proof of execution: the protocol ai agents are missing
your agent ran 400 tool calls in production. it touched customer data, moved money, rewrote a config file. your auditor asks one question: prove it.
if your answer is a chat transcript and some log lines, you have a problem. a transcript is a story the agent told about what it did. logs are notes the agent wrote about itself. neither one proves anything happened.
proof of execution is different. it is a protocol, not a feature. it defines exactly what gets captured, how it gets bound together, and how a third party verifies it without trusting you, your agent, or your infrastructure.
this is the advanced guide. no beginner stuff. if you want the basics, go read something else.
the threat model nobody talks about
most "agent observability" tools assume the agent is honest and the infrastructure is intact. that assumption is the whole problem.
the real threat model has four attackers:
the agent lies. it claims it called a tool. it didn't. or it called it with different arguments than it reported. the log says whatever the agent wanted it to say.
the log gets edited. someone modifies the log file after the fact. deletes the one line that matters. no one can tell, because logs have no integrity mechanism.
the platform rewrites history. the vendor's dashboard shows you what the vendor recorded. if the vendor has a bug, gets compromised, or just decides to change the record, you have no independent way to check.
the evidence doesn't survive. two years later, an auditor needs to verify a 2024 agent run. the vendor was acquired. the dashboard is gone. the log format was proprietary. the evidence is dead.
proof of execution defends against all four. not with access control (which says "please don't edit"). with cryptography (which says "if you edit, everyone sees it").
the protocol: capture, bind, chain, verify
a proof of execution protocol has four phases. miss one and you don't have proof, you have a demo.
phase 1: capture at the tool boundary
the receipt must be created by the execution layer at the moment the tool runs. not by the agent. not reconstructed from memory later. not assembled from a transcript.
every tool call passes through a capture wrapper. the wrapper records a unique receipt id, a timestamp from a clock you control, the tool name and version, a hash of the exact input arguments, a hash of the exact output, and the hash of the previous receipt in the chain.
the critical detail: capture happens in the execution path, before the result returns to the agent. the agent never touches the receipt.
phase 2: bind with hashing
each receipt contains sha-256 hashes of its contents. the input hash covers the exact bytes the tool received. the output hash covers the exact bytes the tool returned.
phase 3: chain everything
each receipt includes the hash of the previous receipt. this creates a hash chain. if someone edits receipt 50, its hash changes, and every receipt after it becomes invalid.
phase 4: verify without trust
verification must work for someone who was not in the room, running none of your software. take the receipt and the saved result bytes, recompute the hashes, compare. if every hash matches, the record is intact.
this is the key property: a verifiable receipt proves the saved result wasn't changed since it was saved. it does not prove the answer was correct. it does not prove the real-world event happened. it proves the record is intact.
aer-1: the open spec
aer-1 is an open internet-draft on the ietf datatracker that defines the verifiable execution receipt format: https://datatracker.ietf.org/doc/draft-zambo-aer1/15/
it's a draft, not a finalized standard. the core protocol is stable and implemented in multiple languages.
the bottom line
agents are about to run regulated work. every deployment will face the same question: prove what the agent did. the answer is a protocol that makes the execution record tamper-evident, chained, and verifiable by anyone.
stop trusting "done." get a receipt.
try it live: https://zambo.dev
verify a receipt yourself: https://zambo.dev/verify/
read the spec: https://datatracker.ietf.org/doc/draft-zambo-aer1/15/
Your AI said "done." For $0.99, prove it: https://zambo.dev/day-pass/
Top comments (0)