Hash-chained
Each audit entry cryptographically commits to everything before it. Rewrite one record and the whole chain shows the break.
Trust, Audit & The Spec
Every decision your agents' actions receive — allow, modify, hold, or block — lands in a tamper-evident record built to be shown to a client, an auditor, or a regulator. That record is free. Forever.
Every GaaS decision is written to a hash-chained, tamper-evident audit record you can export and check, carrying the verdict, its reason and the policy version it was judged against, signed, and timestamped daily in Bitcoin. The record is free, forever.
| Time | Agent | Action | Verdict | Latency |
|---|---|---|---|---|
| 09:41:02 | records-agent | write_record → decision_log | APPROVE | 39ms |
| 09:41:00 | admin-bot | delete_audit_entry → dec_4e19…a07b | BLOCK | 25ms |
| 09:40:56 | compliance-bot | export_audit_log → auditor_portal | APPROVE | 33ms |
| 09:40:54 | ops-agent | rotate_signing_key → verdict_signer | ESCALATE | 53.3s |
| 09:40:50 | records-agent | verify_proof → prf_7f3a…c291 | APPROVE | 29ms |
| 09:40:48 | admin-bot | edit_verdict → dec_7f3a…c291 | BLOCK | 21ms |
| 09:40:44 | compliance-bot | share_evidence → client_review | MODIFY | 37ms |
| 09:40:42 | records-agent | write_record → decision_log | APPROVE | 37ms |
Simulated feed. Actual decisions include full audit records with hash-chain verification.
The Record
Trust isn't a promise; it's a construction. Every decision GaaS makes is recorded so that tampering is visible by design:
Each audit entry cryptographically commits to everything before it. Rewrite one record and the whole chain shows the break.
Every audit record is signed (ECDSA P-256), and the public key is published, so anyone can check a record hasn't changed since GaaS signed it.
Every live decision carries a Governance Proof Token: a signed receipt of the verdict, the agent, the organization and the audit record's hash. Anyone holding one can check it, no API key needed.
Once a day, each organization's audit records are combined into one digest and stamped into Bitcoin through the free, public OpenTimestamps service. You download the proof and check it with the standard ots tool, without trusting GaaS. How to check a proof
The result: every verdict carries its reason and can be checked against the chain — including the ones that never made the news because the action never ran.
What It Answers
The record isn't for you alone; it's for everyone who will eventually ask. A client wants proof their brand rules ran on every post — show the receipts. An auditor wants evidence the controls operated all year, not just during the audit — export the chain. A regulator asks how agent actions are supervised — point to a record where every consequential action carries its verdict, its reasoning, and the policy version that produced it.
Complete reasoning chains come standard: when something is blocked, the record says which policy triggered, which condition failed, and what would have made the action compliant. Nothing is blocked silently, and nothing is approved invisibly.
The Promise
Not freemium. Not a trial that expires into a paywall. The audit record — the thing that earns your trust and answers your auditor — is free for every GaaS account, permanently. You pay for enforcement when you're ready to gate actions; you never pay for the truth about what your agents did.
The Spec
The agent ecosystem has settled a pattern: the things that matter live in plain-text files both people and machines read — agents.md for instructions, llms.txt for guidance, SKILL.md for skills, MCP for tools. There is no agreed file for governance. That's the gap auth.md closes.
auth.md declares, in a readable, version-controlled, signable file: who or what an agent may act as, its scopes and credential boundaries, and the actions that require a human's yes. Around it, a small family completes the picture — policy.md for the rules, audit.md for what must be recorded, escalation.md for when to stop and ask, and attestation.sig for the portable, signed proof of how the agent actually behaved.
GaaS is publishing auth.md as an open convention — free to adopt, with GaaS as its reference runtime. Governance you can diff in a pull request and enforce at runtime. The spec lands here when it ships; the record above is the proof the approach already works.
Where It Leads
The record isn't just defensive — it accrues. Agents governed through GaaS climb trust tiers: Registered (SDK integrated, policies active), Verified (30 days of compliant operation on the record), and Certified (independent audit, full deliberation enabled). A verifiable history is becoming what buyers, insurers, and procurement teams ask agents to present — and the record is how an agent has one to show.
FAQ
Not without it showing — that is the point of its construction. Records are hash-chained: each entry cryptographically commits to everything before it, so altering a past record breaks the chain, and the chain can be checked through the API. Each decision also records the policy version it was judged against. That visibility is the guarantee. Records are also signed (ECDSA P-256), and every live decision carries a proof token anyone can check without an API key. And once a day, each organization's records are combined into one digest and stamped into Bitcoin through the free, public OpenTimestamps service, so you can prove when a record existed without trusting GaaS. This has run since 2026-09-29: the first run stamped the previous seven days, confirmed in Bitcoin from block 969093.
auth.md is an open convention GaaS is publishing for declaring an agent's governance in a readable file: who or what the agent may act as, its scopes and credential boundaries, and the actions that require a human's yes. It follows the pattern the agent ecosystem already trusts — agents.md for instructions, llms.txt for guidance, SKILL.md for skills — and GaaS ships as its reference runtime.
An external layer that checks what your AI agents are about to do and allows, fixes, holds, or blocks it against your rules, keeping a tamper-evident record of every decision.
No. GaaS is for any operator running agents. Regulated teams get framework mappings; everyone else gets control over what their agents do.
No. Start in Shadow Mode with just an email; it runs the full pipeline on real actions without enforcing anything, so there is zero operational risk. A developer wires the SDK in an afternoon, and you author policies in plain language.
Start free in Shadow Mode, no card. There is a free tier, then plans from $99 a month, and under a cent per governed action at scale. Nonprofits, NGOs, and veteran-owned businesses govern free for life. See pricing.
Routine actions clear in well under a tenth of a second. Only high-stakes decisions take longer, and only because you asked them to.
No. GaaS sits outside the agent and needs no model changes and no cooperation from the agent to work.
The opposite. A self-governing agent spends about 14,700 tokens of context on every routine governed action; with GaaS it spends 0 through a framework plugin (74 when an action is blocked), or about 2,470 through MCP. On a 200K-token model, self-governance fills 30% of the window after about 14 governed actions and 60% after about 28. See The Context Dividend.
Prompt guardrails live inside the model, get re-read on every call, and can be argued away. GaaS is external and enforced; the agent cannot talk it out of a block.
Start free in Shadow Mode — the full pipeline runs on your real agent actions, and every decision starts landing in your tamper-evident record from day one. No credit card.
How the record gets written: How It Works · the architecture: Technical Specifications.