Govern the consequence, not the prompt

TrustRail does not claim to identify every malicious instruction. It carries untrusted influence into the authorization decision and makes consequential action harder when the context is attacker-reachable or missing.

Influence becomes a policy fact

Sources

Declare attacker-reachable context

Email, web, documents, MCP tool output, and A2A messages are represented by source type, ingestion time, and digest—not retained content.

Fields

Show what the context touched

Tainted JSON pointers tell an approver whether the untrusted source reached the recipient, amount, ref, environment, or another consequential field.

Invariant

Influence only tightens

The engine evaluates influence-dependent policy twice and suppresses any outcome where caller-supplied influence would have widened authority.

Intent

Trace the initiating authority

Human, schedule, and upstream-agent origins are digest-bound. Selected financial and privileged actions fail closed without a traceable human intent id.

The limitation is part of the control

The influence manifest is supplied by the agent and a compromised agent can lie about it. Missing or malformed influence is therefore treated conservatively for consequential actions, and influence can never be the reason an action becomes allowed. Runtime isolation, credential custody, egress enforcement, and human review remain separate controls.