Organizational Sovereignty Standard (OrgSov)

v0.2 draft · checkable requirements for organizations that let AI agents act and produce knowledge

The canonical text, its signed tags and its history live at github.com/ankayma/orgsov-standard. To challenge a clause, open an issue — each one closed with a reason is a recorded round of co-audit.

Checkable requirements for organizations that let AI agents act and produce knowledge.

Status: draft for the author's review, 10 October 2026. Supersedes v0.1 draft (27 September 2026). Not yet co-audited (see §11).
License: text of this standard under CC BY 4.0; conformance suites and reference implementations under Apache-2.0. The names and the mark "Sovereign Organization" are not licensed (D1.5). See LICENSE.
Author: Bao Trinh (Ankayma, UAE). Public thesis: https://baotrinh.com — risk branch /risk/, speed branch /speed/.

Marks used in this document:

Abbreviations are introduced once, in §2, and each Part repeats the full term at first use. The standard restates, in normative form, what the source specifications already say (Appendix A). Where the two differ, the source specification governs until v1.0.


Overview for the board

An organization is sovereign over its AI agents when it decides what they may reach and what they may treat as true, and can prove both to a third party.

Agents now open connections, run tools and write into company records at machine speed. The question a board has to answer is not whether an agent will make a mistake, but who answers when it does, and whether the record of what happened survives the people who made it. This standard puts two checkable conditions on every agent system:

Both conditions share one invariant: every change of state — a path opened, a claim accepted — has a named, authorized cause, recorded where it cannot be edited, and checked continuously by a machine that can only raise a flag. The agent proposes. A human with something to lose signs. A third party reads the record without asking the operator for help.

An organization that meets both conditions can let any agent, from any vendor, work at full speed in the zones where mistakes can be undone, and can show an auditor, a regulator or an insurer exactly what the agent reached, what it believed, and who stood behind each.

The standard says what must hold. It does not say how to build it, which vendor to use, or which model to run.


1. Scope and place among existing standards

1.1 What this standard governs

Two objects: paths (who can reach what, through the organization's access layer) and claims (what is treated as true in the organization's knowledge ledger). A third object, effects (what an agent does once it has a path), is governed by Part B, which restates the Cause-Justified Change Monitoring invariant.

1.2 What it is not

It is not a management-system standard. ISO/IEC 42001 defines how an organization runs an AI management system — context, leadership, planning, support, operation, evaluation, improvement — and supplies a control set in its Annex A; NIST AI RMF organizes risk work into Govern, Map, Measure, Manage. OrgSov sits one level down: it is a set of control requirements with mandatory evidence, the layer at which ISO/IEC 27001 Annex A controls or SOC 2 trust criteria operate. An organization running ISO 42001 or NIST AI RMF selects OrgSov as the technical control set for its agent systems; OrgSov does not replace the management system.

1.3 Where it lands in the familiar frameworks

FrameworkWhere OrgSov attaches
ISO/IEC 42001:2023Clause 8 (operation) and Annex A: AI system life cycle (A.6), use of AI systems (A.9), third-party relationships (A.10). Evidence records in Part D feed the Statement of Applicability.
ISO/IEC 27001:2022 Annex AAccess control (A.5.15, A.5.18), privileged access (A.8.2), logging (A.8.15), monitoring (A.8.16). Part A is a stricter form of these for the agent access layer.
NIST AI RMF 1.0GOVERN 2.1 (roles, responsibilities and lines of communication documented), MAP 3.5 (human oversight defined, assessed and documented), MANAGE 2.3 (response to newly identified risks). Part A and Part C supply the records; Part D supplies the measures.
IIA Three Lines ModelLine 1: zone owners and signers (management, owns the risk). Line 2: the continuous machine check and the risk function (reads flags, owns no record). Line 3: the independent reader (internal audit). External audit reads Part D without the operator's help.

1.4 Who answers for what

Role in this standardLineAnswers for
Approver (Part A), Signer (Part C)Line 1every path they opened, every claim they signed; their name falls with it
Zone ownerLine 1the ceiling of the zone and the declared scope (A6)
Continuous checkLine 2flags raised on every write; changes no status
Independent readerLine 3reads the ledgers and the conformance evidence; names the gaps
Operator of the access layer or ledger—runs the system; MUST NOT be able to edit either ledger

2. Terms

TermMeaning in this standardSource
access layerthe overlay through which Part A governs reachability; connections outside it are the organization's declared risk (A6)Ankayma page
nodethe endpoint of the access layer on one device or service; accepts a connection only under a current grant that names it as one of the two endsAnkayma page
patha connection between exactly two nodes, alive for the life of one grantAnkayma page
zonea named set of nodes sharing one purpose and one ceiling; membership in a zone creates no pathessay Risk 6; Ankayma page
ceilingthe maximum loss if an entire zone is lost, stated before any grant in itessay Risk 2
grantan approval naming a requester, an approver, two nodes, a scope, a purpose, a validity window and an expiryCJCM; Ankayma page
effecta change in the world caused by an actor: tool call, write, transferCJCM
irreversible effectan effect whose loss cannot be restored with the capital and time availableessay Risk 2
causean approval or standing grant that authorizes a class of effects, recorded independently of the actorCJCM
actor / producerthe identity that performs an effect or produces a claim; may be an agentT-ledger; TK spec
approverthe human whose hardware-bound approval stands behind a grant; never an agentAnkayma page
signerthe human whose name stands behind a claim; never an agentTK spec
claima statement proposed for the knowledge ledgerTK spec
principlean axiom of the ledger owner; has no basis, because it is the basis. Abbreviated P after this table.TK spec, P.9
trusted claima claim that passed admission: a fact with a citable dated source, or a derivation from standing principles and trusted claims. Abbreviated T.TK spec
assumptiona claim held open, with a declared exit. Abbreviated A.TK spec
basisthe source or the premises a trusted claim rests onTK spec
ledgeran append-only record; the access ledger holds grants and path events, the knowledge ledger holds claims with marks, basis, signer, producer and historyAnkayma page; TK spec
movea named, reasoned change of a record's status by a human: promote, demote, retire, recheck, approve, reject, refer, revokeT-ledger §5
flagwork for a human raised by the machine; changes no statusT-ledger §5.3

2b. Invariants

Every clause in Parts A, B and C derives from one of the seven statements below. A conforming implementation keeps all seven true at all times; the test suites in Part D check them. Invariants are referred to by their name, not by a number.

Common.

Cause. Every change of state has a named, authorized cause, recorded where it cannot be edited, and checked continuously off the write path by a machine that can only raise a flag. In Part A the state is reachable; in Part B it is changed; in Part C it is treated as true.

Access — isolated · granted · evidenced.

Isolated. No standing path. A node holds no map. One node compromised is one grant, two nodes, one expiry.

Granted. No path without a grant. No grant without a human bound to hardware who is not the requester. Every grant names two nodes, a scope and an expiry that ends it on its own.

Evidenced. Every grant, opening, closing and refusal is appended. Nothing is deleted. A party other than the operator reads it.

Knowledge — truth · trust · traceable.

Truth. A trusted claim is a fact with a dated source, or a derivation that rebuilds from principles and trusted claims that still stand.

Trust. Exactly one human signs each claim. An agent never signs. The signer's name falls with the claim.

Traceable. Every trusted claim walks back to its basis. Nothing is deleted. When a premise falls, every claim that stood on it reads as fallen. Status is computed from history, never stored.

Part B carries no invariant of its own: it is Cause applied to effects, with the cause channel as the record.


3. Part A — Access (access sovereignty)

Definition. Access sovereignty is the standing work of keeping every path in the access layer at all three: isolated, granted, evidenced. A path exists only for a grant a human made and a ledger holds. The organization is the root of every grant. Nobody alone — an agent, a compromised node or an insider — can create a path or erase its record.

Invariants. Isolated, Granted, Evidenced (§2b). Each section below names the invariant it enforces.

Threat model (informative). Part A is tested against three adversaries: an agent acting against instruction (injection, self-expansion); an attacker who holds an internal node and its keys; an insider with a valid identity and a motive. For each, the suite in D2 checks that no path opens without A2 and that every attempt appears in A4.

A1. Isolated — nodes and zones [runs: Ankayma]

A2. Granted — a human behind every grant [runs: Ankayma, single approver; planned: k-of-n]

A3. Granted — bounded life [runs: Ankayma]

A4. Evidenced — the access ledger [runs: Ankayma]

A5. Evidenced — continuous check [planned: continuous checker over the access ledger]

A6. Declared scope [planned: as a record]


4. Part B — Effects

Part B restates the Cause-Justified Change Monitoring (CJCM) invariant: every effect has a cause. Access (Part A) answers who opened a path and for how long; Part B answers what was done through it, and whether a cause stood behind it. Clauses are carried from v0.1 A2–A4, A7, A8 without change of substance.

B1. Reversibility decides the gate

B2. Cause channel [runs: CJCM]

B3. The invariant: every effect has a cause [runs: CJCM]

B4. Roll-up: appointment is an effect with a price [planned]

B5. Evidence [runs: CJCM report]


5. Part C — Knowledge (knowledge sovereignty)

Definition. Knowledge sovereignty is the standing work of keeping every trusted claim in the ledger at all three: truth, trust, traceable. A claim counts as knowledge only with a path back and a human name. The organization can withdraw any claim, and the withdrawal reaches everything that stood on it.

Invariants. Truth, Trust, Traceable (§2b). Each section below names the invariant it enforces.

Clauses are carried from v0.1 B1–B11, regrouped under the three invariants and one enforcement section.

C1. Truth — three classes and admission [runs: TK]

C2. Trust — a human name on every record and every move [runs: TK]

C3. Traceable — immutability, history, cascade [runs: TK]

C4. Traceable — hierarchy of ledgers [planned: multi-level; runs: single ledger]

C5. Enforced at machine speed — continuous check [runs: TK (gates); planned: continuous checker over the knowledge ledger]


6. Part D — Conformance

D1. Levels of claim

D2. Test suites [runs: Part B, Part C; planned: Part A suite as a published set]

D3. Organizational evidence record [planned as a form; the conditions are public]

An organization claims adoption by producing, per deployment, a record with:

  1. The declared scope per zone (A6): which resources are reachable only through the access layer.
  2. The four insurability conditions and whether each holds: loss has a ceiling; ceiling stated in advance; grants tamper-proof and third-party monitored; independently audited and tested in reality.
  3. Before/after measures:
    • agent freedom: number of agent types operating lawfully inside zones; agents that passed D2 against this deployment;
    • capability used: share of effects in reversible zones that run without a human in the loop; request-to-result time;
    • risk under control: paths opened without a grant (must be 0); irreversible effects run without a cause (must be 0); incidents exceeding a zone ceiling (must be 0); claims entering the knowledge ledger without basis (must be 0).
  4. The names of the signer and of the independent reader.

A record with measures is a trusted claim; a record without is an assumption.


7. Reference implementations (what runs today)

PartImplementationRunsNot yet
AAnkayma (ankayma.com), reference deployment of the access layerblind private mesh (WireGuard, zero trust), hardware-bound human approval, tamper-proof third-party-monitored grants, path proof ("vendor in path: no")ceiling as a recorded field (A1.2); k-of-n (A2.4); continuous checker (A5); scope declaration as a record (A6); refusal records in the ledger (A4.1) — to be confirmed by the author
BCause-Justified Change Monitoring (CJCM), github.com/baotnq/cause-justified-change-monitoring, Apache-2.0cause channel, V(w) exact set difference, off-path, deterministic, fixed test set, alerts schema and JSONL exporton-path admission; roll-up (B4)
BRealtime settlement audit on a public venue record (Kalshi; 15.3M settled markets)invariant applied to a public ledger, anomaly classes recorded, forward-only dispute trailevent-level metrics; second venue
CT-knowledge system (t-knowledge-system), Apache-2.026 operations including assume/admit/promote/demote/retire/recheck, entry/chain/open_items/ledger, gates USE_PROMOTE, PREMISE_NOT_T, SIGNER_IS_AGENT, RESTATE_TAIL, near-duplicate stop; storage-level immutability; status at readrestates as a write; OAuth; multi-ledger hierarchy and sync (C4); continuous checker over the knowledge ledger (C5)

8. Not specified

Storage engine; transport; mesh technology; API or tool names (MCP or otherwise); UI; number of ledger levels and their names; identifier format; check cadence; catalogue of heuristic anomaly patterns; numeric thresholds, including grant lifetime and k in k-of-n; choice of agent or model; whether the model runs locally or with a provider; which resources an organization places behind the access layer (A6 requires only that the choice is declared). Any of these may differ between conforming implementations.


9. Relationship between the parts

One invariant governs all three: every change of state has a named, authorized cause, recorded where it cannot be edited, checked continuously off the write path. In Part A the state is reachable; in Part B it is changed; in Part C it is treated as true.

A grant in Part A may serve as a cause in Part B for effects within its scope. A trusted claim in Part C may serve as the cause of a decision in Part B. A grant in Part A may be recorded as a trusted claim in Part C. Part A says who may reach; Part B says what was done; Part C says what was believed. Together they let a third party reconstruct any agent action from its path, its cause and its premises.


10. How the standard connects to the thesis

Essay step (public anchor)Clause
Risk 1 — AI control is isolating what cannot be undone (/risk/#wrong-axis)A1 isolated, B1 reversibility
Risk 2 — Undone means the loss can be recovered (/risk/#unit-money)B1
Risk 3 — The AI acts; the human behind it pays (/risk/#framework-runs)A2 granted, B2 cause channel
Risk 4 — When that human cannot pay, it rolls up (/risk/#principal-broke)B4 roll-up
Risk 5 — Controlled means someone will insure it (/risk/#insurance-test)D3 evidence record
Risk 6 — The only new thing is enforcement at agent speed (/risk/#whats-new)A3 bounded life, A5, B3 invariant checked continuously
Risk 7 — Adopting it is a calculation (/risk/#the-choice)D3 before/after measures
Speed 1 — AI enablement is enabling claims you can trust (/speed/#enabling-trust)C1 three classes
Speed 2 — A claim becomes knowledge with truth, trust, traceable (/speed/#three-t)C1, C2, C3
Speed 3 — The AI proposes the truth; a human signs the trust (/speed/#propose-and-sign)C2
Speed 4 — The more names sign a claim, the more it enables (/speed/#trust-compounds)C4 hierarchy
Speed 5 — Sovereignty means demoting what no longer holds (/speed/#demote)C2.5, C3.5
Speed 6 — The new thing is knowledge at machine speed (/speed/#machine-speed)C5
Speed 7 — T-knowledge is the cause behind every decision (/speed/#cause-of-decisions)B2.5

One principle underlies all three parts: the agent is an owner with zero capital. Nothing an agent produces — a path, an action or a claim — passes a gate until a human with real capital (money in Parts A and B, reputation in Part C) puts that capital behind it.


11. Known limits (declared, not hidden)


Appendix A — Source documents (normative until v1.0)

Appendix B — External standards referenced (informative)

Appendix C — Changelog

Kept in CHANGELOG.md.