Illustrative reference signals only. Not live settlement or regulated dispatch.
REFERENCE INDEX€8.1425
REFERENCE LATENCY41ms
REFERENCE INDEX€8.1425
REFERENCE LATENCY41ms
Security / Deterministic Safeguards

Deterministic Agent Controls

Security and control-boundary route for G1-G10 safeguards, action-tier limits, telemetry trust downgrade, operator approval, and audit-record requirements.

Trust Controls

Deterministic safeguards are the answer to orchestration overclaim

Use this route to explain what blocks, downgrades, or escalates actions before they become operational recommendations or staged supervised execution.

Abstract security controls visual linking telemetry trust, reserve policy, firmware state, and operator approval.
pilot-readySecurity / Deterministic Safeguards

Deterministic agent controls are framed as bounded trust and control logic, not as cybersecurity certification evidence.

Human/operator gating remains explicit wherever recommendations might affect safety, reserve posture, or shared-asset governance.

Audience

Technical reviewers • Security reviewers • Municipalities

Core Focus

Deterministic Control Safeguards

Best Next Route

Security Overview

Review First

G1-G10 safeguardsAction-tier limitsHuman/operator approval pathTelemetry and firmware trust boundaries

Trust Next Move

Use this route when the question turns from orchestration promise into control limits, operator gating, trust downgrade, or audit requirements.

Jump To Section

G1-G10 Safeguards

Deterministic Control Safeguards

The current safeguard model is designed to constrain orchestration logic with explicit policy, trust, governance, and operator checks.

  • • Public category: Secured Deterministic Grid Orchestration
  • • Technical category: Causal Agentic Orchestration for Cyber-Physical Energy Infrastructure
  • • Procurement phrase: Operator-supervised orchestration agents for storage, telemetry, reserve policy, supplier-risk, and Community Energy Bank operations.

G1-G10 Safeguards

The safeguards below define the minimum downgrade, block, isolate, and record logic for material orchestration recommendations.

  • • G1 - If telemetry trust falls below threshold, orchestration downgrades to observe-only.
  • • G2 - If firmware signature or controller identity fails, the asset is isolated from the orchestration pool.
  • • G3 - If reserve minimum is violated, discharge recommendation is blocked.
  • • G4 - If interconnection or export limits are unknown or exceeded, export-increasing actions are blocked.
  • • G5 - If public-sector procurement or supplier-risk status is unresolved, the system is advisory-only.
  • • G6 - If governance quorum is missing for shared or community assets, allocation updates are blocked.
  • • G7 - If local safety, fire, or AHJ mode is active, dispatch is locked to safe fallback.
  • • G8 - If model confidence is insufficient, the agent may explain but not recommend.
  • • G9 - If human operator authorization is missing, the action cannot advance beyond simulation.
  • • G10 - Every material recommendation must produce an audit record.

Action-Tier Limits

Action tiers keep observe, explain, recommend, and simulate distinct from staged supervised execution or future-only autonomy claims.

  • • T0 Observe: Read telemetry, device state, and market/public signals. Public release: Allowed.
  • • T1 Explain: Generate causal explanation, risk note, and audit summary. Public release: Allowed.
  • • T2 Recommend: Suggest operator action. Public release: Allowed.
  • • T3 Simulate: Run bounded dispatch, reserve, and islanding scenarios. Public release: Allowed.
  • • T4 Supervised Execute: Execute only after policy and operator approval. Public release: Limited / staged.
  • • T5 Deterministic Local Fallback: Pre-approved emergency behavior. Public release: Roadmap / controlled pilots.
  • • T6 Autonomous Market Action: Live market bidding and dispatch. Public release: Disabled / future only.

Human / Operator Approval Path

Material recommendations remain routed through operator review, policy checks, and explicit escalation paths before any staged execution path can advance.

  • • Operator Relay is the control handoff between software guidance and human decision.
  • • Missing authorization keeps actions bounded to simulation or explanation.
  • • This preserves procurement-safe, operator-supervised posture for the current release.

Telemetry Trust Downgrade

Telemetry confidence is treated as a gating signal, not as a silent assumption.

  • • If telemetry trust falls below threshold, orchestration downgrades to observe-only.
  • • Low-confidence telemetry may still support explanation and audit context, but it cannot silently justify stronger action tiers.

Firmware / Device Identity Boundary

Firmware signatures and controller identity determine whether an asset stays in the orchestration pool.

  • • If firmware signature or controller identity fails, the asset is isolated from the orchestration pool.
  • • Firmware Quorum Agent isolates or escalates devices that fail trust-state checks.

Reserve-Policy Block

Reserve rules remain first-class operating constraints for storage-first deployments.

  • • If reserve minimum is violated, discharge recommendation is blocked.
  • • If interconnection or export limits are unknown or exceeded, export-increasing actions are blocked.

Supplier-Risk Advisory Boundary

Supplier-risk and procurement status are treated as gating factors for public-sector and trust-sensitive deployments.

  • • If public-sector procurement or supplier-risk status is unresolved, the system is advisory-only.
  • • Unresolved supplier-risk keeps the system advisory-only rather than quietly permissive.

Governance Quorum Block

Shared-storage actions stay constrained by governance state and policy approval requirements.

  • • If governance quorum is missing for shared or community assets, allocation updates are blocked.
  • • If human operator authorization is missing, the action cannot advance beyond simulation.

Audit Record Requirement

Material recommendations must remain explainable and reviewable after the fact.

  • • Every material recommendation must produce an audit record.
  • • Audit Scribe and Community Ledger Agent keep event trails and governance records aligned.