# Control the action before it runs.

Evaluate policy inputs, approval scope, execution authority and outcome evidence. A focused Rangoon software path for government and security teams.

Canonical: https://rangoon.ai/software/execution-governance/

Launch specification. Application source, downloads and versioned compatibility evidence publish with releases.

Audience: Government, platform & security teams

A capable agent still needs authority for a consequential operation. Rangoon connects the proposed action, applicable policy, approval state and execution evidence in one operating model.

Evaluation outcome: An explicit action boundary: who may do what, to which resource, under which conditions, with which recorded result.

## Operating workflow

### Define the action

Declare the principal, operation, target, data scope and expected side effects. A connector credential supplies access; it is not blanket authority for every operation.

[Review the specification](https://rangoon.ai/product/connectors/)

### Evaluate and authorize

Use LNSAT as the reference execution authority or a versioned authority adapter. OPA, Cedar and other policy engines contribute decisions through their declared contracts.

[Review the specification](https://rangoon.ai/lnsat/)

### Record and reconcile

Relate approval and execution to the exact request. Preserve receipts, denials and uncertain outcomes so an operator can reconcile what happened.

[Review the specification](https://rangoon.ai/architecture/)

## Evaluation checklist

### Where does LNSAT fit?

LNSAT is the reference authorization and evidence engine. Rangoon manages capabilities and workflow context; LNSAT binds a bounded request to authority and receipts. Another authority path must preserve its declared authorization and evidence guarantees.

### How do existing controls participate?

Identity systems identify principals; credential systems grant resource access; policy engines evaluate rules. Review these inputs separately and bind the relevant decisions to the action. A policy allow decision alone does not prove an operation executed.

### What must an evaluation prove?

Test out-of-scope requests, missing approval, changed targets, duplicate attempts and ambiguous results. Identify where enforcement occurs and which records survive failure. Standards references are evaluation context, not a certification or agency endorsement.

## Continue the evaluation

- [Review the authority architecture](https://rangoon.ai/architecture/)
- [Open the government evaluation guide](https://rangoon.ai/solutions/government/)
- [LNSAT](https://rangoon.ai/lnsat/)
- [Policies](https://rangoon.ai/product/policies/)
- [Security principles](https://rangoon.ai/security/)
- [Standards references](https://rangoon.ai/standards/)
- [Agent development](https://rangoon.ai/software/agent-development/)
- [Self-hosted deployment](https://rangoon.ai/software/self-hosted-deployment/)


## More information

- [Documentation index](https://rangoon.ai/llms.txt)
- [AI access and policies](https://rangoon.ai/ai/)
- [Source repository](https://github.com/hypler-dev/rangoon)
