ThePlus Tech
Payments · Security · AI agents

The same controls.
Every action answerable.

ThePlus Tech engineers controlled AI and operational systems for payments, security and autonomous agents — with identity, policy, audit and evidence built into how actions execute.

TrustLedgerEngine built · CI-verified against PostgreSQL
TrustLedger reconciliation screen: four open issues with severity, affected entity, amount at risk, due date and status, above a note explaining that issues stay open until a permissioned operator resolves them.Open full-size interface ↗

Every mismatch stays open until someone resolves it

  1. 01
    Exception state

    Four open issues remain visible until a permissioned operator resolves the difference.

  2. 02
    Financial exposure

    The queue separates the amounts at risk in GBP and NGN.

  3. 03
    Deadline

    An issue past its due date stays explicit rather than silently ageing out.

  4. 04
    Evidence trail

    Every row retains the affected entity and the records that disagree.

Sandbox environment, seeded data. Signed in as ops@uicheck.test.Read the TrustLedger case study

Autonomy without control is a liability. Control without evidence is a claim.

Before an autonomous system acts on money, access, or a customer, six questions need an answer that would survive an auditor. Each one is a control. Here is where each control is implemented, in each system, and where it is not.

ControlTrustLedgerPaymentsCyberGuardPlusSecurityAgent Clearing NetworkAI agents
Who is acting?Identity
TrustLedgerOAuth2 resource server. Every API is tenant-scoped, and a second tenant reading another’s issue gets 403.
CyberGuardPlusJWT, with tenant scope derived from the token and never from a query parameter.
Agent Clearing NetworkOrganisations, human principals, agents and instances, each with a signed passport.
Is it allowed to?Policy
TrustLedgerExplainable fraud rules with score bands, and a fixed transfer state machine that refuses undefined transitions.
CyberGuardPlusDetection rules evaluated against every normalised event on the stream.
Agent Clearing NetworkSigned mandates carrying purpose, limits, counterparty allowlists and expiry, plus a runtime policy endpoint.
What did it do?Audit
TrustLedgerAudit events, and an activity register that keeps every assignment and reassignment rather than the latest state.
CyberGuardPlusA hash-chained log of privileged actions that can be verified on demand.
Agent Clearing NetworkHash-chained audit history with a transactional outbox.
Did it actually work?Evidence
TrustLedgerThe provider original is preserved before anything derived from it exists.
CyberGuardPlusReporting and compliance modules build exports from the stored investigation record.
Agent Clearing NetworkA content-addressed store keyed by SHA-256, with signatures and chain-of-custody metadata.
Who signs off?Human approval
TrustLedgerExceptions are assigned to a named owner with a deadline. High-risk transfers hold for review rather than proceeding.
CyberGuardPlusAn incident carries an owner through its lifecycle, including the ones closed as false positives.
Agent Clearing NetworkMaker-checker approval before a clearing decision stands.
What happened while it ran?Observability
TrustLedgerMicrometer, Prometheus and Actuator endpoints.
CyberGuardPlusPrometheus with 13 alert rules, and Grafana.
Agent Clearing NetworkNot implemented.
  • The Agent Clearing Network has no observability. Its own feature matrix said OpenTelemetry hooks were present until a search found the string in three documents and zero source files, and the row was corrected to No.
  • These are three separate codebases in three languages. They share the same controls, not the same code: no shared package appears in any of their build files, and the Control Plane is deliberately a capability model rather than a repository.
  • Compliance work is delivered by hand as a service, and the governance platform is a roadmap. Neither appears above, because neither is software yet.
Diagram 0001How an action earns execution
IdentityWho is acting?

The request is bound to a named principal before any authority is considered.

Reference control flow showing a sample agent crossing the ThePlus authority boundary, an external provider boundary, and producing a verified evidence record.AgentSAMPLE · agt_7f21SIGNED MANDATETHEPLUS CONTROL BOUNDARY · REFERENCE CONTROL FLOWIdentitywhoAuthoritymay itPolicyshould itDecisionALLOW ✓SCOPED TOKENEXTERNAL PROVIDERGitHubSAMPLE · PR #482POSTCONDITION CHECKEDEvidence recordSAMPLE · ev_9c04VERIFIED ✓Reference control flow recomposed vertically for mobile: a sample agent crosses the ThePlus authority boundary, an external provider boundary, and produces a verified record.AgentSAMPLE · agt_7f21SIGNED MANDATETHEPLUS CONTROL BOUNDARYREFERENCE CONTROL FLOWIdentitywhoAuthoritymay itPolicyshould itDecisionALLOW ✓SCOPED TOKENEXTERNAL PROVIDERGitHubSAMPLE · PR #482POSTCONDITION CHECKEDEvidence recordSAMPLE · ev_9c04VERIFIED ✓

The action is not trusted because an agent requested it.

It crosses the boundary only after identity, authority and policy allow it. Execution then earns a record by passing a postcondition check. This is a reference model, not a runtime trace; every identifier shown is a sample.

  1. Sample agent agt_7f21 requests an action under a signed mandate.
  2. ThePlus verifies identity, authority and policy before recording an allow decision.
  3. A scoped token makes the boundary crossing to the sample external provider lawful.
  4. The postcondition is checked after execution.
  5. Sample evidence record ev_9c04 records the verified outcome.

Security Questionnaire Rescue Sprint

Stop rebuilding trust answers from scratch. Fixed scope, manual outcome first, and you see what is missing before the buyer does.

£1,500First three pilots · fixed scope
  • Workflow and evidence-source map
  • Reusable answer bank
  • Missing-controls report
  • Exportable response pack
  • 30-day automation roadmap

Delivered by hand, not by platform. It exists because the same evidence problem keeps appearing before anyone is ready to buy software for it.

Inside the systems.

Real interfaces, annotated to show why each state matters. Every image is paired with its sandbox or demo scope, because there is no customer deployment to show yet.

CyberGuardPlusEndpoint security MVP shipped
CyberGuardPlus incidents workspace listing seven investigations with severity, status, attack stages, alert counts and age.Open full-size interface ↗

Alerts correlated into investigations that can be closed

Signals become campaigns with an owner, a stage and a lifecycle. A false positive is recorded as one rather than deleted.

  1. 01
    Investigation

    Signals are correlated into seven investigations instead of left as an alert count.

  2. 02
    Severity

    High and critical state remains visible beside each record.

  3. 03
    Lifecycle

    New, investigating, resolved and false-positive outcomes stay distinct.

  4. 04
    Ownership

    The demo workspace names its owner in the interface.

Demo workspace, seeded data. “LIVE” is product status over that seeded data. Signed in as demo.owner@cyberguard.local.Read the CyberGuardPlus case study
FleetOpsResilience and control implementation evidenced
FleetOps Operational demo command centre with fleet metrics, live vehicle positions, driver and vehicle status, and recent alerts.Open full-size interface ↗

Dispatch decisions, checked against policy before they happen

Vehicles, trips, overdue maintenance and fuel anomalies in one operating picture, where every governed decision is policy checked and auditable.

  1. 01
    Operating picture

    Vehicles, trips, drivers and alerts share one command view.

  2. 02
    Demo boundary

    The top bar names this environment “Operational demo” inside the exported interface.

  3. 03
    Maintenance risk

    Maintenance due and overdue counts stay visible in the headline operating metrics.

  4. 04
    Policy evidence

    The sidebar states that governed decisions are policy checked and auditable.

Operational demo, seeded data. “Live” labels current demo telemetry, not a customer deployment. Single-workspace validation build.

Agent Clearing Network

Governs delegated authority, signed mandates, delivery evidence, and clearing decisions between agents.

PostgreSQL-proven reference kernel

AI Governance Platform

Maps AI systems to obligations, control owners, monitoring evidence, and human accountability.

Control-plane product roadmap

Those last two have no interface to screenshot. The Agent Clearing Network is infrastructure other systems call, and its concurrency proof is in the measured Evidence section below. The governance platform is a roadmap, and is listed as one.

How I engineer.

Five rules the work is held to. Each one was learned by paying for its absence.

What most systems recordAgent → API → 200 OK

The request was accepted.

What ThePlus verifiesIntent → Authority → Execution → Postcondition → Evidence

The intended outcome actually occurred.

Agent Clearing Networksrc/acn/application/mandates.py · commit 1d14610 · line-wrapped
mandate = session.scalar(
    select(Mandate)
    .where(Mandate.id == mandate_id)
    .with_for_update()
)
The mandate row is locked before authority is evaluated and consumed. The concurrency run measures the result; the excerpt alone does not prove it.
  1. 01

    Evidence before assumptions

    I measure what the system actually does. A claim without the run behind it is only a claim, and the page says so where that is the case.

  2. 02

    Control before autonomy

    An agent receives explicit authority for a named action, with a budget and a mandate, not standing access to everything it might need.

  3. 03

    Verify the outcome, not the response

    A 200 from an API is not a settled payment or a closed incident. The check is against what changed in the world, after the call returned.

  4. 04

    Security by architecture

    Identity, policy and audit sit inside the system as its first layers. They are not a filter bolted to the edge once the feature works.

  5. 05

    Products from repeated pain

    Engineering investment follows a problem that has appeared more than once with a budget owner behind it. Nothing here was built because it was interesting.

What was measured, and against what.

Results from repository CI. That is not production, and the distinction is the reason this section exists rather than a list of adjectives.

PostgreSQL concurrencyAgent Clearing Network · Measured result
100concurrent attempts
1authorised
99rejected
0errors
Repository CI · 100 concurrent attempts. A refusal is the control working.
Evidence logRev 2026-09-08

MeasuredA run produced these numbers.

PostgreSQL concurrency100 concurrent attempts1 authorised · 99 rejected · 0 errors

Mandate writes remain safe under high contention.

Evidence state · Test-proven
Atomic mandate consumptionMandate consumed1

Exactly-once consumption under row-level locking.

Evidence state · Test-proven
Budget reservation safeguardOver-commitments observed0

Reserved funds are summed under the mandate lock.

Evidence state · Test-proven
Append-only audit evidenceAppend-only, not tamper-evidentDB enforced

Database triggers prevent normal audit-row mutation.

Evidence state · CI-verified
Idempotent recoveryBy idempotency keyRecovered

Timeout-after-commit is recovered without replaying settlement.

Evidence state · Test-proven

Built, not measuredImplemented and reviewed. No run has produced a number yet.

Tenant isolationTenant-aware contractsScoped

Tenant context is enforced across shared contracts and access paths.

Evidence state · Implemented
Not provenProduction behaviour: not observed. Append-only audit: not tamper-evident. Evidence scope: repository CI only. These stay listed until a measurement replaces them.
CyberGuardPlus audit log showing a hash-chained record of privileged actions, with the result: chain intact, two entries verified, no tampering detected.Open full-size evidence ↗
CyberGuardPlus verifying its own hash chain. This is a different mechanism from the append-only audit listed above: that one is enforced by database triggers, has no chain, and is why the limit above says append-only is not tamper-evident. Two entries is the entire log of that demo workspace, not a sample of a larger one.
Founder

Theophilus Ogieva

Founder · AI and software engineer · London

Computer Science and Cybersecurity, University of Kent, 2025

Everything on this site comes from one question: What must be true before an autonomous system is allowed to act?

ThePlus is founder-led engineering. I build the systems that answer this question, and I publish the interfaces, tests and evidence behind the claims rather than asking you to take them on trust.

Notes from the work.

Engineering notes for the people accountable when a system acts on its own. Each states what its evidence does not cover.

  1. Question to evidence
    QuestionControlEvidence
    25 questions · 6 families
  2. Action-time validation
    ResearchRevalidateSend
    2 stale identities stopped before send
    The campaign was ready. Two identities were stale.AUTOPSY · Acquisition controls · 5 min read
  3. Mandate concurrency
    MandateLockAuthorise
    100 attempts · 1 authorised
    One mandate. One authorised action.Trusted AI agents · 6 min read

Start a conversation.

No form and no sequence. It opens an email, and the reply comes from Theophilus.