Cryptographic receipts for delegated AI agent work

Define the work before you delegate it. Prove it was done to spec.

Sequesign binds the mandate to the evidence. Every recorded action is hash‑chained, witness‑signed, and sealed with the mandate into a tamper‑evident receipt that anyone can verify offline.

$ sequesign verify ./invoice-approval.sequesign ✓ valid · L3_POLICY_BOUND
rec_37c17c5f8b6a50c8 task: invoice-approval
mandatetpl_invoice_approval_v2 · bound
delegatorbrent
agentregistered
act_001invoice_reviewed · $1,200.00
act_002payment_approved
witnesssigned
hash chain intact
sequence integrity
witness signature valid
work matches mandate
SEALED
·
L3 POLICY
BOUND
Built on open primitives
The platform

One sealed record, from mandate to proof.

Six stages, one chain of custody. The delegation terms go in before the work starts; the evidence comes out signed by every party that touched it.

01

Define

Pick or write a work template: scope, policy, expected actions, required attesters.

02

Delegate

Open a session bound to the mandate. The agent's identity and authority are fixed at the start.

03

Record

Each action you record is hash‑chained in sequence with its evidence. Nothing can be reordered or removed.

04

Seal

The receipt is finalized and witness‑signed. From here, any change is detectable.

05

Attest

Approvers and counterparties countersign the sealed record by hash. Same facts, every signature.

06

Verify

Anyone checks the package offline, or against a published trust anchor. No account. No vendor.

Five products, one chain of custody

Adopt the receipt. Grow into the proof.

The receipt format and verifier are open: that's how the receipt becomes common ground. Identity, anchoring, and multi‑party workflows are the managed layers, and that's where the assurance climbs.

Core · Open

Receipts

Tamper‑evident receipts for delegated agent work: recorded actions hash‑chained, witness‑signed, sealed against a pre‑bound mandate. Agent claims become proof.

seal · mandate binding
Open source

Verify

Independent verification from the package alone: integrity and mandate conformance checked offline, with zero trust in us required.

offline · zero‑trust

Registry

Enrolled agent and author identity. A receipt proves not just what happened, but which registered agent acted, and on whose authority.

graded assurance

Library

Managed storage, published trust anchors, and permanent citable receipt URLs. The self‑anchored receipt becomes the authoritative record.

anchors · template registry
Enterprise

Countersign

Approvals and counterparty countersignatures bound to the sealed receipt by hash. Every party attests to the same immutable facts.

multi‑party workflows
Pre‑delegated work templates

The mandate comes first. The proof comes sealed.

A log tells you what an agent did. A Sequesign receipt proves what it was authorized to do, and that the two match. Templates capture the delegation terms up front: spending limits, allowed actions, required evidence, who must countersign. The receipt is evaluated against the mandate at seal time, not reconstructed in a dispute.

Browse the template library →
tpl_invoice_approval_v2
max_amount$5,000.00 USD
allowed_actionsinvoice_reviewed · payment_approved
required_evidencevendor, invoiceId, PO match
countersignvendor + reviewer
conformance✓ work matches mandate
Tamper‑evident by construction

Stop trusting agent logs. Start verifying receipts.

Logs are editable, deletable, and hosted by the party with the most to gain from changing them. Sequesign chains every action to the one before it and has an independent witness sign the seal. Alter one byte after the fact and verification fails, loudly, for everyone.

Read the architecture →
chain state
act_001_invoice_reviewed
a3f9…c21e ← genesis
act_002_payment_approved
7d40…98b2 ← a3f9…c21e
seal + witness signature
✓ chain intact · witnessed
Multi‑party attestation

Every party signs the same facts.

Disputes over delegated work usually mean two parties, two records, and no shared ground truth. Sequesign approvals and countersignatures bind to the sealed receipt by hash: the delegator, the reviewer, and the counterparty each attest to one immutable record. When everyone signed the same receipt, there is nothing left to argue about.

See the countersign flow →
attestations · rec_8509cabb3fdf6eb5
brentdelegator · session origin
B. Sequesign
reviewer@acme.exampleapproval · work_submitted
approved
vendor‑abccounterparty countersignature
attested
Independent verification

Verification that asks no one's permission.

A trust product you have to trust is a contradiction. Any Sequesign package verifies offline from the files alone: hash integrity, sequence, witness signature, and conformance to the embedded mandate. Those are the legs that make a receipt evidence, and they never require asking us. Authorship assurance is the graded leg: anchor a registered author key when the stakes call for it.

Run the verifier →
$ sequesign verify ./package.sequesign
validtrue
levelL3_POLICY_BOUND
identityregistered
witnessedtrue
trust anchorexternal · library.sequesign.com
Why it holds up

First we bind the mandate.

Delegation terms, agent identity, and policy context are fixed into the session before the first action is taken. Authority is declared, not inferred later.

Then we prove the work.

Actions chain to each other, a witness signs the seal, attesters countersign by hash, and any verifier on earth can check the result without us.

6
independent checks in every verification, from hash integrity to policy conformance
3
graded assurance levels, up to policy‑bound with registered agent identity
0
API calls to verify a receipt — integrity and conformance check fully offline
1
sealed record that every party, and every future auditor, refers to
rec_eab451ac5ecd245f verified · L3_POLICY_BOUND · external anchor
Where it lands first

Built for agents with real authority.

Wherever an agent's action would matter in an audit, a dispute, or a regulator's file, the receipt belongs next to the work.

Healthcare administration

Prior auth, claims, referrals

Agents are calling payers and submitting authorizations today. When CMS or a health system asks what was submitted and under whose authority, a sealed receipt answers in seconds.

template: prior_auth_submission
See the live demo
Finance operations

Invoices, close, procurement

Approvals, reconciliations, and vendor spend executed by agents inherit the same audit obligations as the humans they replaced. Receipts make the SOX conversation short.

template: invoice_approval
See the live demo
Agent payments

Mandates for machine spend

Authorization protocols prove what an agent may spend. Sequesign proves what it actually did with that authority, closing the loop between intent and settlement.

template: bounded_spend_mandate
See the live demo
Legal & professional work

Delegated document work

When agents draft, file, and docket, privilege and malpractice exposure follow. A receipt is the difference between a billing narrative and admissible evidence of what was done.

template: document_execution
See the live demo
Physical AI & autonomous systems

Robots, drones, and vehicles

When a machine acts in the physical world — inside authorized airspace, under a speed or altitude limit — "it says it stayed in bounds" isn't evidence. A sealed record of what it did, and where, is.

template: flight_execution
See the live demo
Media & content provenance

AI-assisted publishing

When an agent drafts and publishes, readers deserve to know what it was sourced from and whether a human signed off. A content credential turns the byline's claim into something anyone can verify.

template: content_provenance
See the live demo
The regulatory floor is rising

Traceability is becoming a legal requirement, not a feature.

The EU AI Act's Article 12 requires high‑risk AI systems to keep records that make their operation traceable. Financial regulators are converging on mandate‑based authorization and audit trails for agent‑initiated transactions. Sequesign is the evidence layer those obligations assume you already have.

Design partner pilots · now open

Put a receipt on your agent's work this week.

The MCP proxy drops in front of your existing tooling in under a day. We do the integration with you. You get a cryptographic audit trail on one real workflow, free, as a design partner.