What SensCheck does not do
Trust comes from being clear about limits. SensCheck Governance — Core is an application-level governance SDK.
It is not
- an operating-system sandbox or container: use OS permissions, containers and cloud IAM as the real perimeter;
- a hardware security module or key store;
- an authentication system: it consumes identity and authority from providers you supply;
- a safety-certified machinery controller, or a substitute for robot or functional-safety systems;
- a guarantee against malicious host code that bypasses your wrappers.
Specific limits
| Limit | What to do |
|---|---|
| Receipts are hashed, not signed | Store them somewhere the agent cannot modify |
| Replay and approval single-use are per process | Share state in a store you control for multi-process deployments |
| A running action cannot be rolled back or time-limited | Design effects to be idempotent or reversible where you can |
EnvironmentAuthorityProvider is weak by design | Anything that can set env vars can grant itself authority. Prefer real grants |
senscheck audit is pattern matching | Treat findings as a starting list, not proof |
| The SQL classifier is not a parser | Use database permissions as the real boundary |
Use it with defence in depth
Governance catches an agent doing something it should not have been allowed to do. It works best next to least-privilege credentials, sandboxed execution, network egress controls, and review of what agents change.