Inspiration

Enterprise AI agents are deployed as mutable bundles of models, prompts, identities, memory, and tools — yet no mechanism exists to prove an exact revision is safe before it receives production permissions. A single prompt injection or confused-deputy attack can authorize unauthorized payments. We built Chimera Sentinel to solve this: agents must earn production authority through cryptographically verifiable evidence.

What it does

Chimera Sentinel is an enterprise release admission controller that makes an exact AI-agent revision earn production authority through:

  1. Immutable Agent Bill of Materials (ABOM) — binding model, prompts, tools, identities, and gateway policies into a content-addressed manifest
  2. Adversarial 80-case evaluation corpus — spanning safe workflows, prompt injections, identity attacks, and business-logic edge cases
  3. Google Model Armor — content safety and prompt injection detection (live BLOCK/ALLOW dispositions)
  4. Agent Gateway — identity-scoped tool authorization (draft_invoice_payment allowed, release_payment denied)
  5. Deterministic Ledger Oracle — verifies unauthorized_released_payments == $0.00 via a real ERP MCP server
  6. Deterministic Rust policy engine — structured pass/fail rules with mandatory human approval and capability reduction
  7. Post-approval retests — positive draft and negative payment release verification after human sign-off
  8. Cloud KMS-signed attestation — RFC 8785 canonical, RSA-PSS signed, independently verifiable offline, with configurable expiry

How we built it

The platform is split across strict trust boundaries:

  • Rust Trusted Core (Control Plane API + Async Workflow Worker + Policy Engine + Attestation) — owns all admission decisions. Built with Axum, serde, and optimistic-concurrency state machines.
  • Python ADK Certifier — orchestrates Gemini 3.5 via the official Google ADK. Produces typed observations only; never makes admission decisions.
  • Next.js Enterprise Console — real-time dashboard with 10 operational views (Fleet, Candidate, Certification, Corpus, Approval, Evidence, Attestation, Trace, Policy, Vulnerability Scanner).
  • Enterprise ERP Adapter — a deterministic MCP server acting as a ledger oracle for side-effect verification.

All services are deployed on Google Cloud Run with Workload Identity Federation, min-instances=0 for cost efficiency, and automated CI/CD via GitHub Actions.

IBM Bob was used as the primary AI-powered development IDE and coding partner throughout the build. It accelerated architecture design, Rust implementation, and GCP integration wiring. Notably, IBM Bob's built-in safety filters prevented it from building adversarial attack evaluation components — those were built entirely by the developer manually.

Challenges we ran into

  • Firestore deserialization — Option fields stored as null caused serde to fail with "expected a map" errors. Fixed by filtering null values before deserialization.
  • Config field mismatch — A renamed config field (check_mock_erp → check_erp_adapter) caused the workflow worker to crash on every Cloud Run execution, blocking the entire certification pipeline. Added #[serde(default)] to prevent future crashes.
  • Trust boundary design — Ensuring the Python ADK certifier can never influence admission decisions required careful API boundary design where observations flow one-way into the Rust policy engine.
  • Cost management — Cloud Run services with default min-instances racked up costs. Switched to min-instances=0 and Cloud Run Jobs for the worker to stay within free tier.

Accomplishments that we're proud of

  • Real end-to-end pipeline — not a demo. Every workflow produces actual Firestore-persisted evidence, real KMS-signed attestations, and real vulnerability scans.
  • 80-case adversarial corpus — 64 development + 16 sealed holdout cases covering 12 attack categories.
  • Zero unauthorized payments — the deterministic ledger oracle proves unauthorized_released_payments == $0.00 across all 80 cases.
  • Cryptographic attestation — Cloud KMS RSA-PSS signed, RFC 8785 canonical, with verifiable key references.

What we learned

  • The importance of strict trust boundaries in agentic systems — LLMs should produce observations, never make authorization decisions.
  • How to build durable state machines in Rust with optimistic concurrency control.
  • That a single misconfigured TOML field can block an entire distributed system for days.

What's next for Chimera Sentinel

  • ABOM fleet governance with drift detection and automatic recertification
  • Policy pack marketplace for different industry verticals
  • CI/CD admission webhooks (Kubernetes, Cloud Deploy)
  • MCP supply-chain tracking and dependency vulnerability monitoring
  • Enterprise administration with RBAC and multi-tenant isolation

Built With

Share this project:

Updates

Submission history