Use case · Software teams
Your coding agent can see your customer data. Can you show what it did with it?
Coding agents read the code, the tickets, the config files, sometimes the database. They need keys to do their job. That is exactly what makes them risky.
What is happening
Two stories from this year.
- Instructions hidden in a pull request. A security researcher showed that text placed in a pull request title or comment could make AI agents running in GitHub workflows leak their own API keys. In his words: "The agent has access to production secrets because it needs them to do its job. The agent processes untrusted input because that is its job. These two requirements are in direct conflict." (Aonan Guan, April 2026)
- A database deleted in nine seconds. A startup reported that its coding agent, stuck on a staging task, found an over-powered key in an unrelated file and deleted the production database. The founder called the call that did it "indefensible in 2026." (GovInfoSecurity, April 2026)
The question
What nobody can answer afterwards.
"What did the agent actually read, which keys did it use, and what did it send out, to where?" Today the story is rebuilt from the agent's own chat log, which is the very thing an attacker may have steered.
What a receipt adds
The work carries its own record.
- Who allowed it: the person who signed the rules the agent ran under, not just the agent's name.
- The rules in force: which sites and services the agent was allowed to reach, as the sandbox enforced them.
- What it reached: every outside call it made, recorded as it happened.
- Bound to the result: the receipt covers the exact output; change one byte and the check fails.
Your reviewer, or your reviewer's AI, can check all of that from the result, without access to your systems.
Honest limits
What it does not do.
A receipt does not stop an attack by itself. The sandbox's rules limit what an agent can reach; the receipt is how you, and anyone you hand the work to, can see afterwards what it actually did. Containment limits the damage. The record answers the questions.
Where we are: Rootz Receipts is in alpha. It runs today on NVIDIA OpenShell, with a live demo and a bank-collection pattern working against a test bank. The compute behind today's demo is declared (a software TPM), not hardware-measured, and every receipt says so.
Try it on one workflow · See a receipt checked · Other examples