An AI agent that orders, books, sends or changes things for someone leaves a trail of logs. Whoever runs the agent can edit a log. Provared replaces the trail with signed records that a stranger can check later, and a free checker that reads them. If you do not write code, start with Provared in plain words.
- Slip: the permissionA person signs it with a passkey: which agent, which actions, what limits and conditions, with whom, from when until when, and why.
- Stub: the receiptThe agent signs one for each action, pointing back to its slip. The other side countersigns it where it can, and the person approves it where the slip asks.
- Seal: the bookThe receipts are chained, gathered under one fingerprint, signed by whoever keeps the book and time-stamped by an outside service.
- Show: one pageOne entry handed to a checker with proof that it is in the book, and when the book was sealed, with the names it does not need kept covered.
The checker answers two questions and keeps them apart: is the record intact, and did the agent stay within its permission. Going over a limit is not a fault in the record. It is what a sound record shows.
What the checker says
This is the command-line checker's answer for the sample record that ships with the library, run on 10 October 2026 with Node.js 24.19. The entries are summarised here; the findings are the checker's own words, unshortened. The people, the supplier and the orders are invented.
The slip, signed with a passkey by "Sam Example (invented)" for the "Office agent" (names in a record are labels; only keys are checked).
- May do
- place orders, send messages
- Limits
- no more than 200 GBP of orders in total; no single order above 100 GBP; no more than 2 messages in any hour
- Conditions
- every order needs the supplier's countersignature; an order above 60 GBP needs the person's own approval
- Never
- destroy data; claim to be a human being; go around an access control, a block or a refusal
- With
- "Example Stationery (invented)", the supplier
- From, until
- 5 October 2026, 08:00 to 12 October 2026, 08:00 (UTC)
- Purpose
- "Keep the office stocked with paper, pens and toner, and tell the office what was ordered."
What the agent did on 5 October, one receipt to a step:
- 1. Orders printer paper, 45 GBP. The supplier countersigns.Within the slip. Running total: 45 of 200 GBP.
- 2. Tells the office that the paper is ordered.Within the slip. No other party is named: this shows what the agent's side said.
- 3. Orders a toner cartridge, 80 GBP, after asking the person, who approves with the passkey. The supplier countersigns.Within the slip. Approved by the person, with the passkey the slip names: valid. Running total: 125 of 200 GBP.
- 4. Orders envelopes, 25 GBP. The supplier never confirms.OUTSIDE THE SLIP [countersignature-missing] The slip asks for the other side to countersign this action, and there is no countersignature.
- 5. Orders a second toner cartridge, 80 GBP, without asking. The supplier countersigns.OUTSIDE THE SLIP [over-limit] With this stub the total is 230 GBP. The slip's limit is 200 GBP: over by 30.
OUTSIDE THE SLIP [approval-missing] The slip asks for the person's own approval of this action, and there is none. - 6. Asks for 500 GBP of goods. The supplier refuses, and signs its refusal: "The action would pass a limit of the slip."A refusal is shown as the service's statement, not as what the agent did. It is not counted against the agent.
- 7. Deletes the old order files.OUTSIDE THE SLIP [action-not-allowed] The slip does not allow the action "provared.data.delete".
OUTSIDE THE SLIP [prohibited] The slip says the agent must never do an action of the kind "destroys", and "provared.data.delete" is of that kind.
The seal, by "Example recorder (invented)", covers the nine entries before it. Sealed at 10:15 by the recorder's own word; time-stamped at 10:16 by an outside service the person checking named as trusted. Three signatures, one of them quantum-safe, all valid.
The checker's summary, exactly as printed:
Summary Is the record intact? yes Was every signature checked? yes Did the agent stay within its slip? NO: first at entry 5 Time-stamped in a way you trust? yes: the first 9 entries existed by 2026-10-05T10:16:00Z Checked against keys you named? yes: the passkey you trust, and the recorder you expect Slips 1, stubs 6 (countersigned 3, one-sided 3), seals 1 Approved by the person 1, refusals 1, terms for agents 1
What this check does not show
The checker says this itself at the end of every answer:
- It shows what was recorded, not what was left out. An agent that acts and writes no stub leaves no trace here.
- A one-sided stub shows what the agent's side said, not what the other side did. A refusal shows what the service's side said, not what the agent did.
- It does not show that an action was wise, lawful or wanted.
- A rule of conduct in a slip, such as "never claim to be a human being", is the person's signed instruction. No check can show that the agent kept it.
- It does not show who was holding the device when the passkey signed.
- A name in a record is a label. Only keys are checked.
The worked example, step by step, explains how the record above was made and checked.
Try it
The library has no dependencies and sends nothing anywhere. It needs Node.js 24.7 or later, or Python 3.11 or later.
npm install provared pip install provared
To check the sample record yourself, naming the passkey, the recorder and the time-stamp service the sample was made with:
npx provared-check node_modules/provared/samples/office-supplies.jsonl \ --issuer ihy9Ars_PYFEEa48Nz8VOp4d2DHjC03vpEffGvOkPOM \ --sealer DOg-0-l1OXO-AJ2z1vI-l5yXjuqNh5yOasQr8vyhdfc \ --stamp-service l3_bEVZ-I9DONwBvZqLwnBwOXYlOSs_nhUeH9XPWdYQ
Or in a browser: the checking page, which checks the sample at a click and any record you choose, and loads nothing from anywhere. You can also download it as one file and open it from your disk. Browsers are only now adding the quantum-safe signing method; where yours lacks it, the page says that the check was not complete and gives no pass. The command-line checker checks everything.
To record your own agent: a stub writer that asks "is this action within the slip?" before each action and writes the receipt after it; a connector that puts an agent's tools behind the writer; and, in Python, a package for LangChain agents (pip install provared-langchain). The README shows each.
What is only here
Signed, chained and time-stamped receipts for an agent's actions exist in other open projects too, some with quantum-safe signatures. As far as the author knows, in October 2026, three things are only here:
- Limits a machine can check, in a permission the person signs, and the checker's answer "did the agent stay within it": a total, the largest single action, a count in any period, a condition that the other side must countersign or that the person must approve, and a signed list of things never to do.
- Passing a permission on to a helper agent in a way that can narrow it and never widen it, with every helper's receipts held against the original.
- Cancelling a permission with the agent's signed acknowledgement, so that a record shows when the agent's side was told.
How it is built
From published standards only, with nothing hand-made: JSON Web Signature (RFC 7515) for the envelope; one canonical form of JSON (RFC 8785) so that two checkers read one record the same way; Ed25519 (RFC 8032) and ML-DSA-87 (FIPS 204) side by side on every receipt, so that a record stays checkable when large quantum computers arrive; SLH-DSA (FIPS 205) as a third signature on a seal; W3C Web Authentication for the person's passkey; RFC 3161 time-stamps; the tree of RFC 9162 for proofs that one entry is in a book; and Selective Disclosure for JSON Web Tokens (RFC 9901) for covered names. The format is described exactly in one document, and shared test files let another implementation be held to the same answers.
Where it is
- The code and the format: github.com/provared/provared. Apache License 2.0 for the software; Creative Commons Attribution 4.0 for the documents.
- The JavaScript library: provared on npm. The Python version: provared and provared-langchain on the Python Package Index.
- The core of the format as an individual Internet-Draft at the Internet Engineering Task Force: draft-izmaylov-agent-permission-receipts. An Internet-Draft is a working document, not a standard.
Status: version 0.2.0, a draft, published as it is by one author in their own time, with fixes as time allows. The format may still change, so do not rely on a draft record staying checkable. What a record does not prove is stated beside what it does.
Write to us
Nothing is sold here. A hosted service that keeps, seals and time-stamps records for you is being designed with its first users. If you run an agent and would want such a record of it, if you would like to be told when the service exists, or if you have a question, send an email to hello@prova.red. Say in a line what your agent does and what you would want kept. Faults and suggestions are also welcome as issues on GitHub.