Skip to main content

Actor Governance

Rivaro governs agents and users (actors) based on their cumulative behavior over time — not just individual requests. Trust scores, automatic escalation, and a tamper-evident audit trail give you continuous control over every actor in your AI estate.

Where to find it in the app​

Actor governance shows up in three places in the app:

SurfaceWhereWhat you do here
Org-wide policyDashboard → Policies & Authority → GOVERNANCE stage tabSet thresholds, presets, automatic-action toggles for the whole organization
Per–app-context policyDashboard → Policies & Authority → select an App Context → Governance Policy tabOverride governance thresholds for a single AppContext (agent / integration)
Per-agent actionsDashboard → Agent Registry → click an agent → ⋮ Actions menuManually quarantine, terminate, or reactivate an agent; History tab shows the audit trail

The Command Center dashboard and Executive View → Board both surface actors-at-risk and quarantine counts at a glance — both deep-link into the Agent Registry filtered to the relevant status.

Zero Trust Model​

Rivaro starts every actor at a trust score of 0. Trust is never assumed — it must be earned through approved identity and clean behavior. The maximum trust any actor can reach is determined by their identity strength.

Trust Score​

Every actor has a trust score between 0 and 100. It is dynamic — it changes in real time as the actor behaves. You can see the current trust score next to each agent in the Registry and inside the agent detail drawer.

How trust is earned​

EventEffect on trust
Admin approves the agentInitial grant
Clean interaction (ALLOW decision)Incremental gain
Behavioral stability — cold startReduced earn rate until the actor has a track record
Attack chain pattern detectedNo trust gain

Trust ceilings by identity strength​

An actor can never earn more trust than its identity strength allows. An unregistered actor seen only in traffic stays near the bottom of the range no matter how well it behaves; only an approved agent bound to a verified user identity can reach the top. This is the zero-trust property: autonomy follows verified identity, not good behavior alone.

Identity strengthTrust ceiling
BASIC (unknown/unregistered)Lowest
STANDARD (registered, no approved assets)Low
VERIFIED (registered + approved asset)High
STRONG (approved asset + verified user binding)Highest

How trust degrades​

EventEffect on trust
Policy violation detectedIncremental loss per violation
TERMINATE actionTrust drops to 0
note

Passive trust restoration over time is available but disabled by default. When enabled, an actor recovers slowly toward its identity ceiling during clean operation. Toggle it on in Policies & Authority → GOVERNANCE.

Risk Score​

For each enforcement decision, Rivaro computes a risk score (0–100) from four components:

ComponentWhat it reflects
Signal riskSeverity of the detections that fired on this request
Violation riskThe actor's accumulated violation history
Trust riskHow far the actor's current trust sits below full trust
Session riskSession-level aggravators — credential access, sensitive data heading outbound, unusual event volume

Recent violations weigh more heavily than old ones, so an actor that misbehaves twice in an hour escalates faster than one with the same count spread over a month.

Risk levels​

Risk levelWhat triggers itPosture
MINIMALNormal operationNo action
ELEVATEDRisk score or violation count crosses the warn thresholdIncreased monitoring
HIGHSustained elevated risk, or trust below the high-risk thresholdRate limiting
CRITICALRisk score or trust crosses the critical thresholdQuarantine or termination

All thresholds are configurable per organization and per AppContext.

Automatic Escalation​

When risk levels climb, Rivaro automatically applies progressively stricter actions. Each tier is individually configurable from Policies & Authority → GOVERNANCE.

Risk levelAutomatic actionWhat happens
MINIMAL—Normal operation, no action
ELEVATEDWARNViolation logged with elevated visibility in the dashboard
HIGHRATE_LIMITActor throttled to a configured request rate
CRITICALQUARANTINEAll requests blocked; actor moves to QUARANTINED status
CRITICAL + repeatTERMINATEActor permanently blocked (requires admin reactivation)

Rivaro ships with default quarantine and termination thresholds tuned for production use. To change them, open Policies & Authority → GOVERNANCE and edit the threshold fields. To override them for a single AppContext, open the AppContext under Policies & Authority and use its Governance Policy tab.

Governance Presets​

Three preset governance configurations ship out of the box and are selectable from the GOVERNANCE tab:

PresetDescription
LENIENTHigher thresholds, slower escalation — suitable for development environments or low-risk internal tooling
DEFAULTBalanced — the defaults described above
STRICTLower thresholds, faster escalation — recommended for production agents handling sensitive data

Selecting a preset writes its values into the threshold fields, which you can then fine-tune.

Quarantine​

When an actor is quarantined (automatically or manually):

  • All proxy requests return 403 immediately.
  • The actor's status in the Agent Registry changes to QUARANTINED. Filter the Registry by this status to see your queue.
  • An admin must review and either Reactivate or Terminate the actor from the agent's ⋮ Actions menu.
  • On reactivate: the violation clock resets and trust score begins recovering.

Time-aware violation counting​

When an admin reactivates a quarantined actor, the violation clock resets. Subsequent escalation triggers are based on violations since the last reactivation, not lifetime totals — preventing reactivated actors from being immediately re-quarantined.

Termination​

When an actor is terminated:

  • All proxy requests are permanently blocked
  • Trust score drops to 0
  • The actor cannot be reactivated through normal flows — an admin must explicitly use the Reactivate action from the agent's ⋮ menu
  • This is reserved for severe, repeated, or malicious policy violations

Manual Actions​

Administrators can manually quarantine, terminate, or reactivate any actor regardless of their current risk level. All three actions live on the ⋮ Actions menu inside the agent detail drawer in the Agent Registry.

ActionWhere in the UIWhen to use
QuarantineAgent Registry → click agent → ⋮ menu → QuarantineSuspicious behavior, credential probing, urgent containment
TerminateAgent Registry → click agent → ⋮ menu → TerminateConfirmed malicious or repeated post-warning violations
ReactivateAgent Registry → filter QUARANTINED → click agent → ⋮ menu → ReactivateInvestigation cleared the actor; or filter TERMINATED for terminated actors

Each action prompts for a reason before applying — that reason becomes part of the immutable governance history.

Governance History​

Every governance decision — automatic or manual — is recorded in a tamper-evident audit trail. Each record is cryptographically chained to the previous one (using content hashes) so the history cannot be altered retroactively.

View the history per agent on the agent detail drawer's History tab. Org-wide governance history feeds the Compliance Reporting framework reports.

What's recorded​

FieldDescription
actionALLOW, WARN, RATE_LIMIT, QUARANTINE, TERMINATE, or OBSERVE
reasonHuman-readable decision rationale
riskLevel / riskScoreRisk assessment at time of decision
actorTrustBeforeTrust score before this decision
actorViolationsBeforeViolation count before this decision
actorStatusBefore / actorStatusAfterStatus change
decidedAtExact timestamp of decision
signalType / signalSeverityThe detection that triggered this decision
overriddenWhether an admin manually overrode this decision
contentHash / previousRecordHashCryptographic chain-of-custody hashes

Disabling Automatic Actions​

Automatic quarantine and termination can be disabled per organization from Policies & Authority → GOVERNANCE. When disabled, Rivaro still calculates risk scores and trust scores and surfaces warnings in the dashboard — but takes no automatic blocking action. Useful during initial rollout or for non-production environments.

Next steps​