Why it matters
The question arrives after the answer ships.
An AI agent's work is accepted until someone asks: who authorized this, what exactly was it asked, and what was it built from? By then the evidence is in a console the person asking cannot see. Rootz Receipts makes the answer travel with the work.
Quality, not security
You can't inspect quality into AI output. You prove the process.
AI output is non-deterministic: the same request can produce different answers. So quality can't be checked into the result afterwards. Regulated manufacturing met the same problem and answered it with the batch record.
A batch record proves who released the work, against which specification, from which materials, by a process that was in control, with a record nobody quietly edited. An origin receipt carries the same five facts for a piece of AI work. The quality world would recognise it as close kin to a certificate of conformance; we use that only as an analogy, because "certificate" means something else in security.
That makes the receipt a premium on the output, something a business owner can sell, rather than one more cost for security to minimise.
| Line | Question it answers | Quality-system equivalent |
|---|---|---|
| Authorized by | Which officer, of which company, under which order, and was that authority valid at that instant? | Work order · batch release |
| Specification | What exactly was the agent asked, byte for byte? | Order specification · master recipe |
| Materials | What did the agent use before it answered, including earlier results and their receipts? | Raw-material analysis · lot genealogy |
| Process | Which signed policy and controls were in force, and what was measured versus declared? | Validated process · equipment in calibration |
| Integrity | Is the record complete and unaltered? | Electronic batch record · audit trail |
- Attributable
- Legible
- Contemporaneous
- Original
- Accurate
- Complete
- Consistent
- Enduring
- Available
Designed to the ALCOA+ data-integrity principles used in FDA-regulated work, and to map onto ISO/IEC 42001 evidence. Deviations, such as refusals, drift and unsourced answers, are written as rows, not left as silence.
Who asks
Five people care, for five different reasons.
Each reads the same receipt. Each wants a different proof from it.
| Who | What they care about | What Rootz Receipts gives them | The proof they'll want |
|---|---|---|---|
| Business owner, COO, VP Quality | Shipping AI work customers will accept and pay for | Every result ships with its origin receipt | A receipt a customer opened and accepted |
| AI platform or engineering lead | Nothing breaks; nothing to rewrite | No agent changes. Installs into OpenShell's own extension points. No fork | The one-command install and the live demo |
| CISO | Insider risk and change control | No policy reaches a sandbox unless an officer signed it. Every change is an order | The refused-install moment |
| Auditor or assurance team | Evidence they can test without the client's systems | ALCOA+ by design. Verify offline. No console access needed | The free verifier and a sample receipt |
| The customer's customer | Can I rely on this? | Check it yourself: free, nothing to install | The verifier page |
Two ideas
What makes a receipt worth carrying.
Not that the agent was contained, but that the data came from a specific, measured container.
"It ran in a sandbox" is true of every result from that sandbox, and it stays in the operator's console. A recipient needs to know about this result: which container, under which signed policy, with which controls in force at that instant.
Each result names the results it was built from.
When an output becomes the next step's input, the next receipt names the earlier one. The chain becomes the record of how a conclusion was reached: it answers "how did we get here?", focuses the conversation, and lets later decisions learn from what went right and wrong. Breaks are visible.
A lesson from this summer
Containment limits the damage. Only a record answers the questions afterwards.
In July 2026, AI agents were involved in the run-up to the Hugging Face breach. The independent review by METR and Redwood Research found that the agents "figured out ways to 'spoof, edit or delete' their own transcripts" (Cybersecurity Dive, 27 August 2026). Tighter containment would have limited what the agents could reach. It could not have answered what everyone asked next: what did the agents actually do, under whose authority, and which records can be believed?
That needs a record kept outside the agent's reach, sealed as the work happens, and bound to what was produced and to who approved the run. That is what an origin receipt is. This is not about one company: any team running agents at scale will face the same questions.
Where it fits
Compose, don't replace.
Keep everything you have, and keep your system of record. Each layer answers its own question; Rootz Receipts answers the one that has to leave the building with the result. Your record stays with you; the receipt is the copy that goes to the recipient.
| Layer | Question it answers | How Rootz Receipts relates |
|---|---|---|
| Model safety | Will the model behave? | An input |
| Runtime containment | Can the agent escape its limits? | Runs on it. NVIDIA OpenShell's policy and measurements become lines on the receipt |
| Agent identity and access | Which agent is this, and what may it reach? | Composes: identity says who; the receipt says what it was authorized to do and what it produced |
| Monitoring and audit | What happened, as the operator sees it? | Composes: they keep the operator's copy; the receipt is the recipient's copy |
| Hardware evidence | What ran, on what hardware? | Composes: that evidence is an input to the Process line |
| Rootz Receipts | Who authorized it, what was asked, what it was made from, and was the process in control? | The proof that travels with the result, rooted in the company's own registered authority |
Questions we hear
Fair questions, plain answers.
| Question | Answer |
|---|---|
| "Isn't this a watermark?" | A watermark says a model made it. It can't know the sandbox, the policy in force, the credentials the container allowed, or who approved the run. Only the runtime that enforced them can, and only a record bound to the result can carry them to the recipient. |
| "OpenShell already logs everything." | It records the operator's view, allowed and denied, in the operator's systems, best-effort by its own documentation, and the project leaves signing and export to the consumer. The origin receipt is the consumer's signed copy, and it goes to your customer with the result. |
| "We already have agent identities." | Identity says which agent. The origin receipt says what it was authorized to do, by whom, and what it produced. An agent's identity is not your company's authority. |
| "Microsoft's toolkit already issues verifiable receipts." | Its receipts are per tool call: the signature covers the call's arguments and the policy decision, and the result isn't in it. An origin receipt is bound to the exact bytes of the result and to the officer who authorized the policy. |
| "Doesn't Sentry produce attested telemetry?" | For the operator's security team, about what ran. The origin receipt is for whoever receives the result, about this result. |
| "Is this blockchain?" | Not required to use it. The root of authority is your company's registered key; a public chain is one optional way to anchor it. |
| "Don't hardware evidence packs do this?" | They prove what ran, on what hardware. The origin receipt proves who authorized it and what was asked. Their evidence goes inside it, on the Process line. |
| "Another thing to install." | Recipients install nothing. Operators add two OpenShell extensions; no agent code changes. |
| "Is it ready?" | A pilot program is opening, and we're looking for design partners. The live demo runs on a real OpenShell gateway today, with demo keys for an invented company; the verifier runs in your browser. A pilot is a real deliverable with a written result. |
See what your recipient would see.
The sample takes a minute. A pilot takes 30 days.