Governance

Control, permissions, auditability and human responsibility.

Governance is how UNIT2 prevents anonymous automation. They define what an agent is allowed to do, what it may never do and which human remains accountable.
European regulatory readiness

Engineered around EU AI Act high-risk obligations.

Agent6 is designed around the control patterns European enterprises will need: automatic record-keeping, effective human oversight, accuracy, robustness and cybersecurity. Legal classification still depends on the customer workflow, but the architecture is built for regulated use from day one.

Article 12

Record-keeping

Hash-chained audit logs capture LLM calls, signals, decisions, overrides, retries and corrections so consequential work remains traceable and reconstructable.

Article 14

Human oversight

Customer-facing, financial and compliance-relevant outputs route through a human review queue with reasoning traces, verification details and named approval.

Article 15

Robustness

Schema validation, Chain-of-Verification, checkpoint recovery, model failover and local fallback reduce fragile automation and improve operational continuity.

Agent Passport

Control, permissions, auditability and human responsibility.

The Agent Passport is the governance container that prevents autonomous agents from becoming uncontrolled actors. No passport, no execution.

AGENT6 · PASSPORTID 7F3B-A19C

AGENT1

Pricing Agent
Allowed actionsprice_bom · margin_calc · quote_draft
Denied toolserp_write · payment · email_external
Financial limit€50,000 / quote
Accountable humanOperations lead
STATUS: ACTIVEESCALATE: HIGH-SIGMAAUDIT: REQUIRED
We do not remove accountability. We architect where accountability belongs.

Routine decisions route to agents

Low-risk, reversible and well-bounded decisions can move at machine speed under audit, schema validation and passport limits.

Consequential decisions stay with named humans

Strategic, legal, financial, ethical or irreversible decisions are escalated to the human review queue with full context and traceability.

Production primitives

What separates deployment from demo.

Four engineering primitives make the Stack reliable enough for regulated workflows.

E

Trusted Evals

CoVe, schema validation and experiment orchestration identify hallucinations, compare variants and track reliability over time.

L

Searchable Logs

Every LLM call, signal, decision, override and correction is reconstructable through the hash-chained audit trail.

R

Checkpoint Recovery

Crashed workers resume from the last completed phase; provider outages trigger failover; exhausted tasks fail cleanly.

H

Human Review Queue

PIN-protected review preserves human authority for customer-facing, financial and compliance-relevant work.

Correction Memory

The same lesson does not need to be taught twice.

Human review becomes operational memory: attributed, reversible and automatically injected into future work of the same task type.

1

Capture

A human rejects or adjusts an output with written remarks and context.

2

Extract

The system converts the correction into a structured operating rule.

3

Store

The rule is logged with reviewer, source task, timestamp and audit reference.

4

Inject

Future matching tasks receive the correction automatically before execution.

Data sovereignty

Runs on hardware the customer owns.

A standard node can be a commodity small-form-factor PC hosting local agents and a local LLM. Regulated workloads can run with zero outbound network calls while frontier models remain optional for tasks that genuinely need them.

01
Sovereign deployment readyLocal LLM capable. Supabase can be hosted in an EU region or controlled environment.
02
Provider independenceModel routing can move work across frontier, balanced, cheap or local tiers by task type.
03
Predictable economicsRoutine work can run locally; cloud spend is reserved for work that needs frontier reasoning.
04
Resilient continuityIf cloud providers fail, work continues slower — but continues — on the guaranteed local fallback.