The thesis
AI has learned to act. Now it needs authority.
The first wave of AI produced intelligence. This one hands systems the power to do things: approve credit, flag a patient, move money, change production. Every one of those is an exercise of authority somebody delegated, and there is almost no infrastructure for recording that delegation.
People have delegated authority for centuries. Machines have a config file.
Every instrument on the left binds a decision to somebody who answers for it, and each one can be produced later and checked by a person who was not there. The right-hand column is what an autonomous system has instead.
For people
Binds a person to a document.
Binds an agent to a principal.
Binds a representative to a scope.
Binds a decision to a ceiling.
Binds a commitment to an approval.
For autonomous systems
Binds nothing anyone outside can check.
Binds by the system under review.
That is the whole column. Identity infrastructure answers which agent is acting, and answers it well. What a specific action was authorised to do, under which instruction and which rule, is a separate question, and it is the one still open.
Four things happen before the action, and one after.
The first four are inside the operator's systems. The fifth is the only one that matters when the decision is challenged, and it has to work for someone who was never inside them.
The instruction the session is bound to. Immutable once registered.
The rules the organisation wrote, evaluated against the declared action.
Cleared or refused, before the model or the tool is reached.
Signed either way. A refusal is a record, not an absence.
Verified offline against a published key, by someone who need not trust the operator and never contacts us.
The signer is not the subject.
A record is worth something to a reviewer only because the party that made the decision is not the party vouching for it, and because none of the three can quietly do the others' job. The limits are as load-bearing as the capabilities.
Seal
issues the record- Evaluate the policy over the declared action
- Sign the outcome and the moment
- Verify who the agent was
- Prove the action then executed as declared
The operator
holds the record- Produce the record on demand
- Export a pack for review
- Alter a signed field without the check failing
- Decide whether it is accepted
The reviewer
checks the record- Verify offline against a published key
- Accept, override or refuse on the record
- Be required to trust the operator
- Be required to contact Aqta
An argument you can check in two commands.
Everything above is a claim. This is a real record from the production gateway: an AI agent proposed a push to production, and policy refused it before anything ran.
curl -sL https://app.aqta.ai/samples/sample-action.json -o record.json npx aqta-verify-receipt record.json --profile action-1 --key <published key>
It reports valid. Change one character of the file and the signature fails. The key comes from the published key endpoint, and the format, both verifier implementations and 50 conformance vectors are public, so nothing in that check depends on trusting us.
The record formatWhat it does not proveCheck one in your browserRun a pilot