Prove the approval happened.
Every AI governance policy claims human oversight. A Sequesign receipt is how you prove a specific human approved a specific action, and how a reviewer tells a real approval from a claimed one.
Notes and updates from the Sequesign project. Protocol design, trust model, reference implementation, and the occasional opinion piece.
Every AI governance policy claims human oversight. A Sequesign receipt is how you prove a specific human approved a specific action, and how a reviewer tells a real approval from a claimed one.
Why ordinary logs are not proof, and how signed, chained, witnessed receipts let you verify what a delegated AI agent actually did, offline and under scrutiny.
Auditability for regulated AI workflows is not observability or prompt history. It is durable, tamper-evident evidence about a delegated action chain, verifiable offline, with explicit limits on what is proven.
An agent action verification SDK is not observability. It produces signed, chained, witnessed receipts that survive offline audit and keep proven facts separate from agent-asserted ones.
How signed hash chain audit logs turn AI agent activity into tamper-evident, offline-verifiable evidence, and where ordinary application logs fall short.
Standard application logs are built for debugging, not evidence. Tamper-evident agent logs make AI agent actions verifiable later, independently, and with clear trust boundaries.
What it means for an AI workflow's evidence to survive vendor changes, account closure, and long retention windows.
Logs support investigation. Receipts support verification. As AI agents move from drafting text to taking delegated action, the evidence model has to change with them. A working evaluation checklist for technical buyers.
Logs are useful for debugging but not for proving what happened. Audit trails for delegated AI work need signed events, ordering proof, principal identity, provenance boundaries, and verifiability that outlasts the original system.
Audit logs are written by the system under investigation, which disqualifies them as evidence. Sequesign produces independently verifiable receipts that prove what happened, who authorized it, and in what order.
Logs are written by the system being investigated, which disqualifies them as evidence; a receipt is signed at the moment of action, witnessed independently, and verifiable offline by anyone.
We are publicly launching Sequesign, a protocol for cryptographically verifiable receipts of delegated AI work, with a reference implementation, trust model, and live demo.
What offline verification actually does, what a receipt package contains, the nine checks the verifier runs in order, and what the structured report looks like on success and failure.
A walk through the sharp line between what a valid Sequesign receipt proves cryptographically and what it deliberately leaves as agent-asserted, and why that separation is the product.