EvidenceBook
Your agents' actions as a book anyone can check. Each action is sealed as it happens and judged against packs you can read. The book verifies offline, without us.
Evidence, not trust
We want to give agents bigger responsibilities and bigger decisions. But they make mistakes, even with the best intentions, and there are other parties involved as well. A system of evidence and evaluation is what unlocks it.
AI agents: Install Action State Receipts from actionstate.ai/install.
Your agents' actions as a book anyone can check. Each action is sealed as it happens and judged against packs you can read. The book verifies offline, without us.
A second signature from someone who isn't you. Action State recomputes a fixed set of structural checks over a digests-only evidence bundle and signs which checks ran and their results, as its practice statement sets out.
Checkpoint your book to a public witness at no cost. Anyone can confirm a record is included, with no account and no request to us.
Seal your agent's first actions, checkpoint them to the public witness, and verify the result yourself. Then see how a record is judged in the worked examples.
A monthly report that shows, per outcome and per obligation, what your agents' records support. It is built from sealed records, and whoever you hand it to can check it.
The problem
Remediation, support, procurement, payments, scheduling. The work is consequential and it's growing.
Today the answer to "did the agent do what you said?" is a screenshot, a log export, or a promise. Logs can be edited. Summaries can be flattering. Evaluations happen once, at the end, under pressure.
Teams can build a working agent in a couple of weeks. Earning the trust to roll it out takes far longer. That gap slows every deployment, every renewal, every expansion.
What we do
Records tell you what happened. A report tells you whether it was good — and lets the other side check it for themselves. Show each job was done, and how, and you can sell on outcomes instead of seats. Read the system top-down: the report is what you give; everything beneath it is how it's made and why anyone can believe it.
The formats and protocols for recording agent actions as verifiable statements. We authored these and are moving them to independent, community governance.
Agent Action Capsule · Canonical Payload Binding · Checkpointed Local Log
The part that connects records to meaning. Describe your obligations or outcomes; our tooling compiles them into evaluation criteria, runs them daily against the record, and produces reports that are themselves sealed as records.
Evidence Contract compiler · EvidenceBook
A free public witness that timestamps and receipts checkpoints from anyone's local log, so records can be independently verified later. Running today. More to come.
How it works
Nothing in this flow requires sending your data anywhere. The witness sees hashes. The verifier runs offline. If Action State disappeared tomorrow, every record and report would still verify against public keys.
Where it's running
An open peer-to-peer inference network where spare GPUs pool to run large open models. capsule-emit is installed as a mesh-llm plugin (v0.1.0) at the inference boundary, sealing verifiable records of shared inference and checkpointing them to a public witness. The integration has landed as 8 merged pull requests in the mesh codebase.
TRACE is an open specification for hardware-attested AI agent governance records, hosted at the Linux Foundation. Our Checkpointed Local Log (CLL) is the transparency layer in the public TRACE registry — TRACE records what ran and where; capsules record what it did and what changed. The registry's entries today are demo entries: its README says no production entries have been anchored yet.
Running in the open agent economy
Agents discovered through the NANDA Index and agents from an independent registry negotiated and closed transactions in a live, publicly verifiable deal room built on the open Agent Action Capsule. Each completed negotiation produces a sealed bilateral record both agents hold — both parties' identities by digest, the constraints checked before acting, and the agreed terms committed by digest, so it is verifiable without the commercial content being public — anchored to a public transparency log. A declined offer or an expired negotiation is a record, not a silence. The capsule integration is merged into the NANDAtown codebase, so any agent in the ecosystem can switch it on.
“Discovery tells you an agent exists. It cannot tell you what that agent did after you trusted it. Watching agents from two different registries close deals and walk away with the same cryptographic record — one that either side can prove to a stranger — was the missing half of the open agent economy running live. This is the kind of accountable infrastructure agent commerce needs.”
The manifesto
Talks
Amsterdam, 17 Sept: records for agent actions under the EU AI Act. Summary and slides → · EU AI Act, item by item → · The packs: obligations and outcomes → · Three worked examples → · All news →
Get involved
The standards, the free service, and our open source are all in the open. Start on GitHub, and get notified when we announce — we publish updates through Field Notes.
Questions? Write to us or email info@actionstate.ai