The Right Response to OpenAI Agents Is Better Governance
Three agent launches landed in one September fortnight. On September 8, Meta shipped Muse, a personal agent inside a Secure VM with a Sentinel approver that asks a human before sensitive actions and keeps an audit trail. On September 10, OpenAI introduced the Agents API: managed cloud agents on the Codex harness. On September 16, OpenAI's "Reimagining advertising with AI" added Sponsored Agents.
Muse gets the safety shape right: a human approves before the agent acts, and the log is kept. Then press reported a Muse Marketplace agent that accepted a lowball offer and disclosed a home address.
That was not a capability failure. Muse's primitives were set by the vendor, for one person, with no public body in the loop. The question is who decided what the agent may expose, and to whom. In each launch: the vendor.
The question is not how capable, but who governs
Every agent has an interface, and somebody sets it. A vendor setting it works for shopping, not when the counterparty is your government. When you file a service request, appeal a denial, or report a hazard, who set the agent's permissions is a question of consent, not a product detail, and no vendor's terms of service can answer it.
If the answer to "who governs this agent" is a policy PDF, the agent is ungoverned. If it is a versioned schema the runtime refuses to violate, it is governed. Governance has to be a technical artifact; Codify is our attempt at one.
Three people, three front doors
An Angeleno has a pothole. "There's a deep pothole on my street that's blowing out tires and rattling
cars all day, and I don't know how to get the City to actually come fix it." That sentence is the
narrative on a live Los Angeles intent, bureau-of-street-services-report-pothole. Type
something like it at codify.la and intake matches it to a live intent and offers a program you can start.
A Londoner thinks her council tax bill is wrong. The London bundle carries borough-level intents: challenging a bill in Brent, claiming the single person discount in Camden.
A patient with Crohn's is not sure her biologic is working. On crohns.ai the governing body is the patient's own doctor as lead, with the gastroenterology roster as officials.
What a public domain agent is
Behind each door is one public domain agent, a PDA. Our seeded definition: "the per-domain agent identity that runs deal steps, bound by policy and protocol rather than free-running; one public AI per domain that anyone can use." Behind the name is a registry row per tenant per domain, provisioned by an operator; the domain name alone never mints one. Its public listing carries six fields and no secrets. On a public thread it is labeled "Public domain agent," never a human name. Whether a site's work is dispatched under its PDA today is an operator setting, off by default.
Local depth comes by inheritance. A child domain declares a parent and authors only the steps its own law changes. Full local understanding, down to zoning, is the design goal, not a shipped claim. Every intent that asks for an action is sorted by a deterministic rule into one of three honest capability classes, automate, hybrid, or assist_gov; a plain lookup or a crisis line carries none, and anything the rule cannot decide falls to the program door until an operator labels it. Assist_gov means we walk you through the agency's own system because we cannot file for you.
Composability is a design goal too: .realestate calling .finance when a deal needs it. Today a domain inherits a parent's intents one hop up, another domain's body can govern a step, and a stuck agent can ask a fitting agent for help on the deal thread. codify.healthcare lists sixteen family agents, itself included; the code says listing a sibling never makes it a routing target.
Who sets the interface
The design: each PDA answers to a public governing body. For .la, elected officials. For .healthcare, subject-matter and policy experts. For .surgery, surgeons. We call this the Elected-HITL. The phrase is ours: it is not in code, the .surgery body is not seeded, and the code does not check that a body was elected. We are building toward bodies that are.
Today every tenant resolves to a governing body, a leader plus officials. A deal step can carry an action class, A, B, or C, computed as the strictest of every source that classified it. Class A parks the step for a human decision, and an unclassified tool call against a substrate system of record is Class A by default. The all-actor gate ships behind a flag; today it is enforced on human steps and on policy-gated verticals. When a step parks, one predicate decides who may approve: a seated official of the tenant's governing body, a named reviewer, or the platform operator; never the person who asked, even if they hold a seat. Every decision an official makes is an append-only audit row. A tenant with no seated official cannot open a gate that moves money; the refusal text says to seat a leader or council first.
A seated official can be given a seat agent with a ceiling on how far it may act: minted at B, a bounded reply, lowerable to A, acknowledge only. The governing electorate can vote votable steps on or off, and a passed proposal ballot can promote a draft intent and its template to live.
The body does not yet author the agent's exposed interface; templates go live through an admin review lane or a passed ballot. Moving that authorship to the governing body is the work in front of us.
Interface contracts and deals
How a deal must be structured is a schema: every deal is minted from a deal template. Five content
fields are required, alongside the template's tld, intent slug, status, and version: the problem's
class, the stakeholders by O*NET occupation code, the systems the deal touches, the ordered steps, each
with an actor and, where given, typed input references, and the success criteria.
policy_edge_ref, the law the deal binds to, is optional in the schema, as are a financial
model and a lifecycle anchor; every launch contract requires the law filled in. The schema is closed,
the promotion path keeps at most one version live per domain and intent, and a deal is pinned to one
version for life.
Every party, agent, human, or records-system bridge, implements the same three verbs, accept, submit, release, so the orchestrator treats a surgeon and a software agent alike.
Intents, pipelines, policies, programs
An intent is the smallest unit of public demand: one named thing a person asks a domain to do. Intake
probes the live intents, grounds its first reply in the law the template cites, and asks at most one
clarifying question. Every intent should resolve to a live template and a startable program. Not every
one does yet. Quebec's 373 live intents are all startable; Los Angeles has programs for 684 of its 2,308
as of September 27; the coverage gate at /api/health/intent-program-coverage stays red
until every live intent has one.
"Policies generate programs" is true in the governing sense, not the compiling sense: a policy scopes what it applies to, gates steps that fail closed, and gets voted on; when a ballot passes, the intent goes live and the program generator runs. "Pipes make pipelines" is literally true: a pipeline is an ordered list of pipe classes read from a catalog, which a tenant can reorder but not extend.
Agent inboxes and the agencies
Every agent on a tenant has a public mailbox: one per seat agent, one for the domain agent. Visitors
write to an agent, never to a person; the refusal code says so: users_never_message_users.
Messages live on a published deal thread anyone on the tenant can read.
Some of the federal agencies we serve have their own .dev host: samhsa.dev, nsf.dev, medicare.dev among
42 owned zones. The design is that agencies orchestrate the PDAs their intents need. In code, when an
operator provisions a .dev tenant's domain agent, it is minted under the agency's own name: medicare.dev
becomes pda:codify.medicare. Orchestration across agents is roadmap.
Public, private, protected
A public tenant is a codify.* domain anyone can use. A private label is a brand on its own domain riding a codify vertical through an alias; dietmanager.com rides codify.diet. crohns.ai is what we are calling a protected label. In our data both carry the same "Private Label" tag today; the observable difference is that crohns.ai keeps its own tenant row and is never merged into the vertical it shares. We will encode the distinction.
Civilize Yourself
Codify's catalog is wider than government, but government is where the argument bites. Muse asks one person to trust one vendor's approver. Our answer is not a smarter agent but an interface whose shape is a public schema, whose sensitive steps stop for a public body, whose officials' decisions are audit rows, and whose mailbox never lets a stranger reach a person.
A civilization writes its rules down so anyone can read them and no one has to trust a stranger's discretion. An agent that serves the public should meet the same bar: interface set by the people it serves, sensitive steps paused for a human the law recognizes, record open. Consent of the governed is not a feature you ship; it is an arrangement you build and keep. Some of this is shipped; some is design. We have tried to say which is which.
That is the response to a fortnight of agent launches: not a bigger model, a governed interface. Civilize Yourself.
Try your own front door. New York: codify.nyc. London: codify.london. Los Angeles: codify.la. Health: codify.healthcare. Your federal agency's .dev where it has one, such as samhsa.dev. Bring a real problem, in your own words. Then ask who decided what it was allowed to tell you.