AI agents have started to act — calling tools, moving data, and changing enterprise systems. Open Control Stack is open infrastructure for governing those actions at runtime. Authorize what an agent may do. Enforce policy before it runs. Turn every run into portable evidence.
Every proposed action is checked against policy and authority before it runs.
Each run is captured as a structured, replayable record of inputs, decisions, and outcomes.
Records become business-readable proof for security, risk, and audit teams.
As AI agents begin using tools and triggering workflows, enterprises need to answer practical questions before and after each run: What was this agent allowed to propose? What did it actually propose? What did policy allow, block, or escalate? What did the agent rely on? Can the run be reconstructed later? Can the evidence be shared with security, risk, compliance, or audit teams?
Traditional logs, dashboards, and policy documents are not enough by themselves. Governed AI-agent deployment requires structured runtime records and portable evidence artifacts.
The stack is built to fit into existing systems, not replace them — and to keep governance portable across teams, vendors, and boundaries.
No lock-in to a model, framework, or cloud provider.
Open formats that drop into existing agent stacks.
Add tools, policies, and profiles without forking.
Evidence travels across teams, systems, and boundaries.
Every action leaves a structured, reconstructable record.
Authority and policy are enforced before actions run.
Every governed action follows the same runtime path — proposed by the agent, authorized, evaluated against policy, executed, and recorded.
Four open-source reference components, each mapping to one stage of the governed lifecycle — from action inventory to governance review. Use one, or run them in sequence.
The manifest declares the agent's intended action surface.
A lightweight manifest format for documenting an agent's tools, action types, authority requirements, review posture, reliance requirements, payload policies, and redaction hints before runtime deployment.
The control plane records and gates proposed actions during runtime.
A minimal runtime control layer that records action proposals, evaluates policy decisions, captures blocked actions, records authority and reliance, and generates replayable run records before agents affect enterprise systems.
The replay bundle packages a run into portable technical evidence.
A portable replay-bundle format for capturing the task frame, action proposals, policy decisions, evaluation traces, blocked actions, authority records, reliance records, validation reports, redaction metadata, and signature metadata.
The evidence pack converts technical records into business-facing review material.
A business-facing evidence-pack format for summarizing agent purpose, deployment context, tools, actions, authority model, policy controls, blocked actions, reliance, replay bundles, validation results, redacted exports, risks, and review records.
The Cognous Open Control Stack is intentionally narrow. It is not an agent framework, not a model runtime, not a hosted dashboard, not a complete compliance product, and not a full enterprise governance platform. It is a public reference layer that defines practical artifacts for governed AI-agent deployment.
Move agents into production with governance built in, not bolted on.
Add a runtime control layer without adopting a whole framework.
Review what an agent did — and prove it — in business-readable form.
Declare an agent's actions once; get authorization, records, and replay.
The same stack, documented for every audience — from a five-minute executive read to the reference specs and source.
A five-minute overview of what the stack governs and why it matters.
Non-technical collateral on value, scope, and adoption.
The four component specs: manifest, control plane, replay, and evidence.
Source, JSON Schemas, and conformance tests on GitHub.
ODES, the Open Decision Evidence Standard, is a separate proposed open, vendor-neutral public standard for portable decision evidence in AI-mediated and cross-boundary decisions. Cognous Open Control Stack is not ODES and does not define ODES conformance. The stack may produce, package, or reference evidence that could support ODES-style records in future profiles, but the relationship is optional mapping and supporting evidence — not identity and not conformance.
Open, vendor-neutral infrastructure for governing AI agents at runtime. Adopt one component, or run the whole stack.