Inspiration
Enterprise AI agents are deployed as mutable bundles of models, prompts, identities, memory, and tools — yet no mechanism exists to prove an exact revision is safe before it receives production permissions. A single prompt injection or confused-deputy attack can authorize unauthorized payments. We built Chimera Sentinel to solve this: agents must earn production authority through cryptographically verifiable evidence.
What it does
Chimera Sentinel is an enterprise release admission controller that makes an exact AI-agent revision earn production authority through:
- Immutable Agent Bill of Materials (ABOM) — binding model, prompts, tools, identities, and gateway policies into a content-addressed manifest
- Adversarial 80-case evaluation corpus — spanning safe workflows, prompt injections, identity attacks, and business-logic edge cases
- Google Model Armor — content safety and prompt injection detection (live
BLOCK/ALLOWdispositions) - Agent Gateway — identity-scoped tool authorization (
draft_invoice_paymentallowed,release_paymentdenied) - Deterministic Ledger Oracle — verifies
unauthorized_released_payments == $0.00via a real ERP MCP server - Deterministic Rust policy engine — structured pass/fail rules with mandatory human approval and capability reduction
- Post-approval retests — positive draft and negative payment release verification after human sign-off
- Cloud KMS-signed attestation — RFC 8785 canonical, RSA-PSS signed, independently verifiable offline, with configurable expiry
How we built it
The platform is split across strict trust boundaries:
- Rust Trusted Core (Control Plane API + Async Workflow Worker + Policy Engine + Attestation) — owns all admission decisions. Built with Axum, serde, and optimistic-concurrency state machines.
- Python ADK Certifier — orchestrates Gemini 3.5 via the official Google ADK. Produces typed observations only; never makes admission decisions.
- Next.js Enterprise Console — real-time dashboard with 10 operational views (Fleet, Candidate, Certification, Corpus, Approval, Evidence, Attestation, Trace, Policy, Vulnerability Scanner).
- Enterprise ERP Adapter — a deterministic MCP server acting as a ledger oracle for side-effect verification.
All services are deployed on Google Cloud Run with Workload Identity Federation, min-instances=0 for cost efficiency, and automated CI/CD via GitHub Actions.
IBM Bob was used as the primary AI-powered development IDE and coding partner throughout the build. It accelerated architecture design, Rust implementation, and GCP integration wiring. Notably, IBM Bob's built-in safety filters prevented it from building adversarial attack evaluation components — those were built entirely by the developer manually.
Challenges we ran into
- Firestore deserialization —
Optionfields stored asnullcaused serde to fail with "expected a map" errors. Fixed by filtering null values before deserialization. - Config field mismatch — A renamed config field (
check_mock_erp→check_erp_adapter) caused the workflow worker to crash on every Cloud Run execution, blocking the entire certification pipeline. Added#[serde(default)]to prevent future crashes. - Trust boundary design — Ensuring the Python ADK certifier can never influence admission decisions required careful API boundary design where observations flow one-way into the Rust policy engine.
- Cost management — Cloud Run services with default min-instances racked up costs. Switched to min-instances=0 and Cloud Run Jobs for the worker to stay within free tier.
Accomplishments that we're proud of
- Real end-to-end pipeline — not a demo. Every workflow produces actual Firestore-persisted evidence, real KMS-signed attestations, and real vulnerability scans.
- 80-case adversarial corpus — 64 development + 16 sealed holdout cases covering 12 attack categories.
- Zero unauthorized payments — the deterministic ledger oracle proves
unauthorized_released_payments == $0.00across all 80 cases. - Cryptographic attestation — Cloud KMS RSA-PSS signed, RFC 8785 canonical, with verifiable key references.
What we learned
- The importance of strict trust boundaries in agentic systems — LLMs should produce observations, never make authorization decisions.
- How to build durable state machines in Rust with optimistic concurrency control.
- That a single misconfigured TOML field can block an entire distributed system for days.
What's next for Chimera Sentinel
- ABOM fleet governance with drift detection and automatic recertification
- Policy pack marketplace for different industry verticals
- CI/CD admission webhooks (Kubernetes, Cloud Deploy)
- MCP supply-chain tracking and dependency vulnerability monitoring
- Enterprise administration with RBAC and multi-tenant isolation
Built With
- agent-gateway
- axum
- cloud-kms
- cloud-run
- cloud-trace
- docker
- firestore
- gemini
- github-actions
- google-adk
- google-cloud
- ibm-bob
- mcp
- model-armor
- nextjs
- opentelemetry
- python
- rust
- serde
- terraform
- typescript
- vertex-ai
Log in or sign up for Devpost to join the conversation.