Trust, Audit & The Spec

A record no one can quietly rewrite.

Every decision your agents' actions receive — allow, modify, hold, or block — lands in a tamper-evident record built to be shown to a client, an auditor, or a regulator. That record is free. Forever.

Every GaaS decision is written to a hash-chained, tamper-evident audit record you can export and check, carrying the verdict, its reason and the policy version it was judged against, signed, and timestamped daily in Bitcoin. The record is free, forever.

org_demo · audit record
Simulated
TimeAgentActionVerdictLatency
09:41:02records-agentwrite_record → decision_logAPPROVE39ms
09:41:00admin-botdelete_audit_entry → dec_4e19…a07bBLOCK25ms
09:40:56compliance-botexport_audit_log → auditor_portalAPPROVE33ms
09:40:54ops-agentrotate_signing_key → verdict_signerESCALATE53.3s
09:40:50records-agentverify_proof → prf_7f3a…c291APPROVE29ms
09:40:48admin-botedit_verdict → dec_7f3a…c291BLOCK21ms
09:40:44compliance-botshare_evidence → client_reviewMODIFY37ms
09:40:42records-agentwrite_record → decision_logAPPROVE37ms
GOVERNING
15,540 decisions

Simulated feed. Actual decisions include full audit records with hash-chain verification.

The Record

What the record is, mechanically.

Trust isn't a promise; it's a construction. Every decision GaaS makes is recorded so that tampering is visible by design:

Hash-chained

Each audit entry cryptographically commits to everything before it. Rewrite one record and the whole chain shows the break.

Signed records

Every audit record is signed (ECDSA P-256), and the public key is published, so anyone can check a record hasn't changed since GaaS signed it.

Proof tokens anyone can check

Every live decision carries a Governance Proof Token: a signed receipt of the verdict, the agent, the organization and the audit record's hash. Anyone holding one can check it, no API key needed.

Timestamped daily in Bitcoin

Once a day, each organization's audit records are combined into one digest and stamped into Bitcoin through the free, public OpenTimestamps service. You download the proof and check it with the standard ots tool, without trusting GaaS. How to check a proof

The result: every verdict carries its reason and can be checked against the chain — including the ones that never made the news because the action never ran.

What It Answers

"Show me your safeguards" — already written.

The record isn't for you alone; it's for everyone who will eventually ask. A client wants proof their brand rules ran on every post — show the receipts. An auditor wants evidence the controls operated all year, not just during the audit — export the chain. A regulator asks how agent actions are supervised — point to a record where every consequential action carries its verdict, its reasoning, and the policy version that produced it.

Complete reasoning chains come standard: when something is blocked, the record says which policy triggered, which condition failed, and what would have made the action compliant. Nothing is blocked silently, and nothing is approved invisibly.

The Promise

The record is free. Forever.

Not freemium. Not a trial that expires into a paywall. The audit record — the thing that earns your trust and answers your auditor — is free for every GaaS account, permanently. You pay for enforcement when you're ready to gate actions; you never pay for the truth about what your agents did.

The Spec

Governance is becoming a file you can read.

The agent ecosystem has settled a pattern: the things that matter live in plain-text files both people and machines read — agents.md for instructions, llms.txt for guidance, SKILL.md for skills, MCP for tools. There is no agreed file for governance. That's the gap auth.md closes.

auth.md declares, in a readable, version-controlled, signable file: who or what an agent may act as, its scopes and credential boundaries, and the actions that require a human's yes. Around it, a small family completes the picture — policy.md for the rules, audit.md for what must be recorded, escalation.md for when to stop and ask, and attestation.sig for the portable, signed proof of how the agent actually behaved.

GaaS is publishing auth.md as an open convention — free to adopt, with GaaS as its reference runtime. Governance you can diff in a pull request and enforce at runtime. The spec lands here when it ships; the record above is the proof the approach already works.

Where It Leads

A record that compounds into trust.

The record isn't just defensive — it accrues. Agents governed through GaaS climb trust tiers: Registered (SDK integrated, policies active), Verified (30 days of compliant operation on the record), and Certified (independent audit, full deliberation enabled). A verifiable history is becoming what buyers, insurers, and procurement teams ask agents to present — and the record is how an agent has one to show.

FAQ

Every objection, answered.

Can the GaaS audit record be altered or deleted?

Not without it showing — that is the point of its construction. Records are hash-chained: each entry cryptographically commits to everything before it, so altering a past record breaks the chain, and the chain can be checked through the API. Each decision also records the policy version it was judged against. That visibility is the guarantee. Records are also signed (ECDSA P-256), and every live decision carries a proof token anyone can check without an API key. And once a day, each organization's records are combined into one digest and stamped into Bitcoin through the free, public OpenTimestamps service, so you can prove when a record existed without trusting GaaS. This has run since 2026-09-29: the first run stamped the previous seven days, confirmed in Bitcoin from block 969093.

What is auth.md?

auth.md is an open convention GaaS is publishing for declaring an agent's governance in a readable file: who or what the agent may act as, its scopes and credential boundaries, and the actions that require a human's yes. It follows the pattern the agent ecosystem already trusts — agents.md for instructions, llms.txt for guidance, SKILL.md for skills — and GaaS ships as its reference runtime.

What is GaaS, in one sentence?

An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.

Do I have to be a regulated business?

No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.

Is it hard to set up?

No. Start in Shadow Mode with just an email; it runs the full pipeline on real actions without enforcing anything, so there is zero operational risk. A developer wires the SDK in an afternoon, and you author policies in plain language.

What does it cost?

Start free in Shadow Mode, no card. There is a free tier, then plans from $99 a month, and under a cent per governed action at scale. Nonprofits, NGOs, and veteran-owned businesses govern free for life. See pricing.

Will it slow my agents down?

Routine actions clear in well under a tenth of a second. Only high-stakes decisions take longer, and only because you asked them to.

Do I have to change my agent or my model?

No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.

Doesn't governance cost me tokens?

The opposite. A self-governing agent spends about 14,700 tokens of context on every routine governed action; with GaaS it spends 0 through a framework plugin (74 when an action is blocked), or about 2,470 through MCP. On a 200K-token model, self-governance fills 30% of the window after about 14 governed actions and 60% after about 28. See The Context Dividend.

I already have prompt guardrails. Why GaaS?

Prompt guardrails live inside the model, get re-read on every call, and can be argued away. GaaS is external and enforced; the agent cannot talk it out of a block.

Start the record today. It costs nothing, forever.

Start free in Shadow Mode — the full pipeline runs on your real agent actions, and every decision starts landing in your tamper-evident record from day one. No credit card.