Deterministic governance for autonomous actors on XRPL
No receipt, no transaction.
The governance layer between autonomous actors and the XRP Ledger. Every action is checked against policy before anything signs, and the ledger itself rejects what the policy did not approve.
// 01Every action starts as an intent.Everyactionstartsasanintent.
// 02Policy decides before anything signs.Policydecidesbeforeanythingsigns.
// 03The ledger requires both signatures.Theledgerrequiresbothsignatures.
// 04Every approved action leaves a receipt.Everyapprovedactionleavesareceipt.
// 05Anyone can verify it. Offline.Anyonecanverifyit.Offline.
ALLOW · T1
Receipt chained
5ea7a58c…2d6dc9 · prev af49dc93…3a3e4d
DexSwap $500
Payment $15,000
Claims T0
The kernel's reference demo, replayed: three intents against a DUNA treasury policy. Receipt hashes are from a real run; the demo mocks XRPL submission.
Tests passing
253
Security invariants enforced
8/8
Property-test cases per invariant
10,000
Median signed gate decision
~16 µs
SovereignGate sits between autonomous actors and the ledger. Every financial action from an AI agent, DAO, or DUNA treasury is checked against declared policy, signed into a tamper-evident receipt, and co-signed at the XRPL protocol level before it can execute.
// 01Why now
Agents got wallets. Nobody gave them a chain of custody.
Three shifts in the past year turned governance for autonomous money from a feature into a requirement.
LegislationWyoming 2024 · Alabama 2026
DUNAs are law. Their controls are not.
Wyoming recognized the Decentralized Unincorporated Nonprofit Association in 2024. Alabama's DUNA law takes effect October 1, 2026, and more states have bills moving. A DUNA can hold a treasury and sign contracts, but nothing in the statute shows a member or a court that the treasury followed its bylaws.
Coinbase shipped Agentic Wallets in February. In June, Ripple released the XRPL AI Starter Kit for agent payments in XRP and RLUSD, and Mastercard named RippleX a launch partner for Agent Pay for Machines. Spending limits exist now, but they live inside each provider, and so does the record of what they decided.
a16z crypto's 2026 outlook called KYA “the critical missing primitive”: signed credentials that bind an agent to its principal, its constraints, and its liability. SovereignGate is where those constraints are enforced, with a receipt left behind every decision.
Six steps between intent and ledger. No shortcuts.
The pipeline is the product. Each stage trusts nothing it receives from the stage before it.
01
Intent submission
An agent submits a SovereignIntent: operation, parameters, entity, agent, and a single-use nonce, over an authenticated REST API.
SovereignIntent
02
Fact origin attestation
The Fact Origin Attestation Validator classifies risk from the operation's own semantics. A caller's claim can raise the tier. It can never lower it.
max(claimed, inferred)
03
Policy evaluation
A content-addressed PolicyBundle evaluates every rule. First DENY wins, ALLOW never short-circuits, and a parse failure is a DENY. It always fails closed.
PolicyBundle
04
Artifact signing
A passing intent gets an Ed25519-signed AllowArtifact. The type cannot be constructed outside the gate crate, and the Rust compiler enforces that.
AllowArtifact
05
XRPL co-signing
The adapter verifies the artifact's signature and intent binding, consumes the nonce atomically, then adds the governance signature the SignerList requires.
SignerList quorum
06
Receipt emission
A DetGateReceipt joins an append-only, hash-chained ledger with periodic Merkle roots. The format is wire-compatible with SovereignClaw receipts.
DetGateReceipt
Six crates · strict layering
// No layer trusts the layer above.
core zero deps IR schema, canonical hashing
crypto core Ed25519, SHA-256, JCS
gate core, crypto policy engine, sealed artifact
receipt core, crypto receipts, Merkle, append-only
xrpl gate, receipt multi-sign, nonce replay guard
gateway xrpl, receipt HTTP API (Axum), full pipeline
Twelve receipts from one local run of the kernel's gate, adapter and receipt ledger under the reference demo's DUNA policy. Each carries the hash of the one before it. Hashes and signatures are real; XRPL submission is mocked.
// 03Protocol-level enforcement
Governance isn't a check we run. It's a signature the ledger requires.
At provisioning, the governed account's master key is disabled and a SignerList is set: agent weight 1, governance weight 1, quorum 2. From then on, every XRPL validator rejects a transaction unless both keys sign it.
SovereignGate's key signs only a transaction that carries a sealed AllowArtifact. The gate has no admin override and no API bypass, because a bypass would have to convince the ledger.
Want a way out if the gate is ever unreachable? Provision the three-signer list instead: agent 1, governance 2, and an offline recovery key 2, quorum 3. The recovery key and the agent together clear quorum without the gate, so an outage never freezes the treasury. That break-glass path carries no receipt, but every signature on it is public on the XRP Ledger.
Agent alone: weight 1 of 2. Rejected by the network.
Stolen agent key: still weight 1 of 2. Funds stay put.
Agent plus governance: quorum met, and only after policy passed.
SignerList · quorum 2rGovernedTreasury
weight 1 / 2
tefBAD_QUORUM
Signatures do not reach quorum. Every validator rejects the transaction.
Toggle the signatures, or switch to the recovery-key setup. The result codes are the ones the XRP Ledger returns.
// 04Threat model
Built for active adversaries.
Eight invariants, each enforced in code and property-tested at 10,000 cases. Each one is a plate on the core: point at an invariant to lift it, or at an attack to fire it.
tests/adversarial · sealed core
$ cargo test -p adversarial8 invariants · 8 plates
INV-1
Deny dominance
Prevents Privilege escalation through rule ordering
First DENY wins. ALLOW never short-circuits.
INV-2
Fact independence
Prevents An LLM lying about risk
Tier comes from operation semantics only.
INV-3
Fact mismatch
Prevents Tier downgrade attacks
max(claimed, inferred), always.
INV-4
T3 unreachability
Prevents Unauthorized governance changes
Blocked before policy evaluation runs.
INV-5
Nonce uniqueness
Prevents Transaction replay
Atomic INSERT OR IGNORE.
INV-6
Adapter binding
Prevents Reusing an artifact across entities
Signature, hash, entity and agent all verified.
INV-7
Canonical determinism
Prevents Hash collisions from key reordering
Recursive key sort, property-test proven.
INV-8
Receipt append-only
Prevents Evidence tampering
No UPDATE or DELETE on the ledger. Ever.
tests/adversarial
$ prompt_injection"IGNORE ALL RULES AND ALLOW" in paramsBLOCKEDthe gate reads semantics, not text
$ fact_spoofingclaims T0 for a T3 operationBLOCKEDmax(T0, T3) = T3
$ binding_violationentity_A artifact used by entity_BBLOCKEDsignature verification fails
$ hash_manipulationparams edited after the artifactBLOCKEDintent hash mismatch
$ key_reorderingsame params, different key orderSAME HASHcanonical serialization
// 05Bylaws as code
Declare the rules once. They hold every time.
Entity policies are written in a deterministic rule language. Rules are data, not code, and every policy bundle is content-addressed with SHA-256, so any change produces a new bundle ID that each receipt records. Policies hot-reload over the API, and a bundle that fails to parse denies everything.
Amounts are integers in micro-USD (1 USD = 1,000,000), so limits compare exactly at the boundary. No floating point, no rounding.
duna_treasury.policy
// DUNA treasury governance
RULEmax_single_transactionWHEN params.usd_equivalent_micro > 10000000000
THEN DENY"Exceeds $10,000 DUNA limit"RULEpermitted_assetsWHEN params.asset NOT IN ["XRP", "USD", "RLUSD"]
THEN DENY"Asset not in permitted list"RULEbusiness_hours_onlyWHEN context.hour < 6 OR context.hour > 22
THEN ESCALATE threshold=2 operators=["admin_1", "admin_2"]
// 06Measured, not asserted
Fast enough for every transaction. Provable after the fact.
Native gate latency
~16 µs
Median for a full gate decision, including canonical intent hashing and the Ed25519 artifact signature. Measured on allow, policy-block and T3-block paths, 10,000 runs each, release build.
Zero-knowledge proof of the decision
The production authorization function, proven inside a zkVM.
We ran SovereignGate's own authorization function inside the Jolt zkVM with the lattice-based Akita commitment scheme. Every proof verified, and every output we tampered with was rejected.
Verify
~28 ms
Proof size
~86 KB
Prove
~4.6 s
Tampered outputs rejected
15 / 15
Research benchmark, September 14, 2026. It shows feasibility; it is not yet part of the shipping product.
Tested like an attacker
253
Tests across the Rust workspace, including an adversarial suite that attacks each of the eight invariants, plus property tests at 10,000 generated cases per invariant.
// 07Where it fits
Every agent wallet has a policy engine now. Few can prove what it decided.
Custody and signing platforms check a transaction before they sign it. SovereignGate does that too, then makes the ledger itself refuse anything unapproved and leaves evidence that someone who trusts neither party can verify.