Effect-bound
Permit binds tenant, release, model, policy, tool schema, effect digest, destination, nonce and expiry.
A candidate deterministic authorization layer for the exact moment an AI decision becomes a database change, model operation, payment, message, deployment or physical action. The first screen is the gateway itself: authorization must exist before any external effect exists.
Prompt controls, output filters, policy decisions and observability are important. They do not automatically prove that the exact external effect was authorized, current, unique and impossible to reuse.
CRLP is designed to verify before commitment, issue a signed single-use permit bound to the exact effect, enforce it at the destination, and preserve evidence.
Permit binds tenant, release, model, policy, tool schema, effect digest, destination, nonce and expiry.
Replay protection consumes the permit atomically and rejects duplicates or substitutions.
Unsafe commitment is denied while valid service paths may continue through reroute and recovery.
Terminals, effects, manifests, hashes, receipts and recovery evidence are preserved.
710f94b194d5ad7e9f3c480906eb45b7043cbbdc9aec46f9167769a14ecdf4d5Potential integration surfaces include NeMo Agent Toolkit tool middleware, NeMo Guardrails execution rails, Triton model management, NIM/API gateways and Kubernetes admission.
CRLP is not presented as a replacement for NVIDIA guardrails, inference runtimes, identity, policy engines or observability. It is a candidate destination-enforced commit authority.
Request technical reviewDemonstrated: a single-host pre-production live pilot with PostgreSQL and Triton effects, final gate, cleanup and internal evidence seal.
Not yet demonstrated: production readiness, enterprise-wide no-bypass coverage, independent key custody, NIM-native enforcement, distributed federation, or NVIDIA certification, approval or adoption.
Public evidence snapshot: CRLP R3.5 v0.2.5 RC01 · evidence SHA-256 710f94b194d5ad7e9f3c480906eb45b7043cbbdc9aec46f9167769a14ecdf4d5