Actor Governance
Rivaro governs agents and users (actors) based on their cumulative behavior over time — not just individual requests. Trust scores, automatic escalation, and a tamper-evident audit trail give you continuous control over every actor in your AI estate.
Where to find it in the app
Actor governance shows up in three places in the app:
| Surface | Where | What you do here |
|---|---|---|
| Org-wide policy | Dashboard → Policies & Authority → GOVERNANCE stage tab | Set thresholds, presets, automatic-action toggles for the whole organization |
| Per–app-context policy | Dashboard → Policies & Authority → select an App Context → Governance Policy tab | Override governance thresholds for a single AppContext (agent / integration) |
| Per-agent actions | Dashboard → Agent Registry → click an agent → ⋮ Actions menu | Manually quarantine, terminate, or reactivate an agent; History tab shows the audit trail |
The Command Center dashboard and Executive View → Board both surface actors-at-risk and quarantine counts at a glance — both deep-link into the Agent Registry filtered to the relevant status.
Zero Trust Model
Rivaro starts every actor at a trust score of 0. Trust is never assumed — it must be earned through approved identity and clean behavior. The maximum trust any actor can reach is determined by their identity strength.
Trust Score
Every actor has a trust score between 0 and 100. It is dynamic — it changes in real time as the actor behaves. You can see the current trust score next to each agent in the Registry and inside the agent detail drawer.
How trust is earned
| Event | Effect on trust |
|---|---|
| Admin approves the agent | Initial grant |
| Clean interaction (ALLOW decision) | Incremental gain |
| Behavioral stability — cold start | Reduced earn rate until the actor has a track record |
| Attack chain pattern detected | No trust gain |
Trust ceilings by identity strength
An actor can never earn more trust than its identity strength allows. An unregistered actor seen only in traffic stays near the bottom of the range no matter how well it behaves; only an approved agent bound to a verified user identity can reach the top. This is the zero-trust property: autonomy follows verified identity, not good behavior alone.
| Identity strength | Trust ceiling |
|---|---|
| BASIC (unknown/unregistered) | Lowest |
| STANDARD (registered, no approved assets) | Low |
| VERIFIED (registered + approved asset) | High |
| STRONG (approved asset + verified user binding) | Highest |
How trust degrades
| Event | Effect on trust |
|---|---|
| Policy violation detected | Incremental loss per violation |
| TERMINATE action | Trust drops to 0 |
Passive trust restoration over time is available but disabled by default. When enabled, an actor recovers slowly toward its identity ceiling during clean operation. Toggle it on in Policies & Authority → GOVERNANCE.
Risk Score
For each enforcement decision, Rivaro computes a risk score (0–100) from four components:
| Component | What it reflects |
|---|---|
| Signal risk | Severity of the detections that fired on this request |
| Violation risk | The actor's accumulated violation history |
| Trust risk | How far the actor's current trust sits below full trust |
| Session risk | Session-level aggravators — credential access, sensitive data heading outbound, unusual event volume |
Recent violations weigh more heavily than old ones, so an actor that misbehaves twice in an hour escalates faster than one with the same count spread over a month.
Risk levels
| Risk level | What triggers it | Posture |
|---|---|---|
| MINIMAL | Normal operation | No action |
| ELEVATED | Risk score or violation count crosses the warn threshold | Increased monitoring |
| HIGH | Sustained elevated risk, or trust below the high-risk threshold | Rate limiting |
| CRITICAL | Risk score or trust crosses the critical threshold | Quarantine or termination |
All thresholds are configurable per organization and per AppContext.
Automatic Escalation
When risk levels climb, Rivaro automatically applies progressively stricter actions. Each tier is individually configurable from Policies & Authority → GOVERNANCE.
| Risk level | Automatic action | What happens |
|---|---|---|
| MINIMAL | — | Normal operation, no action |
| ELEVATED | WARN | Violation logged with elevated visibility in the dashboard |
| HIGH | RATE_LIMIT | Actor throttled to a configured request rate |
| CRITICAL | QUARANTINE | All requests blocked; actor moves to QUARANTINED status |
| CRITICAL + repeat | TERMINATE | Actor permanently blocked (requires admin reactivation) |
Rivaro ships with default quarantine and termination thresholds tuned for production use. To change them, open Policies & Authority → GOVERNANCE and edit the threshold fields. To override them for a single AppContext, open the AppContext under Policies & Authority and use its Governance Policy tab.
Governance Presets
Three preset governance configurations ship out of the box and are selectable from the GOVERNANCE tab:
| Preset | Description |
|---|---|
| LENIENT | Higher thresholds, slower escalation — suitable for development environments or low-risk internal tooling |
| DEFAULT | Balanced — the defaults described above |
| STRICT | Lower thresholds, faster escalation — recommended for production agents handling sensitive data |
Selecting a preset writes its values into the threshold fields, which you can then fine-tune.
Quarantine
When an actor is quarantined (automatically or manually):
- All proxy requests return 403 immediately.
- The actor's status in the Agent Registry changes to QUARANTINED. Filter the Registry by this status to see your queue.
- An admin must review and either Reactivate or Terminate the actor from the agent's ⋮ Actions menu.
- On reactivate: the violation clock resets and trust score begins recovering.
Time-aware violation counting
When an admin reactivates a quarantined actor, the violation clock resets. Subsequent escalation triggers are based on violations since the last reactivation, not lifetime totals — preventing reactivated actors from being immediately re-quarantined.
Termination
When an actor is terminated:
- All proxy requests are permanently blocked
- Trust score drops to 0
- The actor cannot be reactivated through normal flows — an admin must explicitly use the Reactivate action from the agent's ⋮ menu
- This is reserved for severe, repeated, or malicious policy violations
Manual Actions
Administrators can manually quarantine, terminate, or reactivate any actor regardless of their current risk level. All three actions live on the ⋮ Actions menu inside the agent detail drawer in the Agent Registry.
| Action | Where in the UI | When to use |
|---|---|---|
| Quarantine | Agent Registry → click agent → ⋮ menu → Quarantine | Suspicious behavior, credential probing, urgent containment |
| Terminate | Agent Registry → click agent → ⋮ menu → Terminate | Confirmed malicious or repeated post-warning violations |
| Reactivate | Agent Registry → filter QUARANTINED → click agent → ⋮ menu → Reactivate | Investigation cleared the actor; or filter TERMINATED for terminated actors |
Each action prompts for a reason before applying — that reason becomes part of the immutable governance history.
Governance History
Every governance decision — automatic or manual — is recorded in a tamper-evident audit trail. Each record is cryptographically chained to the previous one (using content hashes) so the history cannot be altered retroactively.
View the history per agent on the agent detail drawer's History tab. Org-wide governance history feeds the Compliance Reporting framework reports.
What's recorded
| Field | Description |
|---|---|
action | ALLOW, WARN, RATE_LIMIT, QUARANTINE, TERMINATE, or OBSERVE |
reason | Human-readable decision rationale |
riskLevel / riskScore | Risk assessment at time of decision |
actorTrustBefore | Trust score before this decision |
actorViolationsBefore | Violation count before this decision |
actorStatusBefore / actorStatusAfter | Status change |
decidedAt | Exact timestamp of decision |
signalType / signalSeverity | The detection that triggered this decision |
overridden | Whether an admin manually overrode this decision |
contentHash / previousRecordHash | Cryptographic chain-of-custody hashes |
Disabling Automatic Actions
Automatic quarantine and termination can be disabled per organization from Policies & Authority → GOVERNANCE. When disabled, Rivaro still calculates risk scores and trust scores and surfaces warnings in the dashboard — but takes no automatic blocking action. Useful during initial rollout or for non-production environments.
Next steps
- Agent Management — Agent profiles, ownership, and identity strength
- Sessions — How session context feeds into risk scoring
- Enforcement & Policies — Per-request policy enforcement
- Compliance Reporting — Use governance history in compliance reports