Contained and measured · for AI agents on NVIDIA OpenShell
Your agent's work leaves the building. Its proof stays behind.
Every AI order signed. Every result carries its origin.
Each result your agents produce leaves with an origin receipt: who authorized it, what was actually asked, what it was made from, and the process it ran under. Anyone can check it, offline, without an account.
Pilot program opening. The receipt here is an illustrative sample; the live demo runs on a real OpenShell gateway.
- Authorized byExample Corp · officer's key (a hardware key in production; a demo key here) · valid at the instant the order was signedverified
- SpecificationThe exact request, byte for byte, unalteredverified
- Materials3 sources fetched and committedverified
- ProcessPolicy installed by the signed order. Platform evidence declared, not yet measuredasserted
- IntegrityIncluded in session checkpoint 42. Checkpoint signature validverified
Illustrative sample, not a record of a real transaction. Change one thing and watch it respond.
The problem
The proof stays in the operator's console.
Sandboxes keep agents inside their limits, and that matters. But the person who receives the agent's work, a customer, an auditor, a regulator, a partner, gets the output and nothing they can check.
Keeps the agent contained
OpenShell confines files, network, processes and credentials. Security tools watch the runtime.
Stays in the console
Logs, telemetry and agent identities live in the SIEM and the gateway. None of it travels with the result.
Has nothing to check
Who authorized this? Was that the real instruction? What went in? Today the answer is "trust us".
How it works
Authorize. Run. Verify.
Rootz Receipts installs into OpenShell's own published extension points. No fork, and no changes to your agents, models or tools.
-
AuthorizeThe order
An officer signs the policy itself as a signed order. OpenShell installs nothing else, and every later change is another order: narrowing needs less authority than widening.
-
RunThe process in control
Agents run unchanged. Before each network request, the controls in force are checked against what the officer authorized, and every request and response is recorded. Local file and process activity is a later phase. Drift is refused, and the refusal is recorded too.
-
VerifyThe origin receipt
Each result carries an origin receipt anyone can check offline with a free verifier. Five lines, each verified, asserted, unavailable or failed. No overall pass mark to hide behind.
Data, not agent
Not that the agent was contained, but that the data came from a specific, measured container.
Containment is a property of the runtime, and it is reported in the operator's console. Origin is a property of the result, and it has to travel with it.
"It ran in a policy container."
- About
- The agent.
- Answers
- Could the agent escape its limits?
- Where it lives
- In the operator's console, for the operator.
"This output came from that container."
- About
- The data: this specific result.
- Answers
- Which container, under which signed policy, with which controls and measurements in force at that instant?
- Where it lives
- With the result, for whoever receives it.
Read the finding in plain language · See it as a demo moment
Keep the chain alive
Each result names the results it was built from.
People don't check origin. They want the output. AI can be trained to check, and to carry the receipt forward.
- Receipt A
Research
An agent extracts the figures, with its sources.
- named by B
- Receipt B
Draft
The next agent writes the memo from A's result.
- named by C
- Receipt C
Decision
The recommendation names B, and through B, A.
When an output becomes the input to the next step, the next origin receipt names the receipts it was built from. The chain becomes the record of the reasoning that reached a conclusion. It answers "how did we get here?", focuses the conversation on the step that matters, and lets later decisions learn from what went right and what went wrong.
The chain is tamper-evident: change or withhold a receipt and the break is visible to whoever checks.
Start
Start small. Each step asks less than the last.
Verification is free and always will be. The side that signs orders and governs agents is what a company pays for.
See an origin receipt Sample on this site
The illustrative sample shows each line and what breaks it.
Verify one yourself With the pilot
The free verifier runs in a browser or on the command line, offline, with no account.
Try the hosted demo Live now
Sign a policy, run an agent task, then change one thing at a time and watch what the verifier reports.
Run it on your OpenShell With the pilot
One command on a workstation or a test cluster.
Pilot for 30 days Opening
One workflow, one policy under orders, one counterparty who verifies what they receive. What a pilot includes.
Put an origin receipt in the OpenShell demo you're already building.
If you're showing agents on OpenShell to your own customers, we'll add the moments that make a demo land: an unsigned policy refused, a changed answer caught, a result verified by a stranger. Design partners get the pilot first.