SKETCH
FORGED
RONIN INC

Ronin Inc  /  AI Agent Governance

AI agent governance: approval before action, an audit trail for every step.

Solomon is Ronin Inc’s governed runtime for AI agents. Agents gather evidence and propose; approval gates hold anything that sends, spends or changes a system until a person says yes; every step is written to an audit trail; and the agents run local-first, so your data stays on-premise, on hardware you control.

Let agents do the work. Keep the final say.

Request pilot access → See how Solomon works
Authorization before action • audit by default • private data fails closed • your data is never training data.

01  /  The problem

Agents that act alone are a liability.

AI agents can now send email, change records, move money and call other software. Most are built to finish the task, not to ask first.

When a support bot promises a refund the business never approved, or an agent trades at 2 AM with nobody watching, the business answers for it. Often there is no record of why the agent acted, what it saw, or who could have stopped it.

Governance is the layer that decides what an agent may do on its own, what needs a human yes, and what gets written down. Ronin builds that layer into Solomon’s runtime instead of bolting it on after something goes wrong.

02  /  The governed chain

Every request runs one chain.

Intent is resolved, evidence gathered, governance gates applied and a verdict formed. Then you authorize, it executes through connectors, and every step writes to the audit trail. The chain is the same for a one-line answer and a full software build. Nothing skips it.

Intent→Evidence→Governance→Decision→Authorization→Execution→Audit

03  /  Approval gates

A human yes before anything with consequences.

An approval gate is the point where an agent stops and waits for a person. In Solomon, gates sit in front of the actions that carry consequences: sending a message, spending money, installing software, or writing to an outside system through a connector. The agent prepares the action and shows you what it will do. It runs only after you approve.

Confidence is part of the gate. Every verdict carries a confidence score and a risk level, and low confidence routes to a question or a hold instead of an action. The reasoning is shown to you as advice, never certified as fact. You see the number the machine used, and you keep the final call.

Uncertainty defaults to no. If the session, ownership, entitlement or proof is unclear, the request is denied rather than guessed open. Consent is becoming a protocol, and the authorization layer is where it is enforced.

04  /  Audit trails

An audit trail by default, not on request.

Every step of the chain writes to the audit trail: what was asked, what evidence was gathered, which gate applied, who approved, what executed and what came back. Work is anchored to a persistent project Twin, one governed and versioned record that every engine reads and writes, so there is no hidden state and no engine working from a private copy.

Claims are held to the same standard. A result ships proof-backed or is marked pending. Solomon does not call something deployed, rendered or finished until the evidence exists. When an auditor, a client or your own team asks why an agent did something, the answer is a record, not a guess.

05  /  Local-first

Local-first, on-premise AI agents.

Solomon is local-first by default. It runs on your hardware, and your files, messages, customer records and business data stay on your device. There is no silent cloud holding them. The core reasoning runs without a network at all; governed internet access is a tool Solomon reaches for on your command, not a dependency it leaks through.

Outbound data moves only through connectors you have explicitly authorized, for tasks you asked for, never in the background. Inbound is wanted-only: anything arriving from outside is dissected and vetted before it is allowed near your data.

Your data is never training data. Solomon learns from the public answers it fetches to ground a task and from the attacks it captures. It never learns from your files, prompts or customer records. More on why: local-first AI is the governed path.

06  /  Data governance

Enterprise data governance for AI agents.

Agents are only as safe as the data rules underneath them. Solomon enforces these in the runtime, on every request.

G/01

The access rule

Every sensitive request re-checks who is asking, what they may do, whether the record is theirs, and whether proof exists on the backend. A URL is not permission, and authentication is not authorization.

G/02

Fail closed

Private data fails closed. If anything about a request is uncertain, the answer is no.

G/03

One-way alerting

Threat intelligence flows out to a sealed oversight channel through a diode. It can raise an alarm; nothing can flow back in to command the system.

G/04

Hostile input is evidence

A hostile payload is never executed. It is quarantined, studied in simulation and turned into a shield. Read the security doctrine.

07  /  Where it applies

Governance wherever agents touch the business.

The same chain governs the systems Ronin builds. In a custom CRM, automations reach out, reconcile and act, with every side effect proposed, confirmed and logged. Outbound messages wait for approval. Payment and merchant actions stay gated. Agencies that resell Ronin systems through our white-label program get the same governance in every client build.

It also answers a problem most companies already have: staff using AI tools nobody approved. A governed runtime gives people a sanctioned way to use agents, with the controls and the record built in.

08  /  Posture

Controlled deployment.

Solomon is in controlled merchant and operator validation. Public mass-market release stays gated by proof, security, signed release, entitlement, connectivity and runtime-validation requirements. Businesses can request pilot access. Individuals can run Kingmaker, the free local build of Solomon for Mac, which still asks before anything that sends, spends or installs.

09  /  Further reading

From the Ronin journal.

Questions

AI agent governance, answered.

What is AI agent governance?

The rules and controls that decide what an AI agent may do on its own, what needs a person’s approval, and what gets recorded. In Solomon those rules are enforced in the runtime, not left in a policy document.

What is an approval gate?

A point where an agent stops and waits for a person to say yes. Solomon places gates in front of actions with consequences: sending a message, spending money, installing software, and writing to an outside system.

What does the audit trail record?

Every step of the governed chain: the intent, the evidence gathered, the governance applied, the decision with its confidence and risk level, the authorization, the execution, and the result.

Can Solomon run on-premise?

Yes. Solomon is local-first: it runs on your hardware, keeps your data on your device, and its core reasoning works without a network connection.

Does Solomon train on our data?

No. Your files, messages, prompts and customer records are used to serve you and are never turned into training data.

Can we use Solomon today?

Solomon is in controlled merchant and operator validation, and businesses can request pilot access. Kingmaker, the free local build of Solomon for Mac, is available to individuals; using it inside a company needs a commercial licence.

Next step

Put agents to work with the gates on.

Tell us where agents would act in your business: outreach, records, payments, operations. We will show you where the gates and the audit trail sit, and what stays on your own hardware.