Prove what an AI coding agent did
A log a vendor can edit is a claim; a signed record is evidence. Scopebond signs every decision — allowed or blocked — into an Ed25519 scopebond:receipt carrying the action, the rule that decided it and cryptographic fingerprints, never file contents or prompts. Anyone can verify a receipt offline against the signer's public key with npx @scopebond/verify@latest, no account. A valid signature supports integrity and provenance; it does not by itself prove an external effect or compliance.
1. Records happen automatically
Once the hook (or gateway, or GitHub Action) is in place, every decision is signed and stored. Read and check them:
scopebond-hook log
scopebond-hook verify
npx @scopebond/verify@latest ./receipt.json # verify a single record, offline
2. Hand a record to an auditor
A receipt verifies against the signer's published key with no network and no Scopebond account, so a client, insurer or auditor can confirm it independently. The workspace (Scopebond Cloud) adds retention, a monthly report and exports on top of the same records.
3. What a signature means
It supports integrity (the record wasn't altered) and provenance (who signed it) for what the signer asserted. It is not a claim about an external effect, completeness, or compliance — Scopebond keeps those distinctions explicit.
What this does not do
A receipt attests a decision, not a real-world outcome or a compliance verdict. Scopebond never mixes evidence classes or presents an unverified number as validated.
Alternatives
- Agent Receipts — a receipts format for agent actions; Scopebond both blocks before an action runs and signs an offline-verifiable record, and can interoperate.
- Microsoft Agent Governance Toolkit — governance + receipts; Scopebond focuses on fail-closed enforcement plus a portable signed record.
FAQ
Can the vendor alter the record?
No — the record is cryptographically signed and verifies offline against the signer's public key, independent of Scopebond.
Does a signed receipt prove compliance?
No. It proves integrity and provenance for what the signer asserted. Compliance is a separate judgement; Scopebond keeps covered, uncovered and refused distinct.
Do I need an account to verify?
No. npx @scopebond/verify@latest checks a receipt offline with no account and no network.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/verify/test).