Skip to main content
PALOPALO FRAMEWORK
v2.5 full-cycle developer preview Internet-reachable evaluation endpoints

Governance before, during and after execution

Make agent authority and its real-world effect verifiable.

PALO-AI is the technical control-plane component of the PALO Framework. It operationalizes selected PALO-AM controls for n8n and agentic automation platforms by binding explicit authority and policy to a one-time execution capability, a trusted receipt and verification that the action produced the declared effect.

Current boundary: this release is for interoperability evaluation with isolated data and non-consequential tools. It is not a production authorization service, certification, or independently assessed security boundary.

Agent / workflowAction proposal
PALO-AI control path
  1. 01Normalize claim
  2. 02Evaluate policy
  3. 03Approve if required
  4. 04Execute through capability
  5. 05Verify the effect
Verified Review required Denied
A policy decision is only authoritative when protected execution cannot bypass the governed path.

One connected governance journey

Method, runtime contract, role-based workspace and evidence boundary

Orientation: PALO-AM v2.0 remains the June 2026 methodology baseline. PALO-AI v2.5 is the July 2026 full-cycle runtime/contracts Developer Preview. The Governance Hub uses illustrative/local data and is not a production console.

Objective: govern agent actions

Build mode refines the route. It does not replace accountability.

First choose your organizational role in the guided Start. Only then choose how you build. PALO-AI keeps the Action Claim, policy decision, approval and evidence vocabulary consistent across all three implementation modes.

01 / CODE

Code-first developer

Integrate JSON Schema, MCP, OPA/Rego, CI gates and a brokered executor into an application or agent runtime.

First move
Validate a canonical Action Claim and force one mock tool through the governed path.
Use
SDK contracts, stdio or remote MCP, Rego tests, gateway adapter.
02 / VISUAL

No-code / low-code builder

Use the visual decision gate for comparison, then move the protected action into the PALO Governed Action node and verify its outcome.

First move
Run the synthetic catalog demo and compare verified, mismatched and inconclusive outcomes.
Use
Local alpha node or native HTTP, Switch and Wait nodes.
03 / RAPID

Rapid prototyper

Connect Copilot Studio or a similar platform to a deliberately narrow set of PALO MCP tools, without writing policy code first.

First move
Select one authority profile, one reversible action and one accountable reviewer.
Use
Streamable HTTP MCP, guided profiles and evidence review.

New guided Governance Hub

One control plane. Two role lenses. No JSON required to start.

The same governance state is translated into an executive cockpit and a technical workbench. Leaders see coverage, authority, verified outcomes and exceptions. Builders configure the exact agent, tool, resource, oversight and outcome verifier through an eight-step guided flow.

  • Executive lensIndependent signals, portfolio exposure, decision queue and assurance reporting.
  • Technical lensRegistry, policies, executions, approvals, incidents and integrations.
  • Progressive disclosurePlain language first; generated Action Claims, Effect Contracts and policy inputs remain inspectable.

Prototype boundary: this browser interface uses realistic evaluation data. Production multi-user operation still requires an authenticated backend-for-frontend, tenant-aware roles, managed keys and independent security assurance.

PALO-AI white Governance Hub showing the guided Bound authority step and the resulting enforcement summary
Selected product direction: a guided governance builder that hides implementation complexity until the user asks for it.

Portable governance lifecycle

From intention to verifiable outcome

  1. 01ProposeAn identified agent or workflow requests an action.
  2. 02NormalizeResource, operation, path, host, network intent and arguments become one Action Claim.
  3. 03EvaluateSchema, registry and Rego policy fail closed on malformed or missing context.
  4. 04ApproveWhen required, a reviewer resolves the exact immutable claim.
  5. 05ExecuteThe protected credential or tool is reachable only through the governed path.
  6. 06ReceiptThe trusted executor records what was actually attempted without accepting caller-supplied success claims.
  7. 07ObserveA separately registered verifier retrieves authoritative post-state.
  8. 08Verify effectExpected and forbidden effects resolve to verified, mismatch or inconclusive.
  9. 09EscalateMismatch and uncertainty create a resource hold and a reviewable assurance incident.

Deployment choice

Local remains possible. Cloud becomes a governed service boundary.

The contract stays portable; identity, keys, persistence, availability and network trust change by deployment mode.

Swipe horizontally to compare every deployment field.

ModeBest fitCurrent availabilityTrust boundary
Local sidecarCode-first development, self-hosted n8n and offline evaluation.Implemented previewKeep OPA, registry, ledger and credentials on the trusted host or private container network.
HybridLocal/private workflows calling a remote PALO decision service over HTTPS.PrototypeWorkflow data crosses the organization boundary; minimize claims and retain protected execution locally.
Managed cloudMulti-team governance with central policies, approvals, evidence and operations.Target architectureRequires tenant isolation, workload identity, RBAC, KMS/HSM, HA and independent assurance.
Private cloud / VPCRegulated or enterprise environments needing organizational control and network isolation.Target architectureCustomer-owned identity, network, keys, retention and operational controls integrate with the PALO service.
HTTPS Gateway: developer previewhttps://governance.paloframework.org/gateway
Streamable HTTP MCP: developer previewhttps://governance.paloframework.org/mcp

Internet-reachable does not mean production-ready. The current VPS adds HTTPS termination and network isolation, but not production workload identity, least-privilege RBAC, managed keys, high availability, distributed exactly-once semantics, attested execution or independent security review.

Integration is not enforcement

Platform capability matrix

A visible check helps people understand a decision. It becomes an authorization boundary only when the protected tool and credential cannot be reached around it.

Swipe horizontally to compare enforcement coverage.

PlatformVisual gateBrokered executionRuntime interceptionAuthoritative today?
n8nPackage 0.2 compatibility decision nodePackage 0.2 Governed Action prototypeNot implemented; alternate credentials or tool paths can bypass the nodeNo. Unpublished and not n8n-verified
Copilot StudioMCP tools can surface governance actionsTarget via narrow PALO toolsPlatform-owned controlsNo. Integration guidance only
DifyNon-production tool exampleAgent Strategy targetPlugin-owned targetNo. Reference example
LangChain / LangGraphMiddleware decision feedbackRecommended adapter shapeBefore-tool middleware / interruptNo. Adapter not packaged
Node-REDCustom node or subflow targetBroker requiredSelf-hosted hook targetNo. Specified pattern
MakeHTTP or custom-app stepPALO-controlled API targetNo universal interceptorNo. Direct actions must be removed
ZapierPrivate/public integration targetPALO-controlled action targetNo universal interceptorNo. Direct actions must be removed

Enforcement invariant: do not expose a direct privileged tool path beside its PALO-governed broker and then describe the flow as enforced.

Assurance before scale

What is real, and what still blocks production

The developer preview includes canonical schemas, a trusted versioned registry, Rego v1 policy evaluation, replay controls, transactional local persistence, signed evidence and official-SDK MCP transports. These are evaluation primitives, not evidence of an independently assured production service.

Required closure

  • OIDC or mTLS workload identity and least-privilege tenant RBAC
  • KMS/HSM-backed signing, rotation and separation of duties
  • Distributed durability for consumed one-time capabilities, workload identity, connector isolation and removal of alternate privileged execution paths
  • Durable approval resume, HA state, outbox, recovery and external evidence anchoring
  • Threat model, independent penetration test, cryptographic review and supply-chain assessment

Current publication boundary

Precisely what this release claims

Prototype

n8n visual decision gate

Locally installable alpha package with Allowed, Approval Required and Denied outputs. It does not execute the protected target.

Prototype

Governed executor

Package 0.2 binds an Effect Contract to a one-time capability, executes through a registered connector, records a signed receipt and verifies authoritative post-state. Alternate credentials or tool paths can still bypass this preview.

Specified

Secure approval resume

Target flow binding authenticated reviewer authority, exact claim digest and one-time workflow continuation.

Specified

Workflow admission

Target deployment gate that rejects flows containing bypass paths before activation.

Publication status: n8n-nodes-palo-ai is unpublished, unverified and not accepted by n8n. npm publication, catalog discovery, n8n verification and connector submission are deferred until real integration and security gates pass.

Architecture preview

Bring one safe workflow. Challenge the boundary.

We are looking for n8n builders, platform integrators, policy authors and security reviewers willing to test a non-production workflow with mock or reversible actions. Do not share secrets, personal data or production credentials.