The model proposes. The harness decides.
Every vendor in this category now says AI. Almost none of them will tell you what happens when the model is wrong. The answer cannot be a better model, because a language model is not deterministic and a plant cannot run on something that isn't. It has to be the envelope around it.
Determinism belongs to the harness, not the agent.
You cannot make a language model deterministic in any sense that would satisfy a controls engineer. What you can make deterministic is everything around it: what the agent may reach, at what priority, against which named device, and what happens to the request if it asks for more. Same manifest, same permitted set, every run — regardless of what the model produced that time. The model is a proposer. It is never the thing that decides what is executable.
Reach is declared before anything runs.
An agent states what it intends to read and write, against which equipment, before it is installed. It is then tested against that specific device and admitted or refused — identity, fit and reach verified, with the verdict and its evidence retained. A candidate that asks for more than it was granted does not receive a narrowed permission; it does not receive an edge directive at all. The admission test is the gate, and it runs before the agent exists on your network.
The envelope holds whatever the model outputs.
Refusals are structural rather than advisory. BACnet priorities 1 and 2 — manual and automatic life safety — are rejected at the gateway by construction, not by a policy an operator can relax under pressure. Writes are bounded per object type, so a value far outside a point's plausible range is refused before it reaches a controller. Under IEC 61511 a safety instrumented system must stay functionally independent of the automation layer; that refusal is how we hold our side of that line. Indagate is not a safety-rated controller and does not become one.
Every action carries the grant that allowed it.
An agent's action lands on the same record as a person's, in the same shape, with the actor, the target, the timestamp and the permission it acted under. That is what makes the two comparable, and it is what makes autonomy underwritable — an agent that can only act inside a declared, recorded envelope is a risk somebody can price. One that can do whatever the model suggested is not.
Specifics
- Deterministic
- The permitted set, not the model. The same manifest yields the same reach on every run.
- Refused by construction
- Life-safety priorities rejected at the gateway; writes bounded per object type
- Recorded
- Actor, target, timestamp and the grant in force, on every action
Common questions
Isn't a language model non-deterministic by definition?
Yes, and that is the premise rather than an objection to it. The model is not the part we make predictable. The reach, the priority, the refusals and the record are, and they hold whatever the model produced on a given run.
What happens when the agent is wrong?
It is wrong inside an envelope you declared and can inspect. It cannot reach equipment it was not granted, cannot write a life-safety priority, and cannot make a change that does not appear on the record with its grant attached. Being wrong becomes a thing you can find and reverse rather than a thing you discover later.
Can we see the envelope before anything installs?
That is the point of declaring it first. The manifest states where the agent executes and what it may reach, and it is readable before install and retained afterwards. A security reviewer can assess it without taking our word for the behaviour.
Bring your point list.
The first conversation is a survey: what you run today, and what it would look like modelled.