Autonomous Risk Containment
Center Guard Policy Studio & Monotonic Attenuation Engine
Mandant solves the autonomous agent containment crisis by enforcing permissions directly in EVM smart contract bytecode. Child agents can only narrow permissions, never expand beyond their ancestor mandate.
Security PostureMAXIMAL
EVM GuardrailBYTECODE
Interactive Policy Configuration
Max Spend Per Job Ceiling$250 USDC
$50 (Micro-Job)$500 (Batch Inference)$1,000 (Max Capacity)
Permitted Execution ToolsHARD-BLOCKED
Raw ERC-20 transfer()
Hard-coded bytecode revert barrier
Onchain policyHash Commitment:
0x7a3e0661098aa25e09592fd34a90ff5a8921d27162bf011fdb75d7c7b147a6f5
Committed into the MandateNode struct slot in MandateTree.sol on Arbitrum Sepolia.
Interactive EVM Bytecode Simulator
Test how the EVM executes when an autonomous worker calls different actions against this policy:
Click any scenario above to execute bytecode simulation...
Monotonic Attenuation Verification
In Mandant's recursive hierarchy, when Orchestrator (Depth 1) spawns Worker Beta (Depth 2), the smart contract enforces:
Allowlist(Child) ⊆ Allowlist(Parent) ∧ Budget(Child) ≤ Idle(Parent)
If an operator or agent attempts to pass an address outside the parent allowlist, the EVM transaction reverts instantly with ChildAllowlistNotSubset().
