Provared

Proof of what an AI agent was allowed to do, and what it then did.

Evidence, not a verdict.

An AI agent that orders, books, sends or changes things for someone leaves a trail of logs. Whoever runs the agent can edit a log. Provared replaces the trail with signed records that a stranger can check later, and a free checker that reads them. If you do not write code, start with Provared in plain words.

The checker answers two questions and keeps them apart: is the record intact, and did the agent stay within its permission. Going over a limit is not a fault in the record. It is what a sound record shows.

What the checker says

This is the command-line checker's answer for the sample record that ships with the library, run on 10 October 2026 with Node.js 24.19. The entries are summarised here; the findings are the checker's own words, unshortened. The people, the supplier and the orders are invented.

The slip, signed with a passkey by "Sam Example (invented)" for the "Office agent" (names in a record are labels; only keys are checked).

May do
place orders, send messages
Limits
no more than 200 GBP of orders in total; no single order above 100 GBP; no more than 2 messages in any hour
Conditions
every order needs the supplier's countersignature; an order above 60 GBP needs the person's own approval
Never
destroy data; claim to be a human being; go around an access control, a block or a refusal
With
"Example Stationery (invented)", the supplier
From, until
5 October 2026, 08:00 to 12 October 2026, 08:00 (UTC)
Purpose
"Keep the office stocked with paper, pens and toner, and tell the office what was ordered."

What the agent did on 5 October, one receipt to a step:

  1. 1. Orders printer paper, 45 GBP. The supplier countersigns.Within the slip. Running total: 45 of 200 GBP.
  2. 2. Tells the office that the paper is ordered.Within the slip. No other party is named: this shows what the agent's side said.
  3. 3. Orders a toner cartridge, 80 GBP, after asking the person, who approves with the passkey. The supplier countersigns.Within the slip. Approved by the person, with the passkey the slip names: valid. Running total: 125 of 200 GBP.
  4. 4. Orders envelopes, 25 GBP. The supplier never confirms.OUTSIDE THE SLIP [countersignature-missing] The slip asks for the other side to countersign this action, and there is no countersignature.
  5. 5. Orders a second toner cartridge, 80 GBP, without asking. The supplier countersigns.OUTSIDE THE SLIP [over-limit] With this stub the total is 230 GBP. The slip's limit is 200 GBP: over by 30.
    OUTSIDE THE SLIP [approval-missing] The slip asks for the person's own approval of this action, and there is none.
  6. 6. Asks for 500 GBP of goods. The supplier refuses, and signs its refusal: "The action would pass a limit of the slip."A refusal is shown as the service's statement, not as what the agent did. It is not counted against the agent.
  7. 7. Deletes the old order files.OUTSIDE THE SLIP [action-not-allowed] The slip does not allow the action "provared.data.delete".
    OUTSIDE THE SLIP [prohibited] The slip says the agent must never do an action of the kind "destroys", and "provared.data.delete" is of that kind.

The seal, by "Example recorder (invented)", covers the nine entries before it. Sealed at 10:15 by the recorder's own word; time-stamped at 10:16 by an outside service the person checking named as trusted. Three signatures, one of them quantum-safe, all valid.

The checker's summary, exactly as printed:

Summary
  Is the record intact?                 yes
  Was every signature checked?          yes
  Did the agent stay within its slip?   NO: first at entry 5
  Time-stamped in a way you trust?      yes: the first 9 entries existed by 2026-10-05T10:16:00Z
  Checked against keys you named?       yes: the passkey you trust, and the recorder you expect
  Slips 1, stubs 6 (countersigned 3, one-sided 3), seals 1
  Approved by the person 1, refusals 1, terms for agents 1

What this check does not show

The checker says this itself at the end of every answer:

The worked example, step by step, explains how the record above was made and checked.

Try it

The library has no dependencies and sends nothing anywhere. It needs Node.js 24.7 or later, or Python 3.11 or later.

npm install provared
pip install provared

To check the sample record yourself, naming the passkey, the recorder and the time-stamp service the sample was made with:

npx provared-check node_modules/provared/samples/office-supplies.jsonl \
  --issuer ihy9Ars_PYFEEa48Nz8VOp4d2DHjC03vpEffGvOkPOM \
  --sealer DOg-0-l1OXO-AJ2z1vI-l5yXjuqNh5yOasQr8vyhdfc \
  --stamp-service l3_bEVZ-I9DONwBvZqLwnBwOXYlOSs_nhUeH9XPWdYQ

Or in a browser: the checking page, which checks the sample at a click and any record you choose, and loads nothing from anywhere. You can also download it as one file and open it from your disk. Browsers are only now adding the quantum-safe signing method; where yours lacks it, the page says that the check was not complete and gives no pass. The command-line checker checks everything.

To record your own agent: a stub writer that asks "is this action within the slip?" before each action and writes the receipt after it; a connector that puts an agent's tools behind the writer; and, in Python, a package for LangChain agents (pip install provared-langchain). The README shows each.

What is only here

Signed, chained and time-stamped receipts for an agent's actions exist in other open projects too, some with quantum-safe signatures. As far as the author knows, in October 2026, three things are only here:

How it is built

From published standards only, with nothing hand-made: JSON Web Signature (RFC 7515) for the envelope; one canonical form of JSON (RFC 8785) so that two checkers read one record the same way; Ed25519 (RFC 8032) and ML-DSA-87 (FIPS 204) side by side on every receipt, so that a record stays checkable when large quantum computers arrive; SLH-DSA (FIPS 205) as a third signature on a seal; W3C Web Authentication for the person's passkey; RFC 3161 time-stamps; the tree of RFC 9162 for proofs that one entry is in a book; and Selective Disclosure for JSON Web Tokens (RFC 9901) for covered names. The format is described exactly in one document, and shared test files let another implementation be held to the same answers.

Where it is

Status: version 0.2.0, a draft, published as it is by one author in their own time, with fixes as time allows. The format may still change, so do not rely on a draft record staying checkable. What a record does not prove is stated beside what it does.

Write to us

Nothing is sold here. A hosted service that keeps, seals and time-stamps records for you is being designed with its first users. If you run an agent and would want such a record of it, if you would like to be told when the service exists, or if you have a question, send an email to hello@prova.red. Say in a line what your agent does and what you would want kept. Faults and suggestions are also welcome as issues on GitHub.