What this is not
What does fail-closed mean for an agent mandate?
Fail-closed mandate checking is advisory, never enforcing. The skill and hosted check return a result and advice. They cannot stop, block, or prevent an agent or another program from acting, even after a deny or error.
This is not a security certification or a guarantee that an agent will behave safely after receiving the result.
A U.S. trademark application is pending. No registration or completed clearance is claimed.
The fail-closed rule
The evaluator does not turn any published fail-closed case into a permit. Those cases include:
- an expired mandate.
- a malformed or unrecognized mandate.
- a mandate or request that does not conform to its schema, which is refused rather than partially evaluated.
- a request missing required fields.
- an unknown operation kind.
- a non-finite or negative amount.
- an empty or host-ambiguous target prefix.
- an unforeseen internal fault.
- a mandate condition the evaluator does not implement.
- a mandate with an unreachable clause, an unbounded prefix, or credential material. Such a mandate is invalid, and every
check_actionreturnserror.
See the skill instructions for the full list.
An absent optional counterparty is not an error. If a clause constrains counterparty and the request omits it, the clause does not match. A clause that sets max_amount does not match a request that states no amount: "clause bounds an amount but the request states none". Evaluation continues to later clauses and then the default.
A non-permit result advises the agent not to act. It cannot prevent the action, close a technical path, or keep another program from ignoring the result.
How evaluation reaches a decision
The evaluator reads structured action fields such as operation kind, verb, target, counterparty, and amount. It compares them with the mandate's ordered clauses. The first matching clause decides.
Put denials before the permits they narrow. Set the mandate default to deny or escalate, never permit. Add not_valid_after so delegated authority expires. When a permitting clause matches an action kind listed in requires_human, the evaluator returns escalate instead of permit.
Structured match conditions determine whether a clause matches. Text in a purpose, note, or justification cannot cause a permit. The expiry, requires_human, and the default also affect the result. A justification that appears to contain credential material can cause a denial.
What to do with each outcome
permit(exit 0): a clause covers the action. The check advises that the agent may proceed and then record the decision.deny(exit 1): the check advises the agent not to proceed, not to attempt the operation by another path, and not to reword the action to get a different answer. Tell the operator.escalate(exit 2): the check advises the agent to ask a person for a decision on this action and not to proceed without it. Silence or a general instruction is not approval.error(exit 3): the check advises the agent to treat the result asdenyand report the error.
Fail-closed means that uncertainty produces a non-permit result and advice not to act. It does not mean the check can enforce that advice.
Entry
The hosted check runs the evaluator and keeps no request content. Use MCP at https://check.hanria.ai/v1/mcp or HTTP at https://check.hanria.ai/v1/check. Inspect the result and follow its advice. A decision log is a local integrity check, not third-party proof.
Instructions, schemas, and examples: https://hanria.ai/developers/ Boundaries: https://hanria.ai/boundaries/
Honest verdict
Use fail-closed mandate checking when you want an agent to receive a non-permit result for the published failure cases and follow advice not to act. Do not treat that advice as a control that can physically prevent an operation.