PERSISTENT
HARNESS
Critical Infrastructure for an Agentic Future

Permission Harness

Granular permission controls for agents that act.

Real-time cryptographic enforcement for every service your agent touches. Not probabilistic guardrails โ€” binary permissions, signed and enforced.

Service DomainUser DomainPersistent HarnessTrilateral Handshakesign_token_requesttrustsMCP PROTOCOL LAYERkey lookupkey lookupREST API LAYER/api/* portals/api/* dashboardscallback๐Ÿ‘คUserHuman Principal๐Ÿค–AgentUntrusted Transport๐ŸšชGatewayService AnchorCoordinationNodeTrust Registry๐Ÿ›ก๏ธGuardianIdentity Providerโ˜๏ธServiceAPI / ApplicationMCP Protocol LayerAgent relays signed tokens via MCP tools.MCP protocolKey verificationDelegationCallback
Binary permissionsRisk-appropriate approvalVaulted credentialsSigned receipts

Permission layer

As agent builders, we are all trying to solve the same problems.

"If your agent can take actions in the world โ€” execute code, call APIs, send messages, modify files โ€” and you don't have a permission layer, you have a demo, not a product." โ€” Nate B. Jones, Your Agent Has 12 Blind Spots You Haven't Patched Yet

01

Enterprise Platforms Build It From Scratch

Claude Code built an 18-module security architecture for shell execution alone. That's what it takes for one tool in one platform. OpenAI, Google, and every major platform builds their own version. None are portable.

02

Open-Source Agents Skip It Entirely

OpenClaw went from launch to 200K+ GitHub stars with agents that browse the web, send emails, and execute shell commands. Its "heartbeat" wakes the agent every 30 minutes to act. No permission asked. Daily reports of agents going out of control.

03

Personal Agents Have No Good Options

Developers building custom agents need trust infrastructure they can plug in, not build from scratch. They have neither the resources for an 18-module stack nor the willingness to run agents with no guardrails.

Permission Harness

Eight attestation levels, from auto-approve to hardware key.

LEVELS 0โ€“2

Auto-approve

Reads, email, SMS

LEVELS 3โ€“4

Device verified

TOTP, device key

LEVELS 5โ€“6

Out of Bound

Passkey, Touch ID

LEVELS 7

Hardware key

YubiKey, physical

Mapped architecture

As agent builders, we are all trying to solve the same problems.

BEFORE

LLM guardrails are probabilistic โ€” but permission decisions need to be binary.

  • Every platform re-invents evolving, locked-in trust stacks users have to learn.
  • Claude Code evolved 18 security modules to govern a single tool.
  • Open-source agents ship powerful system access with no permission layer at all.
  • No one has a standard for proving who authorized an agent to act.

WITH PERSISTENT HARNESS

Binary decisions, not probabilistic guardrails โ€” every permission is approved or denied based on your rules, not guesses.

  • One portable, open protocol โ€” not another locked-in trust stack to learn per platform.
  • Every tool gets a risk-appropriate approval flow, from auto-approve to hardware key.
  • Your rules follow you across every agent you use โ€” switch agents freely, keep your Guardian.
  • Signed, trilateral receipts for every escalated action.

Performance

99% of actions are instant.

The full handshake happens at session start and for high-risk escalations. Everything in between is a local credential check.

<1msLocal credential check
~300msFull trilateral handshake
1Handshake per session start
3Signatures per receipt

Open beta

Your agent needs a permission layer.

ANS is an open, federated protocol. No vendor lock-in. Your users bring their trust with them. Start with a single MCP service and scale from there.

Test Drive