How Lilith is built. Policy on the call, kernel on the syscall, a log that still means something.
1 Enroll-2 Decide-3 Bind-4 Seal
Two parts make the decision hold: the engine writes the rule, the kernel makes it bind. The fourth part is so the story of what happened cannot be quietly rewritten. Simple machinery. Highest guarantee.
Banks already put agents on fraud queues, KYC, and payment ops. The useful work is reading the case and drafting what a human should do. The failure is the last mile: ACH, SWIFT, an internal book transfer, a CSV of every customer. Lilith allows the score and the draft. The send and the export are denied at the syscall, even if the model has already said yes. That deny is in the sealed log.
A hospital agent that can open one chart will try to open all of them. Same for PACS, claims files, the research extract. Policy names the patient and the action: this encounter, this study. Bulk export and the next MRN over are denied. If it already had her labs, that still counts when it reaches for the rest of the ward. The control is which record, on which call.
Classified and restricted shops still want coding agents on the project tree. The model will fetch from the public internet or pack up a share if the prompt asks. Enrolled, the process talks where policy says: the internal model, the repo, a ticket system on the same side of the fence. Crossing a classification boundary is a kernel deny. Unenrolled processes do not get a seat. The record of the deny survives a rewrite of the chat.
Merge bots and coding agents are fine in staging. They become an incident when the same process holds prod credentials: the kubeconfig, the root CA, terraform on the money VPC. Lilith keeps npm test and the staging cluster. Production apply and the secret store stay closed. A prompt that says to fix prod does not open those paths. The kernel never takes that meeting.