Execution authority protocol

The protocol layer for governed AI execution.

Identity proves who the agent is. Access grants what it can reach. reht™ verifies whether a specific action is right to execute, then writes the receipt.

Built to sit between identity, policy, tools and execution.

IdentityOkta · Entra · WorkOS · OAuth · OIDC · SAML
AccessRoles · scopes · sessions · credentials · tool grants
reht™ Authority BoundaryAction · authority · policy · evidence · risk · decision
ExecutionGitHub · ERP · banking · cloud · MCP tools · internal APIs
ALLOW / STEP_UP / DENY
Receipt written

The missing layer

Identity is not execution authority.

SSO, OAuth, OIDC, SAML, JWT and MCP Auth establish identity and access. They do not decide whether this action, in this state, with this evidence, should be allowed to change the world.

Identity

Who is acting?

User, agent, service account, organization and session context.

Access

What can be reached?

Scopes, roles, credentials, grants and tool permissions.

reht™

Is this action right to execute?

Runtime check of authority, policy, evidence, state and risk.

Receipt

Can the decision be proven?

Every execution handoff leaves an auditable decision record.

Protocol contract

One action envelope. One decision boundary.

01

Action

The proposed operation is made explicit before any tool, API or workflow is invoked.

02

Authority

The represented person, team or organization is bound to the action.

03

Policy

The relevant rules are evaluated at runtime, not assumed from login.

04

Evidence

Source validity, context and missing evidence are checked before action.

05

Decision

ALLOW, MODIFY, DEFER, DENY, STEP_UP or HALT.

06

Receipt

The outcome is written as an auditable execution record.

Mental model

Reasoning may be probabilistic. Execution authority must be governed.

IdentityWho the actor is.
AccessWhat the actor can reach.
AuthorityWhat the actor may do now.
ReceiptWhat decision can be audited later.
reht™ is not an IAM product and not a model wrapper. It is an execution authority boundary for agentic systems.

Network play

Provider-neutral by design.

The same authority packet can govern a pull request, purchase requisition, CRM update, payment instruction, cloud deployment or MCP tool call. Adapters change. The boundary stays the same.

reht™ authority boundary Okta Entra WorkOS MCP GitHub SAP Salesforce ServiceNow Banking ERP AWS Azure Google Cloud Internal APIs
Execution handoff only after a valid decision and receipt path. Everything else is stepped up, modified, deferred, denied or halted.

Positioning

Identity proves who the agent is. reht™ decides what the agent may do.

A light protocol layer for governed AI execution across agents, tools and enterprise systems.

Request access