The work — standards, a free service, and our open source.
Three things to know: the open standards we authored and are moving to independent governance, the free public witness that has been running since June 2026, and the company open-source project that connects records to meaning. This page introduces each and links out — the spec detail lives on the .org sites.
Company open source
Action State open source · Apache-2.0
Evidence Contract compiler
Part of EvidenceBook
Obligations & Outcomes to Actions
Records tell you what happened. They don't tell you whether it was good. This project closes that gap.
You describe what you're obligated to deliver, or what outcome you're trying to achieve, in ordinary language: "resolve the customer's request in one interaction,""never pressure an employee,""close critical vulnerabilities within the window." The compiler turns that into a small set of evaluation axes with frozen criteria, wires them to your capsule log, and generates a skill that runs every day, judges each case, and seals the results. A second skill aggregates the daily results into a monthly report.
Where an outcome can be counted, it's counted. Where it must be judged, an AI judges under a disclosed method, and humans calibrate a blind sample every week. The output is a report your customer, your auditor, or your own team can open, drill into case by case, and verify was never altered.
Criteria are fixed before anyone sees results. The judge's method is disclosed. Humans calibrate a sample every week. Every output is itself a record.
What's in the repo
→The Evidence Contract compiler — obligations and outcomes to evaluation axes to skills
→Reference evaluation and aggregation skills
→The report format, itself sealed as capsules
→A worked example on a public customer-service benchmark (an airline support agent)
→Profiles for common obligation types, growing over time
License & governance
Apache-2.0. Maintained by Action State. Contributions welcome.
This project is company open source and is not foundation-bound. That's a deliberate choice, not a shortcoming — it lets us move the tooling forward while the standards it sits on top of move to independent governance.
Showing each job was done, and how it was done, is what lets a team charge for outcomes rather than seats. The report is the deliverable — the records and the compiler are what make it checkable.
Worked example — regulatory obligations
QuadX AI mapped UK BNPL / consumer-credit obligations (the FCA Handbook) to verifiable evidence artifacts — grading each obligation by who can actually check it: operator-asserted (you take the firm's word), participant-verifiable (a party to the transaction checks it cryptographically), or third-party-verifiable (a stranger — an auditor, a regulator, a court — verifies it from the artifact and a public anchor, trusting neither the agent nor the operator). It cites the same independent cross-verification runs as the interop index above.
The FCA clause mapping is QuadX AI's FCA Obligations Mapping v1.0 (22 July 2026): QuadX AI reviewed and corrected the Action State Group strawman and verified the FCA clause references against the FCA Handbook as at July 2026. It codes the rules as written, not as enforced — informative, not legal advice and not an FCA position. That's the point of the compiler on a real regulatory surface: "shown met" becomes a checkable claim with a stated depth, not a promise.
Open standards
Community project · foundation-bound
The formats and protocols for recording agent actions.
We authored these and are moving them to independent governance. The spec detail lives on their own sites; three sentences each is all this page carries.
Community project · foundation-bound
Agent Action Capsule (AAC)
The record format for a single agent action — what was done, by whom, for whom, and with what result, sealed at the moment it touched the world. Action State authored the specification and is working with the community to move it to independent governance. It is the common layer every other tool here builds on.
The digest rule that ensures two independent implementations always agree on exactly what bytes were signed — so a record produced by one tool can be verified by any other without coordination. Action State wrote the initial specification. Without this rule, "verifiable" means "verifiable by the same software that sealed it."
A node's append-only log of agent action capsules, checkpointed at intervals for external registration — so the log's integrity can be verified later without the witness ever seeing its contents. Action State submitted the specification as an IETF Internet-Draft.
One record needs several small standards, each doing one job — so no single document has to be trusted for everything, and each can be verified, adopted, or replaced on its own. Read top to bottom, they compose: the digest rule fixes the bytes, the capsule is the record, the log dates it, the second party corroborates it, disclosure controls what's shown, and the accountability drafts define how the pieces fit and how conformance is checked.
The record & its bytes
Canonical Payload Binding ↗ The canonicalization rule underneath everything, so two independent implementations never disagree about what was signed.
Agent Action Capsule ↗ The record of one agent action: what happened, for whom, under what authority, and what was left out.
Checkpointed Local Log ↗ A node's append-only log, checkpointed so an outside party can date it without seeing its contents.
Selective Disclosure Profile ↗ Reveal or withhold each member of a record without breaking its integrity — a withheld member stays counted, never blank.
The second party & conformance
Bilateral Attestation ↗ Two organizations each seal their half of an exchange, citing the other by digest — so a dispute is not one party's word.
We operate a free public witness for agent action records. It takes two kinds of submission — each a hash, never your content — carrying different levels of detail:
Register a statement (POST /register) — a digest and its timing for a single record, returned with an inclusion proof you can use right away.
Checkpoint a log (POST /checkpoints) — around 300 content-free bytes that cover any number of records at once, so you can show later that your history existed and was unaltered.
Both are witnessing: the witness sees hashes, not records, and verification runs offline against an open-source verifier, so checking a receipt never requires coming back to us. Countersign is a different thing: an operated recompute of a fixed set of structural checks over a digests-only evidence bundle, below.
Free verification checks a record wasn't altered. Countersign is a second party recomputing a fixed set of checks and signing what they found.
An operated layer on top of the free witness. It accepts an evidence bundle with every payload withheld (digests only), recomputes a fixed set of structural checks over it (range membership, profile conformance, chain consistency, cadence, key hygiene) and signs which checks ran and their results. It never checks capture coverage or outcome correctness. The practice statement lists each check and what it reads today. Countersign becomes a paid service once the first acceptors are on record.