ENSv2 · Chainlink CRE · Bazantic · Autonomous Authority

Give AI workers a job.Not the keys to everything.

LATCH establishes verifiable identity on ENSv2, enforces private organizational policy via confidential computing, and provides fail-closed authority before autonomous agents can touch real services.

ENSv2
Onchain Identity
Chainlink CRE
Confidential TEE
Fail-Closed
Decision Model
Bazantic
Controlled Execution
LATCHSepolia
Console
AI Workers
Activity Log
Integrations
indexer live · Sepolia ENSv2
Live agent proposalsSTREAM
  • ACT-0082$4,200.00

    procurement.acme.eth · 20 Monitors

    APPROVEDTEE Verified
  • ACT-0081$12,500.00

    research.acme.eth · Restricted Domain Search

    POLICY_DENIEDExceeds Limit
  • ACT-0080

    ops.acme.eth · Cloud Server Spinup

    REVOKED_IDENTITYENS Stopped
ACT-0082 · Procurement Action

Confidential Policy Evaluation

✓ Authorized by TEE
Identity
ENS VERIFIED
Spend Amount
$4,200.00
CRE Verdict
APPROVED
latch/policy-evaluator.tsConfidential TEE
// TEE evaluates policy secrets without leaking limits
const policy = await runtime.getSecret("procurement_policy");
const decision = evaluatePolicy(action, policy);
✓ Verdict: APPROVED · Passed to Bazantic Recipe

Execute authorized task

Releases capability to Bazantic external gateway

Dispatched
procurement.acme.eth·proposed·20 Monitors·APPROVED
research.acme.eth·proposed·Restricted Domain Search·POLICY_DENIED
ops.acme.eth·executed·Compute Cluster·CONFIRMED
finance.acme.eth·authorized·SaaS Renewal·RECORDED
procurement.acme.eth·proposed·20 Monitors·APPROVED
research.acme.eth·proposed·Restricted Domain Search·POLICY_DENIED
ops.acme.eth·executed·Compute Cluster·CONFIRMED
finance.acme.eth·authorized·SaaS Renewal·RECORDED
How LATCH Works

Propose intent. Prove authority. Execute safely.

Tool access is not authority. LATCH ensures autonomous workers operate only within explicit company boundaries, with immutable cryptographic proofs at every step.

01

Identity Verification

ENSv2 resolves the agent wallet, organization namespace, role, and authorized capabilities from protected onchain records.

Direct onchain verification via ENSv2 Sepolia subnames.
02

Organizational Authority

LATCH validates live administrative records for every proposed action. Revoked or unregistered agents fail closed immediately.

No stale database flags. Zero bypass possible.
03

Confidential Policy

Chainlink CRE evaluates private organizational rules inside a secure TEE without exposing spend limits or vendor restrictions.

Strict sanitized APPROVED / POLICY_DENIED verdict.
04

Safe Execution

Bazantic Recipe coordinates external catalog and payment services, executing solely the exact immutable action authorized.

Guaranteed single-use replay protection.
Fail-Closed Architecture

An identity that can be trusted. Authority that can be revoked.

Organizations retain full ownership of authorization-critical ENS records. Agents cannot elevate their privileges, modify confidential rules, or reverse revocation.

AuthorizedStage 4/4

Correct Agent + Compliant Action

ENS identity active, action strictly within private spend thresholds, and capability released directly to Bazantic.

✓ Complete execution authorized
Policy BlockedStage 3/4

Verified Agent + Non-compliant Action

Agent identity is authentic on ENS, but proposed spend exceeds confidential organizational rules inside the CRE TEE.

× Stopped by confidential policy
Identity BlockedStage 1/4

Revoked or Unregistered Worker

Admin wrote revocation to ENS records. Future execution fails immediately before any policy or API call is triggered.

× Terminated at identity boundary
Establish Your Authority Boundary

Put every agent action through a verifiable decision.

Connect your organization admin wallet, configure your ENS namespace, and onboard the AI workers LATCH should protect.

Launch LATCH

Identity on ENSv2.
Confidential policy by Chainlink CRE.