Product
Your negotiation runtime, and the gate before terms bind.
Your agents run offer-counter exchanges against one standard while you set the authority limits. Anything above a threshold halts and waits for a named person to approve.
What each part of the runtime does.
Deterministic negotiation runtime
A deterministic offer-counteroffer-acceptance state machine that drives every Negotiation and tracks its status in the Live Negotiations view. Your agents conduct the exchange; the operator watches the current state, the tabled terms and where each one sits against your limits. Because the lifecycle is the same across counterparties, a failed negotiation is reproducible rather than a per-relationship mystery.
Machine-readable term templates
A versioned Term-Template Library covering scope, SLAs, liability, data terms and multi-party obligations. Agents negotiate against a shared vocabulary rather than reconstructing message formats per counterparty. AI colleagues maintain and version each TermTemplate; your integration engineers own which versions are live and can pin a template for a given transaction type.
Authority limits and approval gates
An AuthorityPolicy sets value, risk and irreversibility thresholds and approval routing before any negotiation runs. When a proposed Commitment exceeds a threshold or is policy-ambiguous, the runtime halts and raises an Approval in the Approvals & Sign-off queue. Humans set the limits; the runtime escalates the exception rather than resolving it on its own.
Inline policy-as-code checks
Compliance and policy-as-code checks run during the negotiation, not after it. A term that breaches a configured rule is flagged before it can reach acceptance, so governance moves into the exchange itself. The operator sees which rule fired and on which tabled term, and can adjust the policy rather than unwinding a settled agreement.
An operator's day
From a new counterparty to defensible evidence.
What actually happens in the product, stage by stage.
Connect the counterparty once
A new counterparty integrates to the protocol a single time through Protocol Integration. From that one connection it can transact with any other adopting party — no bespoke connector per relationship, no message format to rebuild.
Agents negotiate within limits
Two agents exchange offers and counters against shared templates inside the AuthorityPolicy you configured, with state tracked throughout. When every term sits within your thresholds and passes the inline checks, the runtime records acceptance and the agreement binds.
A named person clears the gate
When a Commitment crosses a value, risk or irreversibility threshold, the runtime halts and routes an Approval to the accountable governor. It cannot bind until that person explicitly signs off, and the decision — approve or reject — is logged against their identity.
Retrieve the record on request
When an auditor, regulator or disputing counterparty asks who agreed what and on whose authority, the compliance owner retrieves the complete ordered AuditRecord as evidence. It supports internal audit and DIFC dispute resolution without piecing events back together.
The boundaries
What is enforced, where, and by whom.
Where the agents act, and where you stay in control
AI colleagues operate the runtime day to day. They conduct the offer-counteroffer exchanges within pre-set authority limits, maintain and version the term-template library, run the inline compliance checks, track negotiation state and assemble the audit record. They do the operating work; they do not hold the authority to bind on their own.
That authority is human, and it is set before any negotiation runs. A named governor configures the value, risk and irreversibility thresholds and the approval routing. When a proposal exceeds a threshold or is policy-ambiguous, the runtime stops and escalates to that governor rather than proceeding. No high-value, irreversible or ambiguous commitment becomes binding without an explicit human sign-off — consistent with the human-oversight principle in EU AI Act Article 14 where a use-case is classified high-risk. The gate is part of the lifecycle, not a setting an operator can quietly disable to hit a deadline; a rejected or bypassed step is itself recorded.
The runtime sits above agent identity and settlement primitives and below application-specific agent workflows. It is horizontal contracting fabric: a shared dependency other ventures and infrastructure providers build on, not a vertical application that owns your agents.
What we are candid about
Compliance and policy-as-code checks run inline, and every action and approval is attributed to an identity in the immutable log. What that log cannot do is settle law on your behalf. Authority-to-bind, how error and liability are allocated when an agent gets a term wrong, and the DIFC-specific treatment of automated contracting are open legal items that require dedicated advice before you rely on them. Subchain gives you the gate, the record and the escalation route so a machine-negotiated agreement can be defended; it does not assert that every such agreement is enforceable in every jurisdiction out of the box.
To be plain about the boundary: Subchain is a human-governed agreement protocol and runtime. It is not a blockchain, a token or a consensus network, and it is not an autonomous signer that closes deals end to end with no human involvement.
Where the runtime is heading
The current build is a bilateral runtime between two adopting parties — the state machine, a curated template set for a defined transaction type, one configurable approval gate, inline checks and the immutable log — designed to be useful from the first relationship rather than requiring ecosystem-wide adoption. From there, the direction is a broader template library and hardened approval routing as more ventures across the Cohort Ventures network transact on the standard, then multi-party obligations, a wider term surface and licensing of the runtime and template library to infrastructure providers. This is direction, not a promise of dates; each step follows evidence from real negotiations and real approvals.
Questions engineers and governors raise.
See the runtime negotiate and the gate hold.
Bring one transaction type and one counterparty relationship. We will walk through a live negotiation, an approval and the record it leaves.