Pilot program opening. Design partners wanted. Live demo on a real OpenShell gateway. Sample receipts use demo keys for an invented company.

Contained and measured · for AI agents on NVIDIA OpenShell

Your agent's work leaves the building. Its proof stays behind.

Every AI order signed. Every result carries its origin.

Contained and measured. OpenShell keeps agents contained. Rootz Receipts makes their work measured.

Each result your agents produce leaves with an origin receipt: who authorized it, what was actually asked, what it was made from, and the process it ran under. Anyone can check it, offline, without an account.

Pilot program opening. The receipt here is an illustrative sample; the live demo runs on a real OpenShell gateway.

Origin receipt Sample · illustrative
result Filing summary order sha256:q3Xm…T8vA session 7Hc2kQ…a91 · leaf 41 verified at 2026-10-06 14:02:11Z
  1. Authorized byExample Corp · officer's key (a hardware key in production; a demo key here) · valid at the instant the order was signedverified
  2. SpecificationThe exact request, byte for byte, unalteredverified
  3. Materials3 sources fetched and committedverified
  4. ProcessPolicy installed by the signed order. Platform evidence declared, not yet measuredasserted
  5. IntegrityIncluded in session checkpoint 42. Checkpoint signature validverified

Illustrative sample, not a record of a real transaction. Change one thing and watch it respond.

The problem

The proof stays in the operator's console.

Sandboxes keep agents inside their limits, and that matters. But the person who receives the agent's work, a customer, an auditor, a regulator, a partner, gets the output and nothing they can check.

The operator

Keeps the agent contained

OpenShell confines files, network, processes and credentials. Security tools watch the runtime.

The evidence

Stays in the console

Logs, telemetry and agent identities live in the SIEM and the gateway. None of it travels with the result.

The recipient

Has nothing to check

Who authorized this? Was that the real instruction? What went in? Today the answer is "trust us".

How it works

Authorize. Run. Verify.

Rootz Receipts installs into OpenShell's own published extension points. No fork, and no changes to your agents, models or tools.

  1. AuthorizeThe order

    An officer signs the policy itself as a signed order. OpenShell installs nothing else, and every later change is another order: narrowing needs less authority than widening.

  2. RunThe process in control

    Agents run unchanged. Before each network request, the controls in force are checked against what the officer authorized, and every request and response is recorded. Local file and process activity is a later phase. Drift is refused, and the refusal is recorded too.

  3. VerifyThe origin receipt

    Each result carries an origin receipt anyone can check offline with a free verifier. Five lines, each verified, asserted, unavailable or failed. No overall pass mark to hide behind.

How it works, for engineers

Data, not agent

Not that the agent was contained, but that the data came from a specific, measured container.

Containment is a property of the runtime, and it is reported in the operator's console. Origin is a property of the result, and it has to travel with it.

Contained · the runtime's claim

"It ran in a policy container."

About
The agent.
Answers
Could the agent escape its limits?
Where it lives
In the operator's console, for the operator.
Measured · the origin receipt

"This output came from that container."

About
The data: this specific result.
Answers
Which container, under which signed policy, with which controls and measurements in force at that instant?
Where it lives
With the result, for whoever receives it.
Why "specific" matters. In our lab on OpenShell v0.1.2, two sandboxes created from the same policy, one with a credential provider attached, had the same stored policy revision hash, though the provider added read-write network access to an external API. Only the effective policy hash showed the difference. OpenShell reports both; the difference is which one travels with the result, and the origin receipt binds to the effective one. This is a gap in what travels with the result, not a flaw in containment.

Read the finding in plain language · See it as a demo moment

Keep the chain alive

Each result names the results it was built from.

People don't check origin. They want the output. AI can be trained to check, and to carry the receipt forward.

  1. Receipt A

    Research

    An agent extracts the figures, with its sources.

  2. Receipt B

    Draft

    The next agent writes the memo from A's result.

  3. Receipt C

    Decision

    The recommendation names B, and through B, A.

When an output becomes the input to the next step, the next origin receipt names the receipts it was built from. The chain becomes the record of the reasoning that reached a conclusion. It answers "how did we get here?", focuses the conversation on the step that matters, and lets later decisions learn from what went right and what went wrong.

The chain is tamper-evident: change or withhold a receipt and the break is visible to whoever checks.

Break a link in the demo

Start

Start small. Each step asks less than the last.

Verification is free and always will be. The side that signs orders and governs agents is what a company pays for.

  1. See an origin receipt Sample on this site

    The illustrative sample shows each line and what breaks it.

  2. Verify one yourself With the pilot

    The free verifier runs in a browser or on the command line, offline, with no account.

  3. Try the hosted demo Live now

    Sign a policy, run an agent task, then change one thing at a time and watch what the verifier reports.

  4. Run it on your OpenShell With the pilot

    One command on a workstation or a test cluster.

  5. Pilot for 30 days Opening

    One workflow, one policy under orders, one counterparty who verifies what they receive. What a pilot includes.

Put an origin receipt in the OpenShell demo you're already building.

If you're showing agents on OpenShell to your own customers, we'll add the moments that make a demo land: an unsigned policy refused, a changed answer caught, a result verified by a stranger. Design partners get the pilot first.