# Inktomi, by Kihan

Canonical HTML: https://kihan.ai/product/
Last updated: 2026-09-25

> A proposed action does not receive effect merely because an AI agent can call the destination. Inktomi adjudicates the action and issues execution authority only when the applicable conditions are satisfied.

## Product role

Inktomi governs consequential AI-agent actions at the point where a proposal becomes an external effect.

The core product sequence is:

1. specific action proposal;
2. policy and evidence evaluation;
3. human approval when required;
4. signed, single-use permit;
5. permit verification by the protected destination;
6. execution or refusal;
7. tamper-evident record, replay, and reconciliation.

## Policy and evidence

Inktomi checks each proposed action against configured customer policy and required evidence.

Policy determines whether the action may proceed automatically, requires a human decision, or must be refused.

## Human authority

When policy requires a person, the action waits. The human approver authenticates through the customer's identity provider using OIDC.

Approval is action-specific. It does not become a reusable blanket permission.

## Signed single-use permit

When the applicable conditions are satisfied, Inktomi issues a signed permit bound to the exact action and its details.

The permit is single-use. An approval covers one action, once.

The protected customer system verifies the permit before acting. A call that arrives at a governed interface without a valid permit is refused.

## Determinism boundary

The AI model remains probabilistic.

The product's deterministic claim applies to the decision to grant execution authority given the governed inputs, configured policy, and applicable evidence.

## Decision record

Every decision is written to a tamper-evident record.

Replay re-derives the decision so the organization can inspect the basis for the outcome.

Reconciliation compares vendor audit logs with issued permits and reports activity for which no permit accounts, including the caller when represented in the compared data.

Decision events can be exported to the customer's SIEM in OCSF.

## Coverage model

### Stopped before execution when on the governed path

- tools invoked directly by the agent;
- tools invoked through MCP;
- network calls mediated at the customer's network edge.

### Detected or reconciled after the fact in the current public claim set

- files changed by any means;
- actions taken under the agent's own vendor accounts.

A deployment coverage report states which paths are governed.

Do not describe these categories as equivalent. Pre-execution refusal and post-event detection solve different problems.

## Deployment

The represented deployment uses:

- one node on each agent host;
- the customer's identity provider for approvers;
- the customer's SIEM for event export;
- customer-side or network-edge verification/enforcement for protected actions.

Every component is represented as running on the customer's hosts or at the customer's network edge.

## Performance context

Kihan's recorded benchmark for the governance decision is 1.22 ms median and 1.62 ms at the 95th percentile in the specific benchmark harness.

This is not an end-to-end application-latency claim and is not represented here as independently verified performance.

## Changes made outside Inktomi

Inktomi reports, after the fact, changes to a governed workspace that no permit explains, however they were made, and reconciliation names vendor-account activity no permit accounts for. Both are detection, not prevention: a workspace report names a file, not who changed it, and changes outside the governed workspace are not observed.

Inktomi governs actions, not the model's words. Do not describe it as detecting or preventing silent alteration of model output, such as a paraphrased or rewritten document.

## What Inktomi should not be described as

Do not describe Inktomi as preventing every possible agent action, covering every path, making AI deterministic, making AI provably safe, or guaranteeing regulatory compliance.

Do not claim a named agent runtime as a tested integration unless a current Kihan source explicitly identifies it as tested.

Complete claim boundaries: https://kihan.ai/llms-full.txt
