KedgeFlow A Programmable Control Plane for Consequential AI Agents
KedgeFlow specifies a programmable control plane for admitting, authorizing, enforcing, and reconciling consequential agent actions. Its formal description, a Distributed Epistemic Admission and Transaction Control Fabric, means that policy, time-bounded evidence, multi-writer coordination, and conserved authority govern protected effects. Nine logical components and six interfaces connect existing agent harnesses to these responsibilities. The deployment profile binds user authorization, SPIFFE workloads, and DPoP proof keys; exchanges target credentials after claim; and defines cryptographic human review, Consequential Tool Descriptors, and hierarchical saga budgets. Negotiated MCP/A2A extensions connect existing workflows. Cedar, etcd, and durable workflow engines provide reusable substrates. Resource guarantees remain scoped to actual predicates and completion boundaries. Complete schemas and bounded reference implementations accompany the specification; Local deployment and staged adoption are defined through explicit acceptance gates; production conformance and industry ratification remain separate requirements.
Authors
- JUN HE
- DEYING YU
Institutions
- Open Knowledge (United Kingdom) (GB)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-06
- DOI
- https://doi.org/10.5281/zenodo.23182412
- Primary Topic
- Access Control and Trust
- Type
- article
- Field-Weighted Citation Impact
- 0.00