Identity, guardrails, execution authority: three boxes, not two.
The identity vendors, the guardrail vendors and the card-standards body are all rediscovering the same question — was this specific action authorised, with proof — from three directions. Why that is a third box, why the first two are inputs to it rather than rivals, and how you can check the claim without trusting us.
In the first week of September 2026 three groups who do not usually agree on anything published the same problem. The card-standards body, EMVCo, put a draft framework for card-based agentic payments out for comment; its central construct, Intent Services, exists to register and manage what a consumer authorised an agent to do, before, during and after a transaction — with recurring purchases and cumulative budgets as the named hard cases (EMVCo — how EMVCo is working to enable card-based agentic payments, 1 Sep 2026). An identity vendor, WorkOS, argued that agents need identity, authorization and audit in the same place, so that “which agent did this, on whose authority” has an answer (WorkOS — Agents need identity, authorization, and audit in the same place, retrieved 6 Sep 2026). And a security vendor, Check Point, describes its Lakera work as moving “from access control to outcome control” (Lakera (Check Point) — From access control to outcome control, retrieved 6 Sep 2026).
Read them side by side and they are one sentence: a valid credential is no longer enough, because the thing holding it can act. The agent had a real token and bought the wrong thing. The card was genuine and the purchase was outside what the consumer meant. The access check passed and the outcome was still wrong. Each group is describing the gap from inside its own box, and each is reaching for a mechanism it does not have.
Why it is a third box
Most evaluations I sit in start with two categories. Identity answers who is acting and what it may reach. Guardrails answer whether what a model says is safe. Both are necessary, and both are done well by people who have spent years on them. Neither asks the question that an autonomous action forces: may this exact action execute, now, under whose approval — and can that be shown afterwards?
That is a different question, with a different unit of control. Identity decides in advance, per principal. Guardrails decide in real time, per prompt or response. The third box decides at the moment of execution, per action, against the organisation’s own policy — and it treats the other two as inputs. It reads the principal and its delegation from the identity layer. It reads a guardrail’s verdict as a fact. Identity and guardrails are inputs to authority, not rivals to it. Decionis sits above your identity layer and beside your guardrails — not instead of either.
Drawing the map explicitly does something useful for everyone in the conversation: it turns the vendors in the first two boxes into complements. Nobody is asked to rip anything out. The map is the same one that sits on the category page and above every named comparison on this site, rendered from one registry, so the note and the site cannot disagree:
The map
Identity proves who. Guardrails judge content. Authority decides the action.
Three questions, in the order a buyer meets them. 2 of the boxes are necessary and not sufficient; the third is the one an autonomous action forces.
Necessary. Not sufficient.
Identity and access
Who is acting, and what may it reach?
What it answers
Authenticates the person or the agent, issues and rotates its credentials, and decides what it may reach in general — roles, scopes, tokens, and the delegation chain from a human to the agent acting for them.
What it cannot answer
Whether the action in front of it should happen. A correctly logged-in agent with the right role can still stack discounts below cost, and a valid token can still spend past the budget it was granted under.
What it hands to Decionis
The principal, its delegation and its scopes — the inputs the authority check reads, from the identity layer you already run. Nothing here is replaced.
Is this input or output unsafe, hostile, or out of policy?
What it answers
Filters prompts and responses, detects injection, leakage and anomalous behaviour, and scores the risk of what a model is about to say or has just said — inside the AI layer, in real time.
What it cannot answer
Whether the resulting action may execute, or who approved it. An agent can reach the same tool from outside the guardrail, and a perfectly clean output can still be a purchase nobody authorised.
What it hands to Decionis
Risk and intent signals, as evidence inside the evaluation. A guardrail verdict is a fact the policy reads; it is not the decision, and it leaves no record a counterparty can check.
Examples: Guardrails AI · Check Point (Lakera) · F5 AI Guardrails · Amazon Bedrock Guardrails · NVIDIA NeMo Guardrails
May this exact action execute, now, under whose approval — and can that be proven afterwards?
What it answers
Evaluates the proposed action against the organisation's own policy before it commits, holds it for a named person when the rules require one, and signs a record of what was permitted that someone who does not run Decionis can re-derive.
What it cannot answer
Who the actor is, or whether a prompt was hostile — it consumes both from the boxes beside it. It is the organisation's instrument for the organisation's policy, not an arbiter between the organisation and its counterparties.
What it hands on
A signed Decision Dossier and an execution grant bound to the exact action — what the downstream system executes, and what an auditor, a bank or a buyer verifies against a published key.
Identity and guardrails are inputs to authority, not rivals to it. Decionis sits above your identity layer and beside your guardrails — not instead of either.
The map folds the seven-layer control stack into three questions. One layer belongs to no box: execution itself — the downstream system’s commit — is what all three exist to govern.
Every adjacent tool is embedded in the stack it evaluates: a gateway watching its own traffic, an identity provider auditing its own tokens. The third box has to stand outside that, and the word has exactly two honest meanings. The policy is evaluated outside the application that proposed the action, so the check survives the failure of the thing it checks. A floor enforced inside the tool that moved the price is gone the moment that tool is what went wrong. The verdict can be re-derived from the dossier by someone who does not run Decionis. A signature proves a record was not altered afterwards; re-derivation proves the answer was the one the policy required.
It does not mean neutral, and it does not mean auditor. We are a paid vendor enforcing our customer’s own policy, and we issue no opinion of our own. The two true readings are strong enough that the false ones are not needed — and the second one is the whole credibility test, because a claim about evidence that cannot be checked is just another claim.
The principle a production system wrote down
The most concrete version of the third box is a default. For a machine-initiated action with unbounded loss — an agent’s tool call, a payment release, a margin gate — an unreachable authority is a refusal, not a pass. Where a present person is transacting with bounded exposure, the default flips so an outage never blocks a sale. Every surface on this site states its row. The point is that the failure direction is chosen, and chosen where a person can read it.
Check it without trusting us
The evidential claim is the one you can test today. A public corpus of signed Decision Dossiers — v0.1.3, Apache-2.0, archived with a DOI (10.5281/zenodo.22312956) — and the open verifier @decionis/verify reproduce every check this site makes, including the negative cases a verifier must refuse. The private key is published on purpose: regenerate the corpus yourself rather than trust fixtures we shipped. The corpus proves the verifier; a production dossier verifies against a live key set, and the technical note walks through both.
What I am asking for
Not that anyone adopt our name for it. That the third box be drawn. If the card-standards body, the identity vendors and the security vendors each keep describing the gap from inside their own box, every buyer will keep being walked from “I thought I needed an identity tool” to “this is a different layer” one conversation at a time. The map costs nothing to draw and it makes every one of those conversations shorter. We are not a member, partner or certified implementer of any of the standards named above; we are one implementer of the third box, and we have published enough that the claim can be checked rather than believed.
The one-page version
The map, the one-sentence answer, the two independence claims and the corpus, on one sheet — to print or to send.