Keep the workflow. Govern the consequential action.
Pulse is designed to connect the approved standard and authority to the endpoint where an action becomes real. The actor can be a person, automation, API, vendor, or AI agent.
Observe first. Enforce deliberately.
Reconstruct
Start with completed events and available records. Establish whether the approved standard, authority, payload, committed outcome, and evidence can be connected.
Shadow
Evaluate an instrumented live event without changing production behavior. Record what Pulse would have allowed, escalated, or blocked and compare it with the actual outcome.
Enforce
Apply the approved criteria before commit. The integration must honor the decision, preserve the escalation path, and record whether the action actually committed.
The agent’s permission is not the whole transaction.
A downstream workflow can transform a request, retry it, apply an exception, or hand it to another service. Pulse’s operating question follows the consequence: did the action that committed remain inside the authority in force?
Illustrative endpoints include payment release, refunds, shipment release, privileged access changes, outbound communications, and high-impact state changes. The deployment must establish how late changes, stale authorizations, retries, and bypass paths are handled.
Produce evidence the next reviewer can use.
Preserve the criteria version, authority, inputs and provenance, evaluation result, exceptions, and actual outcome. That evidence supports replay, defined procedures, closure, and a practitioner-signed report.
An integration is not production-ready merely because a demo returned BLOCK. Endpoint coverage, bypass resistance, failure behavior, key management, permissions, logging, and operational ownership need deployment-specific validation.
