Routh Systems
Routh Systems · Colorado Controls for AI that takes actions

Your AI is about to start acting. Put the controls in first.

An assistant that answers questions over your own documents is read-only and mostly safe. When that same assistant can issue a refund, change a configuration, or move data, ordinary IT controls are not enough. We help you choose the right controls, install them, and show that they work.

Established practice

The controls

Every control below is available today in mature tools, and most companies already have some in place. The usual gap is knowing which controls to implement first, and what each one covers.

In the order worth implementing them
Control What it gives you What it takes to put in What it does not cover
First Least privilege and isolation Bounds damage from any single mistake. Credentials are scoped to the job, not the person. The agent never sees a tool it may not use. Snapshot and restore sit behind anything that writes. Distinct credentials per workflow and a read-only default. Days of work, not quarters, and the cheapest control on this list. It bounds how bad a mistake is, not how likely. An agent operating entirely inside its sandbox can still do the wrong thing with everything you gave it.
Second Authorization at the action layer A defensible decision for each action: this actor, this action, this resource, allow or deny. AWS Cedar, Open Policy Agent, and the agent gateways all answer this same question. Cedar goes furthest by machine-checking properties of its own evaluator. Explicit rules and an enforcement point every call must pass through. The rules take the time. Per-action enforcement does not guarantee the result of a sequence of actions. See The practice.
Third Guardrails and constrained output Input and output filters, classifiers, model judges, and constrained decoding. Constrained decoding gives a hard guarantee about output form. Filters are best-effort guesses about meaning. Little. Mostly configuration on tools you are already paying for, which is why it is often the first thing bought. A syntactically perfect tool call that moves the wrong money passes every content filter. It is useful and cheap, but it is a filter rather than a boundary.
Fourth The audit trail Six months later, even to a hostile reviewer, you can answer why the system did what it did. Capture the action, the inputs it saw, the decision and its reason, and a signed receipt per decision. Deciding what to record before deployment. Retrofitting an audit trail after an incident is the expensive version of this work. Monitoring detects. It does not prevent. A record that cannot reconstruct a decision is logs, not an audit trail.
Fifth Evaluation, before and after Early warning on failures you have already seen. Thirty real cases with known answers, run on every change. Every incident becomes a permanent test. An afternoon to start, then discipline. A limited monitored rollout before you widen. Necessary but insufficient. The failures that matter are the ones the suite was not built to catch, a lesson the frontier labs have published on their own systems.

Before any of it. If you have already put an assistant over your own documents, the permissions belong at retrieval, not at generation. Index everything into one store and rely on the model to be discreet, and you have built a polite interface that answers questions the asker was never allowed to ask. Filter by the asking person's entitlements before anything reaches the model. Know which documents your assistant can see. Most organizations we ask cannot answer that.

How we work

Engagements

Most clients take these in order. The first needs no integration, no traffic, and no change to anything you are running today.

How we work

The practice

Routh Systems works at the seam where an AI decision becomes a real-world action. The work is grounded in formal methods and program verification, a discipline that predates large language models and has spent forty years building tools for reasoning about what a system can and cannot be made to do. We apply it to the specific problem of an agent holding credentials. Some of the current research is our own. Whether each action is permitted is one question. Whether the job can still be completed is another, and it is the one we work on.

We are not a reseller. We keep agent safety and policy frameworks under review across two dozen open-source and commercial products. When an existing engine is right for your deployment, we recommend it. You are buying judgment about which controls you need, in what order, and what each will and will not do once it is in.

Configuring an authorization layer is straightforward. Establishing that it has been configured correctly is the hard half: the rules as written still allow the work to be finished across a whole sequence of actions, not one action at a time. That is where Routh Systems is uniquely equipped. We hold proprietary methods for answering that question and the expertise to apply them to your workflow.

Independence
No reseller agreement or revenue share with any vendor we might recommend to you
Deliverables
Written and yours. Findings, rule sets, and audit design leave with you
Handover
Built on tools your own people can staff and maintain after we are gone
Candor
Every recommendation labeled by what stands behind it: measured, established practice, or judgment
Next step

Request an appointment

Thirty minutes. No preparation required. Bring the AI system you are least certain about, or the one someone is asking you to sign off on.

You will leave with the order to put controls in for that specific system and a straight answer about which of them you already have. That is worth having whether or not you engage us afterward, and it is the fastest way to find out whether we are useful to you.

Terms of the first meeting
Duration
Thirty minutes, by video
Fee
None
In confidence
NDA on request
Direct
william@routhsystems.com
Choose a time

Opens our scheduler, which shows real availability. If you would rather write, the address above reaches the same place.