Two drawings. The first is one action being governed. The second is a proof leaving the system and being checked by someone who does not trust us. Every box below is real code with a real file behind it.
PLATE 1 One action, governed
Left to right in time. The grant is sealed before any work — that ordering is the
product. An envelope written afterwards can be shaped to excuse whatever happened.
Four claims per action, and the agent authors none of them. If the thing being
investigated writes its own record, you have a log. The grant is sealed by whatever opens the
session, the proposal and refusal by the gate, the execution by the executor, the
post-condition by an independent read.
This plate is no longer hypothetical — a real production refusal, walked step
by step with claim IDs and sequences, is in the reference doc under A production refusal,
sealed. It governs work driven through the agent harness; the platform's own
in-cluster autonomous routes are a separate build.
PLATE 2 How a proof leaves the building
Sealed entries take two independent paths: one builds meaning, the other builds
proof. They answer different questions and neither substitutes for the other.
Two paths, two different questions. The proof path answers is this unchanged, and
when did it exist. The meaning path answers was it ever sound. A record can pass
the first and fail the second — one did, in production, for four days.
Three separate properties, and it's worth keeping them apart when you talk. The chain
says the record is unaltered. The external timestamp says it existed by a
moment we don't control. The per-entry signature — added 16 August 2026 — says
who attested to it, and the key needed to check that is published at an
unauthenticated URL, so a stranger fetches it once and verifies offline from then on. The
bundle carries all three today. The verifier page still does not exist, which is why
the auditor box is dashed: an auditor can verify the bundle, but today they need their own
tooling to do it.