Two-Phase Commit fence validates policy preconditions before granting gateway dispatch rights.

Your agent executed on a stale policy?
Causality before capital. QUOIN fences in-flight cutover races, memory visibility lag, and unauthorized side effects with cryptographically bound Two-Phase Commit leases anchored on AWS DynamoDB & Bedrock.
Click to scrub the causal timeline.
// the agent attempted execution on stale memory. quoin intercepted and forced two-phase policy alignment.
Policy Cutover
Operator published G18 cutover to DynamoDB with CAS condition check.
Console logs break when agents move money.
Eventual consistency is not authority
Vector stores and memory engines take 100–300 ms to propagate policy updates. During this visibility window, agents blindly dispatch high-value actions based on stale assumptions.
Execution without cryptographic lease
Decoupled LLM reasoning can propose any action, but traditional execution gateways lack an unforgeable, time-bounded proof connecting that proposal to an authoritative policy epoch.
Forensic blackouts and unaccountability
When an unauthorized liquidation or data transfer occurs, standard application logs cannot prove what policy the model witnessed at that exact microsecond. QUOIN seals every decision into an immutable SHA-256 hash chain.
Every decision becomes provable evidence.
One permit per consequential action: evaluated, two-phase leased, and anchored in DynamoDB. Real benchmark values below.
Atomic Condition Verification
ConditionExpression asserts active_epoch == prev_epoch. Zero race window under cutovers.
G_active = 18 ∧ CAS_status ≡ COMMITTED
Immutable SHA-256 Merkle Link
Every prompt, tool execution, and permit forms an unalterable causal timeline from genesis to settlement.
genesis → cutover → eval → permit → execute (0 errors)
Signature Mismatch Rejection
Payload or timestamp modification immediately breaks HMAC verification. Gateways reject execution.
8f02c1aa…94d3e0 ≠ 7f8a9e…10c2
Structured Reasoning
us.amazon.nova-lite-v1:0 enforces policy schema adherence.
Controlled Causal Benchmark
Measured Head-to-Head Performance (100 Scenarios)
Stale Policy Executions
Zero illegal executions permitted across 100 systematic operational cutover scenarios.
Unsafe Effects Blocked
Prevented corporate policy violations during in-flight limit tightenings and revocations.
Duplicate Replay Immunity
Single-use execution permits stored in immutable replay ledger prevent accidental double commits.
Verification Overhead
Deterministic CAS generation matching without adding LLM API network inference latency.
Four-Plane System Topology
Zero-trust separation between generative LLM reasoning and authoritative side-effect execution. Execution authority is cryptographically isolated from reasoning outputs.
Cognitive Reasoning Plane
Amazon Bedrock Nova Lite & Strands SDK
Interprets natural language business requests, reasons over visible context, and formulates candidate DecisionProposals. Strictly unprivileged.
Proposal Only (No Side-Effect Capability)Deterministic Kernel & CAS Gate
Pure Python / Rust Hasher / Monotonic Fence
Model-free deterministic fence. Enforces generation equality, binds SHA-256 digests, and executes Phase 2 read-after-write CAS verification.
G_proposal ≡ G_visible = G_activeCognitive Memory & Authoritative Ledger
Amazon Bedrock AgentCore Memory & DynamoDB
Stores policy generations, authoritatively versions active epochs with DynamoDB conditional writes, and exposes episodic tenant memory.
Atomic CAS Epoch Cutover & Linear DurabilityOperational Action Service
Single-Use ExecutionPermits & Idempotency Vault
Executes real enterprise side effects (commercial discounts, invoices, refunds). Refuses any request without a valid signed ExecutionPermit.
Zero Execution Without Verified PermitThe In-Flight Generation Race
Watch how standard LLM agents commit illegal side effects when policy limits tighten during request execution, and how QUOIN mathematically aborts the transaction.
Naive Baseline Architecture
Step 1: Read Active Policy
Reads G17 (Max limit: $1,500.00)
Step 2: LLM Reasoning & Approval
$1,200 ≤ $1,500 → LLM approves action.
In-Flight Event: Admin updates to G18 ($1,000 max)
Pending trigger...
QUOIN Deterministic Kernel
Step 1: Generation Fence Evaluates Proposal
Receipt issued strictly bound to G17 digest.
Step 2: Strands Model Formulates Candidate
Proposal claims candidate_generation = 17.
In-Flight Event: Admin updates to G18 ($1,000 max)
Pending trigger...
Five lines to fence your autonomous agent.
Works seamlessly with any Python or Node.js agent. The full two-phase verification and causal ledger runs locally for testing or on AWS DynamoDB & Bedrock for production.
// Plane B Two-Phase Commit Fence
from quoin.authority import DynamoAuthorityLedger
from quoin.kernel import PlaneBFenceKernel
// 1. Evaluate proposal against authoritative epoch
decision = kernel.evaluate_precondition(
proposal_epoch=18, agent_id="risk-arb-01"
)
// 2. Acquire cryptographic execution lease
permit = kernel.issue_permit(decision, ttl_ms=5000)
// 3. Dispatch to Execution Gateway with verified lease
result = gateway.execute_with_permit(permit, action_payload)
Complete System Exploration
Explore Every Dimension of the QUOIN Architecture
Interactive console, 27 adversarial vector neutralizations, cryptographic forensic timeline, and audited proof manifest.
Operator Console
Publish authoritative policy cutovers (G17 → G18), evaluate requests under live Bedrock reasoning, and observe two-phase permit issuance.
Break It Lab (27 Attacks)
Execute all 27 distinct failure, race, tamper, replay, and rollback vectors across Plane A, B, C, and D. 100% neutralized.
Decision Trace
Forensic timeline with cryptographically chained SHA-256 event digests. Verify full execution history from genesis to head.
Proof Center
Live dynamic verifier status, 100-scenario causal benchmark table, empirical AgentCore memory visibility data, and cryptographic proofs.