PINCR · RECOVERY-CONDITIONED AUTHORIZATION

Autonomous systemsneed a way back.

Software will increasingly operate software. Production needs an authority model built for that future.

Before an AI agent receives permission to change production, Recoverability Firewall proves that the exact proposed change is recoverable from the current state. If it cannot prove it, authority never exists.

Most systems ask who is this agent? RF asks has this exact action proven a way back?

Revision 6 candidate · PostgreSQL · ready for partner-owned staging

RF / AUTHORITY BOUNDARYLIVE MODEL
AI proposesRF provesDatabase decides
01proposal.boundPASS
02recovery.provenPASS
03live.stateMATCH
04authority.single_useREADY
DECISIONExecute exact stored SQL oncePERMIT
AGENT CREDENTIAL NONEUNSAFE AUTHORITY REFUSED
PROBLEM / AUTONOMOUS CHANGE OUTRUNS HUMAN REVIEWPRIMITIVE / PROOF BEFORE AUTHORITYWEDGE / TRANSACTIONAL POSTGRESQL

01 / INVESTMENT THESIS

A new control layer for autonomous production.

AI is increasing the speed and autonomy of production change. Identity and policy can decide who may ask. PINCR is building the layer that decides whether the exact action has earned the authority to execute.

01The market shift

Agents remove the reader.

Production controls were designed around a human eventually reviewing the plan. Autonomous execution breaks that assumption.

02The primitive

Proof before authority.

RF makes demonstrated recovery—not model confidence—the condition that creates temporary authority.

03The wedge

Transactional PostgreSQL.

Start where state, rollback, and production consequences are concrete enough to make the protocol testable and enforceable.

02 / CONTROL GAP

The production control gap

The reader is disappearing.

Existing production controls assume a human eventually reads the diff, inspects the plan, and notices what is wrong. Autonomous systems do not merely create more changes. They remove the reader.

Traditional control

Is this actor allowed?

Identity, role, policy, and review decide whether a request may proceed.

Recovery-conditioned control

Has the way back been proven?

The exact action must demonstrate recovery against the state it is about to modify.

03 / THE FUTURE WITH RF

Autonomy without blind trust

Production can become more autonomous without becoming less accountable.

In the future PINCR is building toward, a human, CI system, or AI agent may propose a consequential action. But the protected resource grants authority only after the exact action has produced evidence of recovery—and only while the live state still matches that evidence.

PINCR / NORTH STARRecoverability becomes a prerequisite for production authority.
01From standing trust

No permanent authority for autonomous actors.

Agents propose actions, but do not carry reusable production credentials through the governed path.

02To earned authority

Every consequential action presents evidence.

Recovery is rehearsed, independently verified, and bound to the exact action and current state.

03At machine speed

The resource decides—not the agent.

Authority exists once, briefly, and only while reality still matches the proof. Drift destroys permission.

THE HUMAN ROLE

Humans do not disappear. They move up a level: defining policy, acceptable recovery tiers, protected scope, and escalation. RF makes those boundaries enforceable for individual actions at machine speed.

The expansion is deliberately conditional: PINCR will enter new resource domains only where recovery can be meaningfully rehearsed, evidence can be bound to live state, and the resource can enforce the decision.

Proof before authority

Evidence becomes authority.

RF does not ask an AI model to predict whether a change is safe. It creates a deterministic path from tested recovery evidence to temporary, state-bound, single-use authority.

01Propose

Bind the exact action.

An agent, CI system, deploy tool, or engineer submits the precise forward change and recovery path.

02Rehearse

Prove the way back.

RF executes both paths against a controlled shadow and measures what recovery actually restores.

03Verify

Turn evidence into authority.

An independent verifier attests a permit bound to the SQL, state, resources, identity, policy, and expiry.

04Enforce

Execute once—or refuse.

The database locks the governed closure, rechecks reality, and atomically executes and consumes the permit.

Model confidence is provenance.

Recovery evidence is authority.

Current technical evidence

Built to fail closed.

The current candidate is reproducible from source and package, with live PostgreSQL verification, hostile-schedule exploration, scale tests, and adversarial authority demonstrations.

373 + 14

Live tests

Repository-owned PostgreSQL tests and adversarial subtests, with zero skips in the current release record.

0 / 512

False authorizations

Across the bounded hostile-schedule model for the shipped journal checkpoint protocol.

0 / 100K

Leaked markers

Across 100,000 distinct savepoint mutations in the current rollback-isolation benchmark.

10M

Rows exercised

A current real-PostgreSQL run with the expensive proof work kept outside RF’s final execution-lock window.

EXTERNAL SIGNAL

RF surfaced genuine defects in old Mattermost rollback migrations; a maintainer confirmed and patched them. Mattermost is evidence of the problem—not a customer or design partner.

These are repository-owned results. Partner-network performance, workload SLOs, and production acceptance remain open gates.

Real PostgreSQL · 10,000,000 rows

The proof was expensive. The final lock was not.

Revision 6 moves the full exact-data digest outside the final execution lock. A real 10M-row run shows the difference between doing the proof and enforcing the decision.

3m 58.3sFull 10M harness sweep

End-to-end benchmark wall clock, including database and kernel setup, 10M-row generation, fingerprints, signed permit issuance, independent verifier attestation, and schema/exact-data apply lanes.

01 / PROVE40.18s

Exact-data digest

One isolated observation, performed outside RF’s final execution lock.

02 / ISSUE51.58s

Live binding issuance

Median of two permits; includes production binding, signing, and verifier attestation.

03 / EXECUTE31.58ms

Resident apply

Permit validation, exact stored SQL, post-check, atomic consumption, and round trip.

04 / LOCK PROXY15.23ms

RF final window

Consumption timestamp through kernel result; uncontended and excluding commit tail.

RUN / 20260805T051035Z

PostgreSQL 16.14 · kernel revision 6 · fsync on · 128MB shared buffers

Human report ↗Raw JSON ↗Checksums ↗

One warm-buffer, uncontended local observation—not a tail-latency estimate, concurrent-load test, partner SLO, or production-readiness claim.

A precise security boundary

Strong claims require clear limits.

RF governs a narrow authority path. It does not claim that every migration is good, every shadow is perfect, or every external effect can be reversed.

Request the protocol and security model

What RF guarantees

  • The executor cannot substitute different SQL.
  • State drift invalidates the authority to act.
  • Permits are signed, state-bound, expiring, and single-use.
  • Execution, post-check, and consumption commit atomically.

What remains outside

  • PostgreSQL is the first shipped enforcement domain.
  • Opaque and non-transactional operations are refused.
  • External effects—HTTP, queues, files, and email—remain outside the database proof boundary.
  • This is a verified staging candidate, not broad production certification.

The company behind the wedge

Start narrow. Become infrastructure.

PostgreSQL is where PINCR proves the protocol. The company thesis is larger: autonomous systems need resource-local, evidence-bound authority wherever production state can be damaged.

01 · SHIPPED CANDIDATE

PostgreSQL migrations

Exact visible SQL, deterministic rehearsal, signed permits, and database-local enforcement.

02 · PRODUCT EXPANSION

Database change authority

Broader adapters, operational workflows, policy surfaces, and partner-owned production evidence.

03 · COMPANY DIRECTION

Autonomous production

A common authorization layer for systems that must prove recoverability before they receive authority to act.

WHY NOW

Agent autonomy is rising faster than human review capacity.

WHY PINCR

The product enforces at the resource, not in an advisory dashboard.

NEXT VALUE INFLECTION

Partner-owned staging, then one bounded production lane.

The next gate is external

One design partner. The right early investors.

PINCR is opening two conversations: one technically rigorous design partner for a bounded PostgreSQL staging evaluation, and early infrastructure investors who understand why autonomous production requires a new authority boundary.

Working revision-6 candidatePartner-controlled stagingProtocol-level company thesisFounder-led technical diligence
Start a founder conversation Design partners · infrastructure investors · security and database operators