ZeroGate: Trust-Preserving Fast Paths for Governed AI Agent Runtimes
Separating exact-action approval from durable one-time admission, with explicit revalidation, preparation costs, and replayable evidence.
Separating exact-action approval from durable one-time admission, with explicit revalidation, preparation costs, and replayable evidence.
ZeroGate asks whether an agent's final dispatch boundary can become shorter without weakening the approval it must enforce. Inspired by the separation of preparation and passage in Suica and Sony's FeliCa, the research moves exact-action approval ahead of dispatch while keeping binding checks and one-time admission at the boundary. This is a design analogy, not a railway implementation or an affiliation with Sony or JR East.
The published research report is an arXiv preprint, not a peer-reviewed acceptance. Start with the [22-page whitebook](/assets/reports/zerogate-whitebook-2026-09.pdf) for the design narrative, or the [release article](/blog/action-pass-suica-agent-governance) for a shorter introduction.
An issuer signs a short-lived Action Pass for an exact action. Before dispatch, a trusted runtime adapter reconstructs the final action. The gate checks the pass against that action and its bound authority and context, then atomically consumes the nonce and records admission. The external operation follows; its outcome is separate evidence.
Invalid, expired, or reused passes do not authorize execution. Changed authority or missing freshness evidence requires fresh authorization, explicit review, or rejection, rather than silent reuse. A local snapshot alone cannot establish current-world freshness, and admission does not establish exactly-once remote effects.
CAVA supplies the action identity. PCAA defines authority and proof obligations. BAF supplies the bounded-approval perspective. AREG provides the wider runtime exposure context. ZeroGate explores how work in that architecture can be prepared earlier while preserving the final checks.
These are architectural relationships, not a claim that the benchmark exercised every OSuite product path. The published comparison uses a reference issuer and gate. A skill still only requests authority; neither a skill declaration nor a prepared pass can widen what runtime authorization grants.
Across 4,800 controlled Azure storage attempts, the study compared synchronous and prepared execution through the same reference issuer and gate, at concurrency 1, 8, and 32. Prepared admission-to-dispatch p95 ranged from 9.802 to 11.374 ms, versus 25.018 to 334.000 ms synchronously.
This is not an end-to-end speedup. Prepared mean complete lifecycle was longer at every tested concurrency level because it includes advance preparation and batch waiting. The result identifies where authorization cost is paid; it is not a competitor benchmark, a customer-production result, or a hosted-service SLA.
The report also separates authored semantic fixtures from controlled crash and concurrency experiments. The stated decision-preservation result depends on sound approval, complete and current policy dependencies, faithful observations, and atomic consumption. Neither a matching hash nor the implementation alone establishes all of those assumptions.
Use the unchanged version-pinned archive to reproduce the published measurements. Changes to the evaluator, cases, or runtime belong to a new experiment, not a silent replacement of the paper's evidence.
Request enterprise access and send your first governed decision today.