Glemad

    GLEMAD SAFETY · RUNTIME AUTHORITY

    Action begins with authority, not confidence.

    The Safe Autonomy Framework defines when an Ollandi control may observe, recommend, or act. Authority is explicit, scoped to an environment, revocable at runtime, and constrained by consequence, reversibility, policy, and evidence.

    AUTHORITY ENVELOPEREVOCABLE
    DEFEND
    ASSIST
    OBSERVE
    AUTHORITY IS GRANTEDNEVER INFERRED
    FRAMEWORK POSITION

    Capability describes what a system can do. Authority defines what it is permitted to do now.

    THE THREE OLLANDI CONTROLS

    One operating model. Three distinct levels of authority.

    01

    Observe & Notify

    No authority to change the environment

    Ollandi interprets live infrastructure state, connects evidence across domains, and notifies the responsible operator. The control can explain what it sees and why the event matters, but it does not alter the environment.

    Decision record
    Observed state, supporting evidence, incident interpretation, notification
    02

    Assisted Response

    An operator retains decision authority

    Ollandi prepares a bounded response, shows expected consequence and rollback conditions, and routes the decision to an authorized operator. Approval, refusal, and any amended scope become part of the record.

    Decision record
    Proposed response, impact assessment, policy check, operator decision
    03

    Controlled Autonomous Defense

    Only pre-authorized, policy-bounded action

    Ollandi may execute a response only when an institution has granted authority for the named environment, condition, and action. Runtime policy must still permit it. That authority remains visible and can be withdrawn.

    Decision record
    Authority grant, gate result, action, outcome, rollback state

    THE ACTION GATE

    Permission is tested at the moment of action.

    A prior approval does not remove the runtime check. The current environment, evidence, policy, consequence, and authority state must still agree.

    01

    Policy

    The proposed action falls inside an explicit rule that is active for this environment.

    02

    Evidence

    The conclusion remains attached to the observations that support it, including unresolved conflict.

    03

    Consequence

    The affected services, dependencies, blast radius, and likely operational cost are understood.

    04

    Reversibility

    The response has a defined rollback path, or its irreversible consequence has been separately authorized.

    05

    Authority

    A named institutional owner granted the scope, and that grant remains active at decision time.

    06

    Uncertainty

    Ambiguity, missing context, or conflicting evidence has not crossed the escalation threshold.

    NON-NEGOTIABLE RULE

    Confidence can inform review. It cannot create authority, replace policy, or justify an action on its own.

    WHEN A BOUNDARY IS REACHED

    Block first. Then escalate with evidence.

    1. 01

      Block

      Do not execute an action that falls outside any gate condition.

    2. 02

      Preserve

      Keep the evidence, policy result, and authority state that caused the block.

    3. 03

      Explain

      Show the operator what is unresolved and what consequence requires a decision.

    4. 04

      Escalate

      Return authority to the named human role with a bounded set of response options.

    REVOCATION

    Authority must be removable without redesigning the system.

    An institution can narrow or withdraw an authority grant when policy changes, operating conditions deteriorate, or observed behavior departs from the approved boundary.

    Revocation returns the control to a lower authority layer. The transition and its reason remain part of the evidence record.

    ASSURANCE BEFORE AUTHORITY

    Test the boundary before placing it in production.

    Model evaluation and red teaming examine whether reasoning, escalation, and refusal behavior remain inside the intended authority envelope under pressure.

    Read model evaluation and red teaming