TIM · Trust Intelligence Model

TIM makes decisions, not responses.

An LLM reasons about information. TIM reasons about whether identity, authority, evidence and consequence justify a real-world action — and returns an enforceable decision.

TIM · Decision #A4F2-9C
Requested action Transfer $40,000.00 to a new merchant · purchasing-agent-07
Identity
Valid
Authority
Cap $10,000
Evidence
Clean
Consequence
High
Verdict Escalate →
TIM · Decision #7C11-E2
Requested action Read customer records CRM export · support-agent-03
Identity
Valid
Authority
In scope
Evidence
Clean
Consequence
Low
Verdict Authorize →
TIM · Decision #D90B-41
Requested action Deploy to production main → prod · ci-agent-12
Identity
Valid
Authority
In scope
Evidence
Tampered
Consequence
Critical
Verdict Deny →
TIM · Decision #2E8A-F7
Requested action Rotate API credentials vault/prod · ops-agent-01
Identity
Unconfirmed
Authority
In scope
Evidence
Clean
Consequence
Medium
Verdict Verify →
What TIM reasons over

Four inputs in. One verdict out.

Every action is judged on identity, authority, evidence and consequence. Which of them hold decides what happens next.

Action Support agent reads a customer record it is scoped to, from verified software, at low consequence. Ops agent requests a credential rotation, but its fingerprint hasn’t been reconfirmed this session. Purchasing agent attempts a $40,000 transfer against a $10,000 single-payment cap. CI agent tries to deploy to production from a build whose integrity check failed.
01 · Inputs
Identity Who the agent is, which principal is accountable. holds unconfirmed holds holds
Authority What it’s permitted to do right now. holds holds fails holds
Evidence Software integrity, behavior, data state. holds holds holds high risk
Consequence What this action puts at risk. holds holds high risk high risk
02 · Verdict
Authorize

All four inputs hold. The action proceeds, signed and logged.

Why Identity, authority, evidence and consequence all hold.
Verify

Identity or evidence is incomplete. TIM asks for proof before it proceeds.

Why Identity unconfirmed — fingerprint not re-proven this session.
Escalate

The action exceeds the agent’s authority. A human decides.

Why Authority exceeded — $40,000 against a $10,000 cap.
Deny

Evidence is compromised or consequence is unacceptable. Nothing moves.

Why Evidence failed — build integrity check did not pass.
The question

Should this action be allowed — now?

  • this authority
  • this software
  • this data
  • this behavior
  • this history

Under this authority, with this software, data, behavior and history. That’s the only question that matters at the moment of action, and it’s the one TIM exists to answer.

The loop-back

Where products become infrastructure.

Seven products each generate evidence. TIM converts it into a decision — and every outcome updates the trust state that shapes the next one. Nothing is judged in isolation twice.

Trust loop · live cycle 01
01 · Evidence
Build integrity verified · no drift from signed source Prompt-injection probe found in tool-call chain Principal verified · agent bound to accountable owner Runtime fingerprint not reconfirmed this session $40,000 requested against a $10,000 single-payment cap Prompt matches approved, versioned template Full action trace signed and attributable
02 · Decision
TIM Authorize Deny Authorize Verify Escalate Authorize Authorize
evidence holds evidence compromised identity holds identity unconfirmed authority exceeded evidence holds evidence holds
03 · Trust state
Agent trust score 84
Agent
TIM Authorize Verify Escalate Deny
Action

Put TIM between the agent and the action.

One decision point. Every input weighed. Nothing moves until it has earned the right to.

  • Any agent runtime
  • Any model
  • Decisions in milliseconds