sigma · controlled evidence
agσ

sigma

Policy-scoped behavioural decision layer.

Sigma reads what code is able to do — statically, pre-runtime — and resolves it to one auditable decision on a five-step escalation ladder: observe → shield → contain → quarantine → terminate. Calibrated for low false-positives: benign trees rest at observe, and only corroborated, high-confidence critical chains escalate to a hard fail.

evidence ledger

measured facts, not exposed machinery.

Decision profile from the 2026-05-17 low-false-positive calibration on a mixed developer workspace. Determinism verified by hermetic repeat-replay.

escalation ladder
observe → … → terminate · 5
benign baseline
resolves to observe · 0 false quarantine
fail-hard
terminate on confirmed invariant chain
escalation gate
corroborated, high-confidence evidence only
determinism
3/3 identical · tier/path/health/grade
verdict
structured JSON · milliseconds
public layer

Low false-positive by design.

Benign developer trees rest at observe. Escalation requires corroborated, high-confidence evidence — raw signal counts never escalate on their own. Terminate stays reachable only for confirmed critical chains, and every decision carries an auditable trace of why it escalated.

gated layer

The mechanism.

Gate names, the trusted-source set, capability resolution and invariant mechanics, and formula identifiers stay sealed. Sensor coverage has known boundaries — characterised honestly and disclosed to evaluation partners under NDA, never advertised.