Auditors read the action receipt. The receipt cites the delegation. The delegation cites the passport. The chain is verifiable without us.
A regulator asks for the audit trail behind an agent action. Today the answer is text logs in Datadog or Kibana, with no chain of authority, no signed scope, no contestability surface, no proof of which inputs the agent saw at decision time. APS replaces text logs with cryptographic evidence that holds up under independent verification.
Public modules. Mapped to articles your auditor already reads.
Cryptographic audit trail mapped to real frameworks. EU AI Act Articles 14 and 26. NIST AI RMF across Govern, Map, Measure, Manage. ISO 42001 audit requirements. Generated from receipts on disk.
Action receipts as evidence, not as logs. Every receipt is signed, contestable, replayable. Authority-boundary receipts prove what the agent was authorized to do. Custody receipts prove what data the agent saw.
Cascade revocation as enforcement. When a delegation is revoked, downstream actions invalidate without a manual log search. The receipt ledger answers is this still authorized in a single signature check.
| Framework | Article | Requires | APS primitive |
|---|---|---|---|
| EU AI Act | Art. 14 | Human oversight | AuthorityBoundaryReceipt + HumanEscalationFlag |
| EU AI Act | Art. 26 | Transparency to deployer | ActionReceipt with signed scope chain |
| NIST AI RMF | GOVERN-1.1 | Accountability structures | Charter + offices, separation of powers |
| NIST AI RMF | MEASURE-2.7 | Risk evaluation evidence | CustodyReceipt + ContestabilityReceipt |
| ISO 42001 | A.6.2.6 | Decision audit trail | DecisionLineageReceipt, replayable |
| ISO 42001 | A.9.2 | Continuous monitoring | APSBundle Merkle aggregation |
The protocol specifies procedural validity. Effect safety is a separate axis, catalogued in Paper 8 (The Evidence-Safety Gap). We cite our own limits.
Issue receipts from your agents, run generateComplianceReport against the framework you operate under, hand the output to your auditor.
Hosted receipt store, framework templates, signed exports for regulators. Pricing on request.
[email protected] →