Home/Research/Specifications/Deterministic Governance
Canonical Research SpecificationLevel: Architect
Verified: July 2026

Deterministic Governance

30-Second Executive Definition

Deterministic Governance is the architectural practice of enforcing security policies and operational limits through external, hard-coded software gates rather than probabilistic LLM prompts.

Deterministic Governance replaces probabilistic text instructions with hard-coded code execution gates that cannot be bypassed by model hallucination.

Why It Matters:

Probabilistic AI models can never guarantee 100% adherence to natural language instructions. Deterministic Governance guarantees zero unauthorized actions by running policy gates in standard code.

Who Should Care:
CTOs & VPs of EngineeringSecurity EngineersEnterprise Software Architects
Canonical Architecture Flow

Deterministic Control Plane Interception

Step 01LLM Tool Generation
Step 02Deterministic Policy Validator
Step 03Allowlist Evaluation
Step 04API Gateway Dispatch
Infinite Relationship Navigator118-Node Sovereign Knowledge Graph

Multi-Hop Causal Traversal Engine

Explore how concepts dynamically feed into each other across 1-hop, 2-hop, and 3-hop transitive relationships. Click any node to navigate the causal highway.

Current Traversal Path (1 Hops Traveled):
AI GovernanceRichard Ewing Canon (Original Framework)Confidence: 98%
Open Full Specification ↗

Deterministic Governance

Deterministic Governance is the architectural practice of enforcing security policies and operational limits through external, hard-coded software gates rather than probabilistic LLM prompts.

Connected Tool:Exogram Proving Ground[Proving Ground]
Launch ↗
Relationship Filter:
Hop Level 1

Direct Relationships (27)

Hop Level 2

Transitive Neighbors (Connected via Hop 1)

Hop Level 3

Extended Causal Ripple Effects

Academic & Industry Citation Graph
Publications6
Newsletters10
Calculators2
Book Chapters1
Keynotes2
GitHub Repos5
Ecosystem Recursion & Cross-Pollination

Reverse Citations: Implemented & Audited Across Platform

★ Canonical Research Position

Richard Ewing’s Research Thesis

Relying on natural language prompt rules (CLAUDE.md / .cursorrules) for security is security through optimism. Real governance requires deterministic proxy interception.

Genesis & Intellectual Positioning

Why This Specification Exists

1. The Problem

Developers rely on text instruction files (.cursorrules, CLAUDE.md) which models routinely ignore under context rot.

2. Existing Approaches

Adding more rules to the system prompt.

3. The Structural Gap

Prompt instructions compete for context space and fail during reasoning pressure.

4. This Specification

Created an external TypeScript proxy layer enforcing strict JSON schema allowlists.

Operational Realignment

What Changes If You Believe This?

Engineering

Move security checks from system prompts into backend proxy middleware.

Finance & COGS

Prevent un-sanctioned API calls from scaling compute costs.

Product Strategy

Define rigid API parameter boundaries for customer-facing agents.

Security & Audit

Log immutable, audit-ready cryptographic execution traces.

Consensus Propagation Index

Specification Maturity & Ecosystem Spread

Website
Newsletter
Book
Video
Talk -
Framework
Calculator
Research
Case Study
Audience-Specific Executive Guidance

Recommended Action by Role

CTO & VP Engineering

Deploy proxy gates in backend services to intercept tool calls before DB writes.

Recommended Next Step →
Executable Tool[Proving Ground]

Exogram Proving Ground

Test deterministic control gates against real-time agent payloads.

Launch Tool ↗
Freshness & Research Updates

Latest Publications & Research Activity

Built InSeptember 2, 2026

Who’s Actually Responsible for Your AI Agents?

Read Work ↗
BeehiivAugust 28, 2026

Cursor vs Google Antigravity for Production AI Building

Read Work ↗
LinkedInAugust 24, 2026

Most Companies Shouldn’t Be Using Autonomous Coding Agents Yet

Read Work ↗
Answer Engine FAQ Matrix

Frequently Asked Questions

Q:What is Deterministic Governance?

Enforcing security rules via hard-coded backend software rather than LLM prompts.

01 • Origin & GenesisProvenance Record

Canonical Specification Origin

Relying on natural language prompt rules (CLAUDE.md / .cursorrules) for security is security through optimism. Real governance requires deterministic proxy interception.

First IntroducedFebruary 2026 (Built In)
Primary VenueBuilt In
02 • Internal Research Corpusrichardewing.io

Corpus Interconnections

Richard Ewing artifacts developed around this canonical framework, including publications, execution tools, and diagnostic models.

Articles1
Tools1
Specs1
Chapters1
03A • Verified Human External EvidenceAudit Status: Baseline

External Adoption & Peer Citations

Documented instances where independent researchers, engineering teams, and publications have cited, implemented, or referenced this concept outside Richard Ewing’s ecosystem.

External Evidence: No independently verified references recorded yet.

This concept is part of Richard Ewing’s original baseline canon. External citations and implementations are added only upon rigorous empirical verification.

Inspectable Evidence Ledger

Classified evidence items supporting, extending, or refining this canonical research specification.

Evidence ItemPublisherEvidence TypeStrengthRoleAction
Security Gates for AI AgentsBuilt InProduction Telemetry★★★★★OriginInspect ↗
Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?CIO.comTier-1 Media★★★★★ExtendsInspect ↗
I Used AI to Build My Startup. Here’s What I Learned. (Cursor vs. Google Antigravity)Built InIndustry Analysis★★★★★SupportsInspect ↗
How Does Meta’s Muse Code Compare to Other AI Coding Tools?Built InIndustry Analysis★★★★★ExtendsInspect ↗
Cursor vs Google Antigravity for Production AI BuildingBeehiivIndustry Analysis★★★★★ExtendsInspect ↗
Who’s Actually Responsible for Your AI Agents?Built InTier-1 Media★★★★★ExtendsInspect ↗
05 • Downstream Operational RealizationActionable Pathways

Translating Deterministic Governance into Execution

Relying on probabilistic LLM guardrails (system prompts) to validate security boundaries allows prompt injection and unauthorized database mutations. Impact: Catastrophic unauthorized transactions, data leaks, and regulatory compliance failure (EU AI Act & SOX).

[ENGINEERING RUNTIME]IMPLEMENTS
For: Security Architects & Lead Engineers

Deploy Deterministic EAAP Runtime Proxy

Exogram implements the Executable Agent Action Protocol (EAAP), enforcing binary boundary controls in <5ms.

[EXECUTIVE ADVISORY]ADVISES ON
For: CISOs, General Counsel & CTOs

Enterprise AI Governance & Audit Architecture

Retain Richard Ewing to establish board-level AI governance frameworks and deterministic compliance boundaries.

Note: Research specs and evidence ledgers remain independent and factual. Downstream pathways provide verified implementation channels for teams managing this operational problem.

Academic & Industry Attribution Standard

Recommended Citation

Canonical Reference String

Ewing, R. (2026). "Deterministic Governance." Richard Ewing Research Canon. Available at: https://www.richardewing.io/concepts/deterministic-governance

BibTeX Citation
@article{ewing_deterministic_governance,
  author = {Ewing, Richard},
  title = {Deterministic Governance},
  journal = {Richard Ewing Research Canon},
  year = {2026},
  url = {https://www.richardewing.io/concepts/deterministic-governance}
}
First Origin & Provenance:Built In (February 2026)
Current Specification Version:Version 1.0 (Q2 2026 Baseline)