Plan-bound authorization
Execution is evaluated against the approved plan and scope before tools are permitted to mutate external systems.
DSG ONE separates who proposes, proves, authorizes, executes, and observes AI-agent work. External side effects are bounded by an approved execution contract and evidence-backed verification.
DSG ONE binds execution to approved intent, separates trust domains, and keeps proof, authorization, execution, and observation from silently collapsing into one agent decision.
Execution is evaluated against the approved plan and scope before tools are permitted to mutate external systems.
Cinema and exact Z3 verification provide a separate proof boundary rather than allowing the candidate generator to validate itself.
Approved work reaches APIs, MCP tools, browsers, and deployment adapters through bounded execution paths.
Execution evidence, hashes, replay state, and post-deploy observations remain inspectable after the action.
The system that creates a candidate does not approve it. The verifier does not execute it. Monitoring does not mutate production. Select a trust domain to inspect its responsibility.
Required authorization, plan alignment, capabilities, constraints, execution conditions and evidence support continuation.
The requested step remains inside the approved plan, but execution pauses until the required permission or capability is provisioned.
The system does not convert missing authority, failed constraints, incomplete proof, or out-of-plan actions into success.
Formal encodings can be searched deterministically. Natural-language hints without the required encoding do not become executable proof.
Exact Z3 verification is a bounded mathematical claim about the encoded problem, not a certification or legal/compliance conclusion.
Browser sessions are tied to approved work. Verifier-side observation is separated from executor-side mutation, and out-of-scope actions are expected to fail closed.
Monitoring evidence can support acceptance of the next baseline, hold for review, or rollback recommendation while mutation authority remains separate.
The public product surface is a working MVP and architecture/evidence package. Production-provider binding and scaled commercial rollout remain explicit next-stage work.
Canonical authority model, independent Cinema/Z3 proof path, bounded execution design, public documentation, source evidence, and CI/E2E references.
Production adapters must be explicitly bound and authorized. An unbound provider remains blocked by design and is not presented as deployment success.
DSG ONE does not claim marketplace acceptance, independent audit, legal certification, or Google Cloud endorsement without separate external evidence.
This section maps the canonical architecture to concrete execution rules: candidate admission, deterministic search, independent proof, promotion authority, multi-lane joins, browser isolation, and post-deploy control.
Candidate admission requires composite-score improvement, real-efficiency improvement, and no protected-metric regression.
ADMIT = scoreImproved ∧ efficiencyImproved ∧ noProtectedRegressiondsg-agi-simulation/src/candidate-admission.tsInteger-based deterministic search can evaluate formally encoded QUBO/Ising problems. Natural-language hints without the required encoding do not become executable solver input.
missing constraints.aimoEncoding → REVIEWShard progress and whole-space proof are separate states; one shard cannot claim a global optimum before the full search boundary is established.
searchComplete ≠ wholeSpaceSearcheddsg-agi-simulation/src/aimo/solver.tsCinema uses Z3 to obtain a candidate, applies deterministic tie-breaking, then creates a separate proof obligation asking whether any assignment exists with strictly lower energy.
verifier_objective < candidate_energyOnly the UNSAT proof path yields verified=true for that bounded encoded problem.
The promotion boundary requires the approved plan hash, baseline/candidate commit binding, allowed paths, plan alignment, passed constraints/tests/build, objective improvement, required evidence, and independent Cinema proof.
candidateAuthority = SIMULATION_ONLYpromotionAuthority = DSG_CONTROL_PLANEselfPromotionAllowed = falseRequired evidence includes commit, metric, test output, and build output. Candidate commit and Cinema proof binding must agree before promotion can be authorized.
promotion-gate.tsParallel lanes move through an explicit state machine and must satisfy join requirements before the wave can complete.
QUEUED → RUNNING → READY_TO_JOIN → JOINED → COMPLETEDJoin checks require a joinable state, commit SHA, evidence, and no blockers. Missing evidence in one required lane can block the wave rather than silently merging partial success.
BLOCKED / FAILED remain explicit statesControl Plane multi-lane runtimeRemote Browser sessions bind to an approved plan, approved step, and agent identity. Mutation-capable controllers are separated from verifier-side observation.
agent_verifier → extract / screenshot onlyPlaintext passwords, OTPs, API keys, passkeys, private keys, secrets, and MFA codes are not intended to travel through the model/evidence path. Delegation uses opaque references such as secret_ref and otp_ref.
Remote endpoints require HTTPS, reject localhost/private-address targets, validate DNS against SSRF-style private resolution, and seal session tokens with expiring AES-GCM protection.
api_v1/remote_browser.pyProduction evidence feeds a monitoring decision while mutation authority remains separate.
PASS → COMMIT_NEXT_BASELINEREVIEW → HOLD_REVIEWBLOCK → EXECUTE_ROLLBACKMonitoring is observation-only; the canonical authority owns execution. An unbound provider or disabled production-deploy capability fails closed instead of being represented as deployment success.
PRODUCTION_TARGET_UNBOUND → BLOCKCurrent rollback adapter scope is bounded to declared providers such as AWS, GCLOUD, and DOCKER with HTTPS endpoint requirements.
post-deploy control / deployment adaptersAGI may propose. Cinema may prove. Monitoring may report. Executors may act. None of those roles silently grants itself canonical authority.
DSG ONE separates test-surface coverage, real E2E path coverage, deployment evidence, and instrumented source coverage instead of treating them as interchangeable claims.
Path-scoped workflows compile, run unit/contract/integration suites, enforce deterministic governance assertions, validate packages, and keep channel-specific failures visible.
Current E2E paths include isolated Azure Cinema→Z3 proof/replay, plan-bound Browserbase production execution, and authenticated Copilot CLI + DSG MCP flows.
Deployment receipts, GitHub Actions artifacts, client evidence, proof hashes, and production probes support specific runs. An old PASS is not evidence for a later revision.
DSG ONE is delivered as B2B infrastructure for teams that need controlled external execution, deterministic verification, and evidence-backed outcomes.
Organizations operating AI agents or automated workflows that need plan-bound authorization, controlled side effects, proof receipts, audit evidence, and replayable execution history.
Current delivery surfaces include the Direct API, GitHub/CI integrations, agent and MCP integrations, marketplace packages, and enterprise deployment paths. Package availability does not imply external marketplace approval.
The operating path starts with capped free activation, then governed usage and commercial plans where the required billing and entitlement gates are verified. Enterprise deployment remains a separate delivery option.
Value is concentrated in approved-plan binding, deterministic verification, controlled execution, evidence collection, replay, proof receipts, and production governance around AI actions.
The system proposing work is separated from the verifier, canonical authority, executor, and observer. This reduces the risk of an agent authorizing or validating its own side effects.
Internal package readiness, CI success, or a deployment receipt is not represented as marketplace acceptance, third-party certification, or independent audit. External approvals remain separate evidence gates.
DSG ONE checks whether recorded AI-agent execution conforms to an approved plan, remains inside its declared scope, includes the required evidence, matches replayed outputs, and supports a verifiable proof receipt.
The Console shows plan alignment, constraint verification, recorded execution, evidence coverage, replay match, the final decision, and machine-readable receipt hashes without requiring the user to search server logs.
plan_01m10z7zgrgegen3pcxat2exec_01m10z8094pdy67kzrsptrproof_01m10z80rtpx6qstcwfmwe7baac0c87bbf64ce335cdc2f396d636fef79b022b13c32b4d163e3b904ae694eReceipt hashf788b7b4bdb6efac119922616cee8220c730267087369396ee2cde3e791dc50fFail-closed evidence: the first attempt without a valid API key stopped at plan creation with UNKNOWN_KEY and issued no decision or proof. After explicit free-key activation, the authorized flow completed and the receipt was read back with a matching recomputed hash.
DSG ONE is a founder-led software startup developing governed execution infrastructure for AI-agent systems. This public profile separates what is available now from the next cloud-scale milestones.
Founder-led B2B software product. Primary customer groups are AI teams, SaaS operators, and agent platforms that need controlled external execution and verifiable evidence.
Available now: governed architecture, code-backed control boundaries, independent Z3 verification, CI/E2E documentation, public interactive architecture, and a production-domain information site.
Founder: Thanawat Suparongsuwan
Email: t.dealer01@dsg.pics
Website: dsg.pics
This is the intended technical roadmap, not a claim of completed migration or Google endorsement.
Developing DSG ONE around deterministic governance, controlled agent execution, and evidence-first product behavior. Contact: t.dealer01@dsg.pics
DSG ONE treats proposal, proof, authority, execution, and observation as separate trust domains. Claims on this site are scoped to the implementation, evidence, and external status actually established.