Sometimes you want an AI agent to stop everything, right now.
Verax has a halt switch for that. Once an operator pulls it, every call the agent makes after that point is refused, and each refusal is signed and recorded like any other decision.
Who can pull it, and who can let go
On an install the switch is the command line: verax halt, and since 0.4.1 verax resume. Behind them are two HTTP doors. POST /api/halt accepts any operator session. POST /api/resume needs verax:approve. The agent's token carries neither, so the agent cannot stop itself to dodge a check, and it cannot lift a halt someone else set.
GET /api/halt answers whether the body is halted and who halted it.
The resume is written down first
Who halted, who resumed and when go to halt-history.jsonl, a file next to the switch. The resume line is written before the halt is lifted. If that line cannot be written, the body stays halted.
That file is a plain log, not a signed one. Since 0.4.2 each halt and resume is also written to the ledger as a control record signed by the body's record key, beside the signed refusals made while the switch is down, and verax verify fails on any allow inside a halt window. The body signs that record, not the operator.
What it doesn't do
A call that is already running when the switch is pulled is not cut off. The switch stops everything after it.
The halt is a file in this machine's state directory. It stops the body it sits next to, not one it cannot see.
In the film the switch is a lever. On a released install it is the command line and those two doors; the panel that would carry a real button opens through verax desktop, which is not released yet.
Episode 3 of the series, animated in three.js and voiced with ElevenLabs.
Source (Apache-2.0): https://github.com/verax-ai/verax
Top comments (0)