APP
01 03 04 08
[ACCORD★CONTROL]
Autonomous intelligence spending money
in your immediate vicinity
Motto: mandate · monitor · account
Actions checked
0
Held for a human
0
Blocked
0
Unaccounted
0
Live interceptsall agents
Mandateprocure-07
Spend today
Used of daily cap$3,910 / $5,000
Access
netsuite.purchasingread · write
bank.wiresapproval
hr.* · infra.prod.*deny
Never
credential.createblocked
agent.spawnblocked
Escalation
Approversfinance · 1 of 3
Timeout30m → deny
Recordsigned · 7 yrs
▸LAUNCH APP
MAP: U.S. CENSUS BUREAU STATE OUTLINES
PUBLIC DOMAIN
▶ Read the thesis + Try a mandate Launch app 𝕏 @Accordgovtech
OCT 2026· WASHINGTON, D.C.
LIVE
SECTION 01
[THE RACE]
Five labs are making intelligence autonomous

OpenAI, Google, Meta, xAI and Anthropic are racing to make intelligence autonomous. AI is turning into SI: systems that do not just answer prompts, but browse, code, use tools, reach into systems, spend money and keep working on their own.

Lab 01
San Francisco, CA
OPENAI
Buildingagents
Lab 02
Mountain View, CA
GOOGLE
Buildingagents
Lab 03
Menlo Park, CA
META
Buildingagents
Lab 04
Palo Alto, CA
XAI
Buildingagents
Lab 05
San Francisco, CA
ANTHROPIC
Buildingagents
From AI to SIwhat autonomous intelligence already does
Browsethe open web
Codeand ship it
Use toolsany API, any app
Access systemsprod, data, finance
Spend moneycards, wires, vendors
Keep workingunsupervised
SECTION 02
[THE BOTTLENECK]
When intelligence acts, control is the bottleneck

As intelligence becomes more autonomous, every organization has to answer five questions. Today most answer them with trust. Accord answers each one with a mandate.

Question
01

What can this agent access?

Answer: scopes
Question
02

What can it spend?

Answer: spend limits
Question
03

What actions can it execute?

Answer: action rules
Question
04

When does it need human approval?

Answer: approvals
Question
05

What exactly did it do?

Answer: the record
SECTION 03
[HOW IT WORKS]
Every action is checked before it happens

An agent asks to do something. Accord checks it against the mandate in milliseconds: scope, spend, action. Then it allows it, holds it for a human, or blocks it. Either way, the record is written.

01 · Requestprocure-07
02 · Mandate check0.0 ms
Scope—
Spend—
Action—
03 · Decision
ALLOW
04 · Recordsigned
SECTION 04
[TRY A MANDATE]
You set the rules. Watch the agents obey.

Move the limits. Flip the switches. The stream on the right is a procurement agent's day of requests, evaluated live against the mandate you just wrote.

Your mandateprocure-07
Over-limit goes to a human
Allow new vendors
Allow production writes
Never: credentials, new agents
Live evaluation$0 spent today
Allowed
0
Held for a human
0
Blocked
0
SECTION 05
[THE PRODUCT]
Every agent gets a mandate.
Every action leaves a record.

Not another chatbot. Accord is Cloudflare + Stripe Dashboard + IAM for autonomous intelligence: it sits between your agents and everything they can touch.

Like Cloudflare

In front of every action

Every tool call, payment and system touch passes through Accord first, and is allowed, held or blocked before it runs.

Like Stripe Dashboard

Every dollar accounted for

Per-agent budgets, per-transaction caps, vendor allowlists and a live ledger of what each agent spent, and why.

Like IAM

Permissions by the verb

Read, write and execute rights per system and per dataset. Least privilege for intelligence that never sleeps.

Accord fleet overview console
Fleet overview · every agent, its mandate, its spend and every intercept
Mandate as codeprocure-07.mandate.yaml
Three outcomesnothing in between
Allow

Inside the mandate. It runs, and the record is written.

Hold

Over a limit. A named human approves or denies it, from a laptop or a phone.

Block

Outside the mandate. It never happens, and the attempt is recorded too.

Pause

One switch stops a single agent, a team of agents, or every agent in the company.

Accord approval queue
Approvals · a $18,400 wire held for a human
Accord mandate editor
Mandates · access, spend, actions, escalation
SECTION 06
[HUMAN IN THE LOOP]
Big decisions stay human

When an agent reaches past its mandate, Accord freezes the action and puts it in front of the right person, with everything the agent did to get there.

Accord approval on a phone
Approve from anywhere · Face ID
One held wireREQ-20261001-0418
Agent matches the invoiceprocure-07 runs a 3-way match on PO 88213. Allowed.
Wire requested · $18,400Over the $5,000 per-transaction limit. Accord holds it. Nothing moves.
Routed to financeM. Okafor gets the request on her phone, with the agent's six steps attached.
Approved with Face IDNote to the record: "Bulk order for Q4 line."
Wire released · record signedRequest, decision, approver and note are hash-chained into the audit trail.
Approvals today
Median wait
4m 12s
Decided by humans
212
Timed out · denied
3
If nobody answers30m → auto-deny + notify owner
Above $25,0002 approvers, one from Treasury
Approver channelsphone · Slack · console
SECTION 07
[THE RECORD]
What exactly did it do? Every answer, signed.

Every request, decision and approval becomes an event. Each event carries the hash of the one before it, so nobody, including the agent, can quietly rewrite history.

Audit chain3,820,114 events
Chain verifieded25519 signatures7-year retentionlog.delete: never
Accord audit trail
Audit trail · replay any agent session, export it for an auditor
SECTION 08
[THE ACCORD]
Four layers of controls and audits

The White House Accord on Super Intelligence explicitly calls for internal controls, monitoring, independent evaluation and oversight around frontier systems. Accord productizes that same control philosophy at the agent and action layer.

Internal controls to monitor models. An internal team to keep those controls operating. An independent external evaluator. A board committee that oversees them all. The four layers, summarized · Full text via Washington Examiner
The announcement@WhiteHouse · 30 Sep 2026
View the post on X ▸
Layer 01

Internal controls

Mandates enforced on every action. Agents cannot reach systems in ways they were never granted.

Accord: enforced
Layer 02

Internal control team

A console for the people who keep controls working: control tests, alerts and remediation.

Accord: operating
Layer 03

Independent evaluator

A read-only workspace for outside auditors, with signed exports and replay of any agent session.

Accord: read-only seat
Layer 04

Board committee

A quarterly oversight packet generated from the record, so directors see what agents did.

Accord: quarterly packet
Accord oversight view mapped to the four layers
Oversight · each layer produces its own evidence
SECTION 09
[THE STACK]
From the mandate to every layer of the AI economy

The White House sets the mandate. ACCORD is the coordination and intelligence layer that turns it into live controls across compute, models, cloud, cyber and government. Truth Signal feeds new policy back in as it happens.

The mandate
WHITE HOUSE SI MANDATE
Accord on Super Intelligence · four layers of controls and audits
Coordination · intelligence layer
ACCORD
Translating policy into mandates, monitors, audits and oversight
Compute

Compute

Training runs and inference capacity registered against the mandate before they start.

Clusters under mandate0
Models

Models

Every frontier model version, its evaluations and any capability change before deployment.

Versions tracked0
Cloud

Cloud

Agent runtimes, tenancy and network boundaries, enforced where the agents actually run.

Runtimes enforced0
Cyber

Cyber

Controls around cybersecurity, threat monitoring and incident reporting, as the Accord asks.

Controls active0
Government

Government

Board reports, independent audits and regulator-ready evidence, if the steps become law.

Reports filed0
TRUTH SIGNALLive policy and intelligence feed · via Truth API0 signals
SECTION 10
[WHO IT'S FOR]
Everyone who signs off on what agents do
The CFO
CAPITAL

Knows every dollar

  • Budgets per agent and per team
  • Caps per transaction
  • Vendor allowlists
  • A live spend ledger
The CISO
PERMISSION

Owns every scope

  • Least-privilege access
  • Egress and prod guards
  • Prompt-injection screens
  • A kill switch
The board
OVERSIGHT

Sees what happened

  • Quarterly packets
  • Incident escalations
  • Independent evaluator seat
  • Accord-mapped evidence
The builders
ACCOUNTABILITY

Ship agents faster

  • Mandates as code
  • Simulate against real history
  • Any model, any runtime
  • Approvals without a meeting
SECTION 11
[SECURITY ARCHITECTURE]
Defense in depth for autonomous intelligence

Accord is built on zero-trust principles. No agent is trusted by default, no agent holds standing credentials, and no action runs without passing six independent layers.

The stackoutside in
L1Agent identityshort-lived workload identity · mTLS
L2Isolationsandboxed runtime per agent
L3Egress controlper-agent network allowlist
L4Secrets brokerscoped, expiring tokens only
L5Signed mandatesversioned · two-person publish
L6Evidencehash-chained · externally anchored
Zero trust

Identity for every agent

Each agent gets its own cryptographic identity that expires in minutes. Every call is mutually authenticated.

No standing secrets

Agents never hold keys

A broker issues narrow, short-lived tokens per action. Nothing long-lived ever reaches the model's context.

Least privilege

Default deny

Anything not granted in the mandate is blocked, and every grant is scoped to a system, a verb and a limit.

Change control

Two keys to publish

Mandate changes are signed, diffed, simulated against history and need a second approver before they go live.

SECTION 12
[THREAT COVERAGE]
Every known agent risk, covered in layers

No single control is enough. Each risk is met by at least two of the four Accord layers, so a failure in one is caught by the next.

Coverage matrixthreat × layer · swipe →
Threat01 Control02 Monitor03 Audit04 Oversight
Prompt injectionScreenDetectReview
Tool misuseBlockDetectReviewRevoke
Data leakageEgressDetectReviewPause
Privilege escalationDenyAlertVerifyApprove
Unvetted MCP serversRegistryVerifyReview
Runaway spendCapsAlertApprove
Model drift after upgradeDetectRe-testRoll back
Log tamperingVerifyAnchorEscalate
SECTION 13
[BUILT FOR THE SOC]
Agent events, in the tools your team already runs

Every Accord decision streams out as a structured security event, so your security operations center sees agents the same way it sees people and servers.

Event streamaccord.events · json
SIEM
SplunkDatadogElasticSentinel
Identity
OktaEntra IDSAML SSOSCIM
Telemetry + alerting
OpenTelemetryPagerDutySlackWebhooks
Data protection
In transitTLS 1.3 · mTLS
At restAES-256 · per-tenant keys
Key custodyHSM-backed · rotated
ResidencyUS regions by default
SECTION 14
[FRAMEWORKS]
One record, many auditors

Accord's evidence is organized against the frameworks your auditors already use, so one control produces proof for all of them.

Framework

White House Accord

4 layers
Framework

NIST AI RMF

Govern · Map · Measure · Manage
Standard

ISO/IEC 42001

AI management system
Guidance

OWASP LLM Top 10

application risks
Attestation

SOC 2

security · availability

Mappings show where Accord evidence supports each framework. They are not certifications.

SECTION 15
[ANY MODEL. ANY SYSTEM.]

Accord sits at the action layer, so it does not care which model is thinking. It governs what the agent touches.

SECTION 16
[QUESTIONS]

No. Accord does not think for your agents. It sits between them and your systems, and decides what each one is allowed to do, spend and touch.

A short, versioned file per agent: which systems it can read or write, how much it can spend, which actions need a human, and which are never allowed. You can simulate a new version against past activity before you publish it.

The Accord calls for internal controls, monitoring, independent evaluation and oversight around frontier systems. Accord puts that same four-layer philosophy into production at the level where agents take actions. Accord is an independent company and is not affiliated with the White House.

Any. Accord governs the actions, tool calls, payments and system access, so the model underneath can be from any lab or your own.

The mandate decides. The default is a timeout that denies the action and notifies the owner, so nothing slips through by waiting.

No. mandate.modify and log.delete are never-allowed actions, and the audit trail is hash-chained and signed, so any tampering is detectable.

SECTION 17
[THE THESIS]
Frontier labs are building intelligence. We are building the infrastructure that controls what intelligence is allowed to do.
▸ Launch app Try a mandate
01The race