The Trust Assurance Framework. Policy-based, evidence-backed, provenance-tracked trust in AI-augmented systems — asserted claim by claim at release, and verified step by step at run time.
The goal is reliance matched to a system's actual, demonstrated trustworthiness — because over-reliance and under-reliance are both failures. A dependable system nobody can interpret invites under-reliance; a polished interface over an undependable system invites dangerous over-reliance. Origi is built to deliver, and to demonstrate, both sides: objective dependability and the affordances that let you perceive it accurately.
Every trust claim is an assurance case — claim, argument, evidence — bound to exactly one policy with an explicit threshold and owner. A claim is satisfied only when the measured outcome meets the threshold and the evidence chain validates: every signature verifies, no hash link is broken, no evidence has expired. Never on a passing number alone.
Each carries its own policy, claim, measurable outcomes, and evidence chain — and each maps to the NIST AI RMF trustworthiness characteristics, so the dossier cross-walks to recognised governance.
Accurate, reliable performance across approved conditions — graceful at the edges.
Explanations measured for faithfulness, not just presence — at a level fit to the reader's role.
Stated confidence reflects actual likelihood of being correct — and signals where competence ends.
Stable under benign variation and across versions; changes detected and announced, never silent.
Decisions traceable end-to-end, human oversight on high stakes, a working appeal path.
Measured on the worst-served group, not just the average — a strong aggregate can hide real harm.
Resists manipulation and adversarial input within a stated threat model; protects sensitive data.
Pursues the goals stakeholders actually intend — an approved specification, not a harmful proxy.
Humans keep control where it matters, and rely on the system exactly as much as warranted.
The recurring theme: confident wrongness is the most corrosive failure — it teaches users to over-rely and get burned, or to distrust the system entirely. Several components track confident errors separately.
The same claims, policies, and provenance move to inference time. The harness is a reference monitor for trust: nothing an agent produces — plans, messages, tool calls, outputs — is trusted by default. A checkpoint sits at every boundary, and delegated authority can never exceed the authority that delegated it.
Assigns the policy profile, checks input integrity and requester authority. Verdict: allow, sanitise, clarify, or refuse.
Validates each handoff and tool call against policy, enforces least privilege, bounds autonomy, and routes irreversible or externally-visible actions to a human hold.
Checks the output is faithful to what actually happened, attaches calibrated confidence, screens for fairness and leakage, and attaches the provenance manifest.
Security and high-stakes checks fail closed — a timed-out evaluator blocks rather than allows. And no single probabilistic check is ever a sole gate: deterministic controls and least privilege bound the impact if any one check is wrong.
Trust zones set the maximum capability an agent may even request, and the envelope expands only as trustworthiness is demonstrated — every action still individually verified. Promotion requires clearing a higher bar and sustaining it; a single breach or detected attack revokes capability immediately.
The control plane itself is split three ways — an Observer assesses evidence it did not produce, a Judge rules against zone policy, and a Controller acts only on a signed verdict. No component can both decide an agent deserves more power and grant it — the self-escalation path is removed by construction, and every transition is signed provenance.
The framework is itself tested: an independent adversarial program attempts to defeat the controls round after round, every finding becomes a fix and a permanent regression test, and because every run is signed, replayable provenance, the evaluation itself is reproducible. Origi is the trust harness inside Northwind, Lamassu, and the ECCC engagement — the same machinery, proven in the field.
Book a walkthrough and watch a request cross the harness — pre-flight to post-flight, with the trust dossier it leaves behind.