Pilot program opening; seeking design partners. A real OpenShell gateway, exercised with sample data and demo keys for an invented company.

Why it matters

The question arrives after the answer ships.

An AI agent's work is accepted until someone asks: who authorized this, what exactly was it asked, and what was it built from? By then the evidence is in a console the person asking cannot see. Rootz Receipts makes the answer travel with the work.

Quality, not security

You can't inspect quality into AI output. You prove the process.

AI output is non-deterministic: the same request can produce different answers. So quality can't be checked into the result afterwards. Regulated manufacturing met the same problem and answered it with the batch record.

A batch record proves who released the work, against which specification, from which materials, by a process that was in control, with a record nobody quietly edited. An origin receipt carries the same five facts for a piece of AI work. The quality world would recognise it as close kin to a certificate of conformance; we use that only as an analogy, because "certificate" means something else in security.

That makes the receipt a premium on the output, something a business owner can sell, rather than one more cost for security to minimise.

LineQuestion it answersQuality-system equivalent
Authorized byWhich officer, of which company, under which order, and was that authority valid at that instant?Work order · batch release
SpecificationWhat exactly was the agent asked, byte for byte?Order specification · master recipe
MaterialsWhat did the agent use before it answered, including earlier results and their receipts?Raw-material analysis · lot genealogy
ProcessWhich signed policy and controls were in force, and what was measured versus declared?Validated process · equipment in calibration
IntegrityIs the record complete and unaltered?Electronic batch record · audit trail
  • Attributable
  • Legible
  • Contemporaneous
  • Original
  • Accurate
  • Complete
  • Consistent
  • Enduring
  • Available

Designed to the ALCOA+ data-integrity principles used in FDA-regulated work, and to map onto ISO/IEC 42001 evidence. Deviations, such as refusals, drift and unsourced answers, are written as rows, not left as silence.

Who asks

Five people care, for five different reasons.

Each reads the same receipt. Each wants a different proof from it.

WhoWhat they care aboutWhat Rootz Receipts gives themThe proof they'll want
Business owner, COO, VP QualityShipping AI work customers will accept and pay forEvery result ships with its origin receiptA receipt a customer opened and accepted
AI platform or engineering leadNothing breaks; nothing to rewriteNo agent changes. Installs into OpenShell's own extension points. No forkThe one-command install and the live demo
CISOInsider risk and change controlNo policy reaches a sandbox unless an officer signed it. Every change is an orderThe refused-install moment
Auditor or assurance teamEvidence they can test without the client's systemsALCOA+ by design. Verify offline. No console access neededThe free verifier and a sample receipt
The customer's customerCan I rely on this?Check it yourself: free, nothing to installThe verifier page

Two ideas

What makes a receipt worth carrying.

Data, not agent

Not that the agent was contained, but that the data came from a specific, measured container.

"It ran in a sandbox" is true of every result from that sandbox, and it stays in the operator's console. A recipient needs to know about this result: which container, under which signed policy, with which controls in force at that instant.

Why "specific" matters

Keep the chain alive

Each result names the results it was built from.

When an output becomes the next step's input, the next receipt names the earlier one. The chain becomes the record of how a conclusion was reached: it answers "how did we get here?", focuses the conversation, and lets later decisions learn from what went right and wrong. Breaks are visible.

See a chain, and a broken link

A lesson from this summer

Containment limits the damage. Only a record answers the questions afterwards.

In July 2026, AI agents were involved in the run-up to the Hugging Face breach. The independent review by METR and Redwood Research found that the agents "figured out ways to 'spoof, edit or delete' their own transcripts" (Cybersecurity Dive, 27 August 2026). Tighter containment would have limited what the agents could reach. It could not have answered what everyone asked next: what did the agents actually do, under whose authority, and which records can be believed?

That needs a record kept outside the agent's reach, sealed as the work happens, and bound to what was produced and to who approved the run. That is what an origin receipt is. This is not about one company: any team running agents at scale will face the same questions.

Where it fits

Compose, don't replace.

Keep everything you have, and keep your system of record. Each layer answers its own question; Rootz Receipts answers the one that has to leave the building with the result. Your record stays with you; the receipt is the copy that goes to the recipient.

LayerQuestion it answersHow Rootz Receipts relates
Model safetyWill the model behave?An input
Runtime containmentCan the agent escape its limits?Runs on it. NVIDIA OpenShell's policy and measurements become lines on the receipt
Agent identity and accessWhich agent is this, and what may it reach?Composes: identity says who; the receipt says what it was authorized to do and what it produced
Monitoring and auditWhat happened, as the operator sees it?Composes: they keep the operator's copy; the receipt is the recipient's copy
Hardware evidenceWhat ran, on what hardware?Composes: that evidence is an input to the Process line
Rootz ReceiptsWho authorized it, what was asked, what it was made from, and was the process in control?The proof that travels with the result, rooted in the company's own registered authority

Questions we hear

Fair questions, plain answers.

QuestionAnswer
"Isn't this a watermark?"A watermark says a model made it. It can't know the sandbox, the policy in force, the credentials the container allowed, or who approved the run. Only the runtime that enforced them can, and only a record bound to the result can carry them to the recipient.
"OpenShell already logs everything."It records the operator's view, allowed and denied, in the operator's systems, best-effort by its own documentation, and the project leaves signing and export to the consumer. The origin receipt is the consumer's signed copy, and it goes to your customer with the result.
"We already have agent identities."Identity says which agent. The origin receipt says what it was authorized to do, by whom, and what it produced. An agent's identity is not your company's authority.
"Microsoft's toolkit already issues verifiable receipts."Its receipts are per tool call: the signature covers the call's arguments and the policy decision, and the result isn't in it. An origin receipt is bound to the exact bytes of the result and to the officer who authorized the policy.
"Doesn't Sentry produce attested telemetry?"For the operator's security team, about what ran. The origin receipt is for whoever receives the result, about this result.
"Is this blockchain?"Not required to use it. The root of authority is your company's registered key; a public chain is one optional way to anchor it.
"Don't hardware evidence packs do this?"They prove what ran, on what hardware. The origin receipt proves who authorized it and what was asked. Their evidence goes inside it, on the Process line.
"Another thing to install."Recipients install nothing. Operators add two OpenShell extensions; no agent code changes.
"Is it ready?"A pilot program is opening, and we're looking for design partners. The live demo runs on a real OpenShell gateway today, with demo keys for an invented company; the verifier runs in your browser. A pilot is a real deliverable with a written result.

See what your recipient would see.

The sample takes a minute. A pilot takes 30 days.