AS ActionSlate Agentic Release Assurance BACK TO LIVE DEMO ↗
CONTROL BOUNDARY
Why ActionSlate exists

Capability
is not
authority.

An AI agent may be able to publish a trailer, localize it, use a digital voice, and spend money. None of those capabilities prove that it is authorized to do them now.

THE OPERATING QUESTIONWhich exact parts of this request are supported by evidence right now?
01 · THE PROBLEM

“Permission to publish” tells us almost nothing.

If an agent has permission to publish a trailer, does it have permission to publish an unreleased version? In a territory where the rights window has not opened? Using a performer’s digital voice for a use they never approved? With $25,000 of autonomous ad spend?

As AI moves from answering questions to taking actions, one natural-language instruction can cross editorial approval, territorial rights, embargo timing, likeness consent, provenance, and delegated budget boundaries at once.

“Launch the Eclipse Protocol trailer worldwide tonight. Localize it for France and Spain using Ava’s voice, then maximize paid reach.”
01 Asset identity02 Territory03 Timing 04 Digital voice05 Spend authority06 Provenance
02 · THE APPROACH

Separate understanding from authorization.

A

Gemini interprets

Gemini 2.5 Flash on Vertex AI decomposes a producer’s natural-language request into typed consequential actions and material arguments.

Provenance is attached to each argument: explicit, contextual, inferred, defaulted, or unknown.
B

Evidence decides

A deterministic Greenlight Engine compares the proposed consequences with the fixed Eclipse evidence pack. Gemini does not choose ALLOW, REVIEW, BLOCK, or UNKNOWN.

Missing proof is visible. UNKNOWN is never approval.
C

Execution stays bounded

ActionSlate extracts the evidence-supported subset instead of turning a compound request into a blanket no.

For this prototype, all external actions are simulated.
03 · SECURITY BY DESIGN

Least agency is the feature.

Prompt injection

Only the canonical Eclipse command is accepted. It is validated before the Gemini client is constructed, passed as JSON data beneath a separate system instruction, and automatic function calling is disabled.

Improper output

Model responses use typed Pydantic validation with bounded actions, values, lists, provenance, and a single retry for invalid structured output. Dynamic content is escaped before rendering.

Excessive agency

The model cannot read or alter evidence, select policy outcomes, or call tools. Deterministic Python owns the Greenlight decision and safe-plan fixture.

Execution integrity

A successful assurance run issues a five-minute HMAC-SHA256 capability bound to the safe plan. Forged, expired, or wrong-plan capabilities are rejected.

Availability and cost

Requests are rate-limited per client and process, concurrent Gemini calls are capped, provider and server timeouts are bounded, and API responses are never cached.

Honest boundaries

No accounts, uploads, prompt retention, durable audit store, real publishing adapter, voice generation, ad buying, or distributed rate-limit layer exists in this demonstration.

04 · WHAT THE DEMO PROVES

Useful restraint, not a generic denial.

SAFE TO STAGEV12 approved master
US + Canada
$5,000 campaign envelope
HELD FOR PROOFV13 internal review
Global distribution
France + Spain
Ava voice use
Unsupported derivatives
FINAL GUARANTEECapability-gated
simulation-only
Greenlight Receipt
BUILT FOR THE GOOGLE CLOUD AGENTIC CINEMA HACKATHON

A focused control-boundary demonstration for consequential media agents.

ActionSlate was built in the Replit partner track using Google Cloud Vertex AI, Gemini, and Replit-managed secrets and hosting.

AUTHORSubodh KCAI Security Architectsubodhkc.com ↗