"Where did this number come from?"
- Today
- An engineer searches the logs and writes an explanation.
- With a paper trail
- The trail arrives with the work. They check it themselves in seconds, without access to your systems.
AI's missing paper trail, in two minutes. Watch on YouTube · Skip to the text
What NVIDIA announced, and what it leaves out
Logs are for IT. Receipts are for AI.
On 28 September 2026 NVIDIA launched the Open Agent Safety Platform, backed by more than a hundred companies. It keeps AI agents inside the limits their operators set. It does not give the people who receive an agent's work any proof of how that work was made.
"Did the agent stay inside its limits?"
OpenShell answers this"Can I rely on this result? Who authorized it, and under what rules?"
Nothing in the platform answers thisAI watermarks tell you a machine made it. Logs tell the operator what happened. Neither tells your customer who authorised it, under what controls, or what it was made from. Rootz Receipts puts that on the result.
What NVIDIA announced
AI agents no longer just answer questions. They read files, call systems, use credentials and act on their own. NVIDIA's platform is built to keep them from going where they shouldn't.
Runs each agent in a sandbox that denies everything by default. The agent can reach only the files, networks and credentials its policy allows, and the policy is enforced from outside the agent, so the agent can't switch it off.
A hardware watchdog that monitors agents independently and can quarantine one that misbehaves within milliseconds.
This is real progress, and it is the right foundation. It protects the company running the agents: an agent in OpenShell can't wander off with data it was never meant to touch. What it records stays with the operator, in the operator's own systems.
What it leaves out
The person who relies on an agent's work isn't asking whether your agents are generally well behaved. They are asking about one result: where it came from, who allowed it, and what rules applied when it was made.
We have seen this before
When a company lost a laptop full of customer records, the law excused it only if that data was encrypted. Saying "we encrypt our laptops" wasn't enough. Breach announcements from that era often admitted the company could not say whether the lost laptop had been encrypted. What actually protected a company was proof that this laptop was encrypted at the moment it was lost.
Rootz's founders built that proof for self-encrypting drives at Wave Systems. The people who bought it were the lawyers, not the IT department.
AI agents are at the same point. "Our agents run in OpenShell" is the new "our laptops are encrypted".
The question that decides liability, acceptance and payment is narrower: was this result produced by an agent running under approved controls, at the moment it was produced? Rootz Receipts answers it, with proof attached to every result.
Who will ask
Nobody asks how an AI result was made until it matters: a disputed number, an audit, a customer who has to rely on it.
What Rootz Receipts adds
Rootz Receipts installs into OpenShell's published extension points. Your agents don't change. Three things happen that didn't before.
An officer of your company signs the rules the agents run under. OpenShell installs nothing else, and a change that widens what an agent may do needs a new approval.
Every request and response an agent makes through OpenShell is recorded exactly as it happened. (Local file and process activity is a later phase.) If the controls drift from what was approved, the agent is stopped and the stop is on the record.
Each result leaves with its own paper trail: who authorized it, what it was asked, what it used and the controls in force. Change one number and the trail breaks where anyone can see it.
Who reads it
People won't check a paper trail. Their AI will. Your customers want the answer, not the evidence behind it. But an AI checks a trail in a second, every time, and flags the one that doesn't hold up. Hand an AI only the answer, and it can find the trail and check it. When one agent's work feeds the next, the trail follows, so months later you can still answer "how did we get here?"
Three ways in
Your clients' agents will need sign-off. Test every agent output against evidence signed when the work happened, instead of a sample pulled from their console.
You already run agents in OpenShellYou turned it on to keep agents contained. Add the paper trail and the same agents can take on work that has to stand up to review: customer deliverables, regulated figures, decisions.
You are launching agents on OpenShellYour customers will ask how they can trust what your agents produce. We add the answer to the demo you are already building.
Go deeper
Change one number in an agent's answer and watch the trail catch it. Real code, running in your browser.
What the trail contains, the five things it proves, and how it fits next to what you already run. We call it an origin receipt.
How it installs into OpenShell's published extension points, with no fork and no changes to your agents.