What SensCheck does not do

Trust comes from being clear about limits. SensCheck Governance — Core is an application-level governance SDK.

It is not

Specific limits

LimitWhat to do
Receipts are hashed, not signedStore them somewhere the agent cannot modify
Replay and approval single-use are per processShare state in a store you control for multi-process deployments
A running action cannot be rolled back or time-limitedDesign effects to be idempotent or reversible where you can
EnvironmentAuthorityProvider is weak by designAnything that can set env vars can grant itself authority. Prefer real grants
senscheck audit is pattern matchingTreat findings as a starting list, not proof
The SQL classifier is not a parserUse database permissions as the real boundary

Use it with defence in depth

Governance catches an agent doing something it should not have been allowed to do. It works best next to least-privilege credentials, sandboxed execution, network egress controls, and review of what agents change.

← All lessons