๐Ÿšฆ Action-Level Gates

Tier 2 โ€” gates that inspect what a model may do, not what it says

Tier 2 ยท #7

Frontier Control Gate

Sits between a frontier model and the world. The model proposes an action; the gate decides ALLOW / BLOCK / REQUIRE_APPROVAL before it executes. Nothing the model emits runs unchecked.
action: send_email(to="all-staff@company.com", body=customer_records)
action: read(file="report_q3.pdf")
action: git_push(branch="main", force=true)
Tier 2 ยท #8

Action Licence Gate

"A harness executes; it does not license." Sits between an intent and its action; returns exactly LICENCE or REFUSE with a measured rationale.
intent: deploy v2.1 to production (tests green, change advisory approved)
intent: delete backups older than 30 days (no retention policy cited)
Tier 2 ยท #9

Robotics Safety Gate

Wraps the causal engine into a C API (es_safety_gate.h). One question: "Given what is observed now, would this action cause a bad outcome?" DEFAULT-DENY โ€” returns SAFE only on positive evidence.
observed: human_absent=false, arm_speed=0.9 ยท action: close_gripper(force=80N)
observed: human_absent=true, workspace_clear=true ยท action: weld(joint=B)
observed: sensor_1=ERROR (stale), sensor_2=OK ยท action: advance_arm(2m)
The design point

Why action-level, not text-level

Earlier gates (Moral / Behavior / Harm Marker) inspect text. A frontier model can produce perfectly polite text that proposes a catastrophic action. Action-level gates close that gap: they sit on the actuation boundary, where text becomes a consequence. Every gate here is deterministic and reason-coded โ€” the model does not get to grade its own action.