutability
the cage is not editable from inside the cycle
exit 50

The vision

We are building the AI-Native Enterprise Platform.

GitHub for code. Noetfield for agent execution — admit, verify, deploy, prove.

Humans still merge platform source on GitHub. Agents that want to publish present an artifact: gates run, a bound token is minted, and Cloudflare or Railway admit only those exact bytes.

The pipeline enterprises run today was built for humans committing code they wrote and understood. Agents break every assumption underneath it. Noetfield inverts that — the artifact is the unit, the verdict is a hash, and permission to deploy is earned, not ambient.