IntentFlow: Governed LLM Agents With Auditable, Hash-Chained Traces
Last Updated on August 19, 2026 by Editorial Team
Author(s): Diogo Santos
Originally published on Towards AI.
A small declarative language that compiles agent intent into a governed plan — and proves, after the fact, that the run stayed inside its rules.
You wired up an LLM agent. It can read a GitHub issue, search the repo, draft a reply, and — because you were in a hurry — it can also post that reply and close the issue. You put the guardrails in the prompt: “Never close an issue. Always cite evidence. Ask a human if you’re unsure.”

The article explains why “agent governance” implemented only through prompt wording, application code, or framework callback logic can leak under real-world pressure, and argues for an enforced, reviewable governance artifact that yields independently verifiable proof after the run. It introduces IntentFlow: a small declarative “.iflow” language that compiles an agent’s objectives, evidence requirements, action policy, verification rules, uncertainty handling, and output contract into an execution plan enforced outside the model via an ActionGate that never reads model output. Every run produces an append-only, hash-chained (optionally signed) trace, and an auditor can re-derive the rules from the source and prove conformance using only the source file and the trace. The post walks through a concrete example (.iflow for GitHub issue triage) showing how denied actions, approval-gated actions, typed outputs, and confidence thresholds lead to machine-checkable verification and escalation (e.g., fail closed or needs_human) rather than relying on trust. It also describes the runtime/audit pipeline, demonstrates offline usage with validate/explain/run and audit commands, and notes current pre-alpha limitations (fixed calibration, typed contracts at the top level but not internally, some uncertainty primitives recorded but not executed, and side-effecting tools not yet executed), concluding with takeaways and guidance to try the project offline and report what breaks.
Read the full blog for free on Medium.
Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.
Published via Towards AI
Towards AI Academy
We Build Enterprise-Grade AI. We'll Teach You to Master It Too.
15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.
Start free — no commitment:
→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day
→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages
Our courses:
→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.
→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.
→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.
Note: Article content contains the views of the contributing authors and not Towards AI.