AERF, signed receipts for AI agent actions
Cosign for agent evidence with compliance mappings, but still draft spec.
Agent Evidence Receipt Format (AERF) — an open specification for tamper-evident, independently verifiable records of AI agent actions.
Cosign for AI agents: cryptographically signed receipts for every agent action.
AI infrastructure engineers and auditors
cosign · slsa-verifier
Cosign for agent evidence with compliance mappings, but still draft spec.
Ed25519 signed receipts solve AI agent accountability across org boundaries.
Proof-of-behavior for AI agents before Anthropic or OpenAI build their own.
Clever hash-chain audit trail for AI reproducibility, but demo-only with unclear adoption.
Governance rules live in version-controlled YAML and can be applied either by decorating functions with @sanna_observe or by dropping a gateway between an MCP client and downstream tools. It emits portable Ed25519-signed receipts you can persist and verify, which is a neat, practical way to build an auditable trail — the tough part will be ecosystem adoption around MCP and agent integrations.
Microsoft merged this teenager's code into their agent governance toolkit twice.