The Permission Plane

Digital permission is not enough for physical consequence.

Your building already decides who may enter, and which floors they reach. Robots arrive on a different rail, a vendor API scoped to a building, not to a mission, a tenant, or a floor. QuikSync resolves accountable authority against the live operation, weighing tenant identity, eligibility, shared-resource allocation, and, where the stakes require it, a person's recorded approval.

Every physical action crosses the permission plane.

The authority path

  1. Resolve

    Who is acting, what they want, and the world they are acting in.

    1. Identity

      Identity establishes who or what is acting.

    2. Intent

      Intent makes the requested outcome explicit.

    3. World context

      The ontology resolves the place, the machine, the people, and what each is doing right now.

  2. Plan

    The outcome becomes bounded work, matched to real resources.

    1. Workflow

      Declared logic turns the outcome into bounded work, conditions, and hand-offs.

    2. Resource allocation

      Live context matches work to eligible people, machines, and shared resources.

  3. Authorize

    Policy, eligibility, and a person where the stakes require it.

    1. Authority

      Policy and eligibility bound the work, and what matters most holds for a named, recorded operator.

    2. Current-state re-check

      Supervisor actions

      On supervisor actions, activation policy is revalidated before dispatch, and a version-fenced effect refuses to apply if its target changed underneath the decision. Machine safety remains with each validated safety system.

  4. Act

    The command crosses into the physical world, and the account outlives it.

    1. Physical effect

      Validated connectors carry the bounded command into the machine and building systems the estate already runs.

    2. Evidence

      Evidence preserves a reviewable account of the outcome.

The authority path, as we are building it. Steps marked with a scope apply to that class of action today.

  • The Permission Plane at work

    An approval that no longer fits the world is refused.

    One decision joins the job to the policy that governs it.

    A pallet is crossing to the eighth floor when a command inside the job stalls. An operator approves a bounded recovery, scoped to that command and that target, under the floor-access policy in force at the time. Before it acts, QuikSync revalidates what the approval depended on. The tenant has since revised who may reach that floor, so the recovery is refused, the operator is shown the condition that changed, and the incident escalates rather than closing quietly.

    • The refusal lands in the Permission Trace with every other decision
    • The job holds while a person decides
    • The same check applies whoever approved it, person or agent
  • Identity, tenancy, and world context

    Know who is acting—and inside which operational world.

    Resolve authority against the current actor, place, and state.

    Human and machine access is scoped through deployment identity and tenant context, while the ontology resolves the place, the asset, and its live state.

    • Deployment identity, not a shared API key
    • One identity model for people and agents
    • Resolved against live state, not a cached role
  • Resource allocation and validated deployment

    Constrain action to eligible, deployment-validated systems.

    Match work only to people, machines, and shared resources.

    The platform allocates work only to the people, machines and shared infrastructure a deployment has deliberately enabled.

    • Eligibility is data, not a code branch
    • Capacity- and priority-aware allocation
    • A new vendor joins without a fork
  • Human authority and current-state check

    Put a person in the path of anything that matters.

    Escalate ambiguity; re-read the playbook at dispatch.

    Ambiguous and recovery actions can escalate with context to an accountable operator. Auto-matched actions, and any action configured to require it, hold for that approval; activation policy is revalidated before dispatch, and a version-fenced effect refuses to apply if its target changed underneath the decision. Machine-level collision safety remains with each validated safety system.

    • Approval holds the action, not a notification
    • A decision that went stale does not apply
    • Collision safety stays with the machine
  • Illustrative Incident Room console: one incident's evidence, chronology, and decision state on a single spine.Illustrative Incident Room console: one incident's evidence, chronology, and decision state on a single spine.
    Illustrative product concept. Interfaces and data are representative.

    Permission Trace and evidence

    Keep a chain of custody for the operation.

    Follow intent through authority, effect, exception, and outcome.

    Every decision, command and effect keeps the governed path available to inspect and replay, whether the reader is an incident reviewer, a board, or a regulator.

    • Correlated across services, not one log per system
    • Replayable, not merely searchable
    • Exportable for an audit you did not schedule
  • Enterprise assurance

    Keep tenant, data, and safety responsibilities explicit.

    Govern shared work without blurring enterprise boundaries.

    Hard tenant isolation scopes each organization. Customer operational data stays inside its configured tenant and deployment boundaries. Machine controllers and safety systems retain their functional-safety responsibilities while QuikSync governs cross-system work, authority, and evidence.

    • Hard tenant isolation
    • Explicit deployment and data boundaries
    • Machine safety remains with each safety system

Put authority before consequence

Design the path from software intent to accountable Physical AI execution.