Arcezia

Arcezia / Glossary

Glossary: checking what an AI agent does before it runs

Plain definitions of the terms used on this site for checking what an AI agent does before it does it.

Execution integrity

Execution integrity means every action an AI agent executes is backed by evidence and authorized, checked before it runs rather than scored after.

What it is: a property of the actions, not of the text. A tool call can be polite, on-topic and well-formed and still rest on a fact no tool ever established.

What it is not: a content filter, and not a log reviewed after the action has run.

Example: a support agent calls process_refund for an order no tool ever returned. Every text check passes; the order does not exist. The worked example.

Where it sits among the other layers of agent security (model, governance, identity, environment): where execution integrity fits.

Other uses: the phrase is also used in embedded-systems security and in AI research papers, with related but different meanings. This page gives the sense Arcezia uses.

Pre-execution verification

Pre-execution verification is checking a tool call an AI agent proposes, and the facts it rests on, before the tool runs, then answering ALLOW, BLOCK or REVIEW.

What it is: a gate between the agent deciding to call a tool and the tool running. Only ALLOW reaches the tool.

What it is not: grading a model’s answers, or monitoring that reports after the action.

Example: in an independent review of the public service, a database read inside the session’s scope was held for review, and a delete under the same scope was blocked. Both answers came before anything ran.

Also called tool-call verification or pre-action checks. One call checked three ways, with the answers measured on the live service: action authorization.

ALLOW, BLOCK and REVIEW

ALLOW lets the tool call run. BLOCK refuses it and says why. REVIEW holds it and names what would release it, such as a person’s approval or an answer from your own check.

The same input always gets the same answer. How to handle each answer.

Authority Fabrication Index (AFI)

The Authority Fabrication Index (AFI) is how often an AI agent asserts authority or evidence it does not actually have when attempting an action: an approval nobody gave, an order no tool returned, a backup that never ran.

The agent fabrication benchmark measures this failure and how often guardrails approve it.

Signed decision record

A signed decision record is the receipt Arcezia keeps for each check: the answer and its reason, signed so that a later change to the record shows when it is checked.

It is evidence that the check ran before the action. It is not a certification. A real sample and the offline checker: audit evidence.

Questions

What is agent tool-call verification?

Checking a tool call an AI agent proposes, and the facts it rests on, before the tool runs, then answering ALLOW, BLOCK or REVIEW. Only ALLOW reaches the tool. See pre-execution verification.

How do I keep an audit trail of AI agent actions for the EU AI Act?

Arcezia keeps a signed record of each decision and its reason, made before the action runs. The developer docs map these records to EU AI Act Articles 9, 11 and 12, 13 and 14, and 15, and to NIST AI RMF Measure 2.6: Receipts and compliance.

The record is evidence, not a certification, and using it does not by itself make a system compliant.

Related