One boundary for every consequential action.
One boundary replaces your tracer, eval tool, and guardrail library. Receipt, gate, root cause, and audit — all reading one action record.
A receipt after. A gate before. The loop around both.
Every piece reads and writes one action record. The receipt and gate are the wedge; the rest completes the loop.
The receipt
A claimed-vs-actual verdict on every run. Proves what the agent actually did, not what it said it did.
The gate
A deterministic block before irreversible actions. No prompt, no suggestion — a hard stop until a human approves.
Root cause
A deterministic graph walk to the step that diverged. No LLM guess, no vibes, just the facts.
Kill-switch
Budget, loop, and token caps enforced before the next call. Free and loud.
Tracing
OTEL-native spans, tool calls, retries, tokens, and cost. Attach to your collector.
Audit
A SHA-256 hash-chained action log with one-command export. Compliance-grade, not compliance-flavored.
Prove every action. Stop the irreversible ones.
The open trust boundary for AI agents, one decorator away.