AI 中文总结
本文提出Brain API,一个面向策略治理智能体系统的意图感知控制平面,通过决策工件实现意图到执行计划的可审计映射,并在外部策略语料库上验证了其有效性。
AI 中文摘要
当代云和分布式系统通过资源中心的抽象来暴露控制:服务、部署、网络流、执行图。与此同时,智能体系统和工具增强系统已将应用逻辑转向意图驱动、自适应执行。现有的控制平面、工作流引擎和服务网格缺乏意图级决策治理的抽象:它们不能将高层目标表示为一等控制对象,不能对从意图到执行计划的映射实施策略,也不能产生关于为何选择某条执行路径而非其他替代方案的可审计记录。因此,控制逻辑被嵌入应用代码中,使系统变得脆弱、不透明且难以治理。我们提出Brain API,一个用于策略治理的智能体系统的意图感知控制平面。其核心贡献是决策工件:一个持久化、版本化、可审计的记录,记录意图如何成为可执行计划,捕获了哪些策略被应用、哪些能力被评估、哪些替代方案被拒绝以及原因。一个激励用例是智能体数据集:在驻留、合规和成本约束下作为策略治理能力参与的数据集。我们针对两个非我们编写的策略语料库评估了决策层的原型。在OPA Gatekeeper约束库上,它在42个可编码案例中的42个与库自身发布的裁决一致,其中19个允许,23个拒绝。在Cedar示例策略上,通过与其参考实现的差分测试进行标记,一个故意不相似的领域暴露了我们模型中的三个缺陷,包括一个默认允许假设,该假设会反转每个授权策略。评估涵盖策略过滤和选择;上下文信号和排序仍是设计声明,负载下的决策延迟未量化。
英文摘要
Contemporary cloud and distributed systems expose control through resource-centric abstractions: services, deployments, network flows, execution graphs. Agentic and tool-augmented systems have meanwhile shifted application logic toward intent-driven, adaptive execution. Existing control planes, workflow engines and service meshes lack abstractions for intent-level decision governance: they cannot represent high-level goals as first-class control objects, cannot enforce policy over the mapping from intent to execution plan, and cannot produce auditable records of why one execution path was chosen over its alternatives. Control logic is therefore embedded in application code, leaving systems brittle, opaque and hard to govern. We propose Brain API, an intent-aware control plane for policy-governed agentic systems. Its central contribution is the decision artifact: a durable, versioned, auditable record of how an intent became an executable plan, capturing which policies applied, which capabilities were evaluated, which alternatives were rejected, and why. A motivating use case is agentic datasets: datasets participating as policy-governed capabilities under residency, compliance and cost constraints. We evaluate a prototype of the decision layer against two external policy corpora we did not author. On the OPA Gatekeeper constraint library it agrees with the library's own published verdicts on 42 of 42 encodable cases, 19 admit and 23 deny. On Cedar example policies, labeled by differential testing against its reference implementation, a deliberately dissimilar domain exposed three defects in our model, including a default-allow assumption that would have inverted every authorization policy. The evaluation covers policy filtering and selection; candidate generation, context signals, ranking and plan synthesis are not measured, nor is decision latency under load.
Comments32 pages, 6 figures. Prototype evaluated against two external policy corpora: the OPA Gatekeeper constraint library and Cedar's published example policies. v2: adds figures; results unchanged