Learn
How to keep agents from doing what nobody approved.
Short, concrete lessons. Each one maps to behaviour you can run and test in SensCheck Governance — Core.
Why fail closed
Fail-open and fail-closed, why an outage is not a refusal, and the four outcomes SensCheck uses instead of true/false.
Core ideaIntelligence is not authority
Why a model that proposes an action can never be the thing that authorizes it, and how SensCheck enforces that.
Core ideaEffects: what actually gets authorized
Why SensCheck authorizes a typed, canonical effect instead of free text, and how a digest stops an approved action from changing.
PracticeHuman approval that means something
Independent, effect-bound, single-use approval, and why "the user clicked OK" is not enough on its own.
PracticeReceipts: what happened, honestly
Authorized, attempted, executed: the difference, why the receipt comes first, and what its integrity hash does and does not prove.
PracticeGoverning MCP tools
Put a fail-closed boundary in front of MCP server tools: classification, schema preservation, and the bypasses to avoid.
Deep diveThe threat model in plain English
What SensCheck assumes about attackers, which attacks it blocks, and where the remaining risk lives.
Read thisWhat SensCheck does not do
An honest list of what the free Core package does not protect, and what to use alongside it.
ReferenceGlossary
Plain definitions for the terms used across SensCheck: effect, principal, authority, digest, receipt and more.