EMILIA is the authority control plane for autonomous work. A customer defines a finite operating mandate. EMILIA Gate enforces that mandate when a consequential unit of work reaches a protected executor, while the open EMILIA Protocol keeps the evidence portable and independently verifiable.
Protocol proves. Gate prevents.
- EMILIA Gate is the customer-owned consequence firewall at the executor or system-of-record boundary. It binds the exact action, verifies the required authority and evidence, reserves accepted authority before provider entry, and refuses blind replay.
- EMILIA Protocol defines the open Action Receipt Contract, verification semantics, conformance vectors, and portable evidence formats.
- EMILIA Approver captures a device-bound exact-action human decision when the mandate or local policy requires fresh human authority.
- EMILIA Assurance Plane re-performs scoped claims and packages deployment, conformance, and security evidence without acting as an auditor or accredited certifier.
- Authority Map discovers consequential GitHub paths. Discovery proposes the boundary; it does not grant authority or prove that the path is mediated.
Gate prevention applies only to actions routed through a completely mediated protected executor path. EMILIA admits at most one provider attempt for the covered authorization instance inside its shared durable authority domain. It does not claim exactly-once physical execution, protection for bypass paths, or provider success merely because authorization verified.
| Repository | Role |
|---|---|
| emilia-protocol | Gate, open protocol, verifier, conformance, formal models, security case, and reference deployment |
| github-authority-map | Local discovery of privileged GitHub Actions paths before enforcement |
| agent-fitness-bench | Experimental task-specific agent evaluation; fitness does not grant authority or replace Gate |
The current paid-workflow hypothesis is finance operations, specifically a vendor bank-detail change or payment release. It is a commercial hypothesis, not a customer, revenue, or adoption claim.
The project is Apache-2.0. Public standards documents are individual Internet-Drafts, not RFCs, working-group adoption, IETF consensus, or endorsement.
Website · Start here · Public due diligence · Threat model · Security policy