Exogram Action Admissibility Protocol (EAAP)
An open standard and architectural RFC designed to govern the tool execution boundaries of autonomous AI agents. EAAP defines a strict set of binary admissibility gates that filter and validate proposed agent actions against deterministic allowlists prior to execution. By decoupling the probabilistic reasoning of the LLM from the deterministic execution of the environment, EAAP ensures that agents cannot perform destructive, unauthorized, or financially ruinous actions, even if they hallucinate the intent to do so. This is the foundational protocol powering Exogram's runtime governance.
“Govern the execution, not the imagination. Let the model dream, but strictly regulate what its hands can touch.”
As agents move into Zone 3 and Zone 4 of the AI Liability Gradient, relying on system prompts to enforce safety is structurally insufficient; LLMs can always be jailbroken or confused. EAAP provides a hard, cryptographic boundary at the execution layer. It guarantees that regardless of what the LLM decides to do, the system will only execute mathematically verified, pre-approved actions. This is the only way to safely deploy autonomous agents in high-stakes enterprise environments without exposing the company to infinite liability.
Multi-Hop Causal Traversal Engine
Explore how concepts dynamically feed into each other across 1-hop, 2-hop, and 3-hop transitive relationships. Click any node to navigate the causal highway.
Exogram Action Admissibility Protocol (EAAP)
An open standard and architectural RFC designed to govern the tool execution boundaries of autonomous AI agents. EAAP defines a strict set of binary admissibility gates that filter and validate proposed agent actions against deterministic allowlists prior to execution. By decoupling the probabilistic reasoning of the LLM from the deterministic execution of the environment, EAAP ensures that agents cannot perform destructive, unauthorized, or financially ruinous actions, even if they hallucinate the intent to do so. This is the foundational protocol powering Exogram's runtime governance.
Direct Relationships (5)
Transitive Neighbors (Connected via Hop 1)
Extended Causal Ripple Effects
Richard Ewing’s Research Thesis
Enterprise agent deployment is negligent without a deterministic admissibility protocol intercepting all tool calls.
Why This Specification Exists
System prompts are continually bypassed, leading to dangerous autonomous agent behavior.
Telling the AI "do not do this" in the prompt.
No deterministic execution boundary between the LLM and the real-world environment.
A formal protocol (EAAP) that validates all agent actions against hard rules before execution.
What Changes If You Believe This?
Must build explicit deterministic boundaries around every tool exposed to an agent.
Lowers risk profile of enterprise AI deployments.
Must specify the exact tool parameters needed for a feature to function safely.
Security teams stop auditing prompts and start auditing execution allowlists.
Recommended Action by Role
Deploy cryptographic runtime admissibility gates between AI models and internal databases to prevent unauthorized state mutations.
Decouple probabilistic model reasoning from deterministic API execution so agents only trigger pre-cleared enterprise actions.
Audit agent permission allowlists against regulatory requirements to ensure machines never bypass enterprise access controls.
Implement binary admissibility schemas in proxy middleware before allowing agents to call external third-party tools.
Latest Publications & Research Activity
Salesforce and SAP are putting AI agents inside your workflows. Who tells them no?
Enterprise SaaS providers (Salesforce, SAP, Oracle) are embedding autonomous AI agents directly into transactional workflows with authority to issue refunds, alter contract terms, and spend corporate capital - creating a critical breakdown in corporate signing matrices and shadow delegation that bypasses internal executive approval controls.
Claude Code vs. Gemini Spark: How Do They Compare?
Claude Code won the terminal through active human presence and localized error feedback loops, while Gemini Spark bets on remote background persistence across office apps and external MCP connectors. However, persistence is not authority: extending execution duration without strict write boundaries allows flawed assumptions to silently corrupt shared systems. Because explainability is not recoverability, unmonitored background agents turn operators into forensic auditors, proving that an autonomous agent's true metric is not how long it works without you, but how much authority you give it when you are away.
AI Agents Are Creating New Enterprise Governance Risks
With Gartner predicting 40% of enterprise applications embedding AI agents by end of 2026 and 40% being decommissioned by 2027 due to post-incident governance gaps, organizations face an insidious new failure mode: the transaction that succeeds. While operations dashboards glow green with 240-millisecond response times, automated agents silently violate corporate procurement limits, accounting rules, and customer credit policies. Because monitoring is not authorization, enterprises must separate system health from business permissioning across four pillars (Monitoring, Auditability, Authorization, Accountability) and establish external policy firewalls before autonomous software commits corporate capital.
Things I Got Wrong: A Founder's Post-Mortem on Building AI Products
Examining early AI product failures reveals three operational misconceptions: assuming evaluator models can govern worker models, believing vibe coding replaces software architecture, and building isolated application monoliths. Evaluator models fail identically to worker models under distribution shift because probabilistic systems cannot police probabilistic systems. Real architectural resilience requires non-AI deterministic execution gates, strict system rules, and shared runtime platforms like Exogram that amortize infrastructure overhead.
Frequently Asked Questions
Q:Why not just tell the agent not to do bad things?
LLMs are probabilistic. They do not understand hard boundaries. EAAP acts as a physical wall that the agent cannot pass, regardless of its instructions.
Q:Does EAAP limit agent capability?
It restricts freedom to ensure safety. The agent can only select tools that have been explicitly provisioned and cleared by the EAAP gateway.
Canonical Specification Origin
Enterprise agent deployment is negligent without a deterministic admissibility protocol intercepting all tool calls.
Corpus Interconnections
Richard Ewing artifacts developed around this canonical framework, including publications, execution tools, and diagnostic models.
External Adoption & Peer Citations
Documented instances where independent researchers, engineering teams, and publications have cited, implemented, or referenced this concept outside Richard Ewing’s ecosystem.
External Evidence: No independently verified references recorded yet.
This concept is part of Richard Ewing’s original baseline canon. External citations and implementations are added only upon rigorous empirical verification.
Inspectable Evidence Ledger
Classified evidence items supporting, extending, or refining this canonical research specification.
| Evidence Item | Publisher | Evidence Type | Strength | Role | Action |
|---|---|---|---|---|---|
| Salesforce and SAP Workflow Agents | CIO.com | Tier-1 Article | ★★★★★ | Origin | Inspect ↗ |
| Runtime Governance Architecture | Beehiiv | Newsletter | ★★★★ | Extends | Inspect ↗ |
| Deterministic Control Plane | Beehiiv | Newsletter | ★★★★ | Extends | Inspect ↗ |
| Salesforce and SAP are putting AI agents inside your workflows. Who tells them no? | CIO.com | Executable | ★★★★★ | Supports | Inspect ↗ |
Recommended Citation
Ewing, R. (2026). "Exogram Action Admissibility Protocol (EAAP)." Richard Ewing Research Canon. Available at: https://www.richardewing.io/concepts/eaap-protocol
@article{ewing_eaap_protocol,
author = {Ewing, Richard},
title = {Exogram Action Admissibility Protocol (EAAP)},
journal = {Richard Ewing Research Canon},
year = {2026},
url = {https://www.richardewing.io/concepts/eaap-protocol}
}