⚡
Brief IA
›

IntentFlow: A Language for Auditing LLM Agents

🔬 Research·Tom Levy·

IntentFlow: A Language for Auditing LLM Agents

IntentFlow: A Language for Auditing LLM Agents
⚡
Key Takeaways
1Each execution produces a hash-linked append-only trace, verifiable with only the source file.
2The agent plan is compiled into .iflow and applied by an ActionGate outside of the model.
3Pre-alpha: offline usage (validate/explain/run, audit) and known limitations.
💡Why it matters — IntentFlow aims for independent post hoc compliance proof, beyond the safeguards of prompts and code.
⚡Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

IntentFlow offers a declarative language to frame LLM agents and generate independently verifiable execution proofs. The plan is implemented outside the model via an ActionGate, and each run produces a hash-chained trace. The tool is currently in pre-alpha, with offline usage and known limitations.

Hash-Chained Traces and Verifiable Compliance, Up to Escalation

Each execution generates an append-only trace that is hash-chained and can be signed. An auditor can re-derive the rules from the source file and establish compliance by relying solely on this file and the trace. In the provided example, action refusals, required approvals, typed outputs, and confidence thresholds lead to verifiable machine checks and escalations, rather than relying solely on trust. Anticipated escalation outcomes include "fail closed" and "needs_human."

A .iflow Language and an ActionGate that Enforces the Plan

IntentFlow presents itself as a small declarative language called ".iflow." It transforms the agent's objectives, proof criteria, action policy, verification procedures, uncertainty considerations, and output contract into a plan intended for execution. This plan is implemented outside the model by an ActionGate, which never consults the model's output.

Offline Execution, GitHub Example, and Pre-Alpha Limitations

An execution and audit pipeline is defined, and offline usage is possible through the commands "validate," "explain," "run," and "audit." A concrete example of GitHub ticket triage in .iflow is provided with this presentation. Among the restrictions of the pre-alpha version are a fixed calibration, contracts typed only at the top level and not internally, uncertainty primitives that are recorded without being executed, and side-effect tools that are not yet supported. The project encourages testing it offline and reporting any potential issues. In the background, it is asserted that safeguards based solely on prompts, application code, or callbacks may fail in real-world scenarios, hence the promotion of a governance artifact that is imposed and revisable, providing verifiable proof post-execution. The initial example specifically mentioned prompt rules such as not closing a ticket, always citing proof, and requesting human intervention in case of doubt.

⚡

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.