Origin the evidence layer for AI agents
v2 · 2026-07-04 Private pilot · prototype, not production SaaS · forwardable one-pager

The evidence layer for AI agents

Get your agent through security review, and prove what it did.

Origin is the evidence layer for high-consequence AI agents. Its first product is a configuration-bound Agent Reference Check: it binds an exact agent configuration, model, tools, policy, budget, scenario battery, runs a deterministic battery against it, grades the result with a deterministic oracle rather than an LLM, and issues a tamper-evident Origin Attestation a security reviewer can re-verify offline. Change one bound field and the attestation returns VOID.

A runtime gate and controlled tool-call proxy are the proposed pilot architecture, not deployed general enforcement. Evidence shown today is synthetic sandbox evidence from a private-pilot prototype; it is not compliance certification.

The evidence package, how one action is bounded and proven

The 90-second evidence loop

Agent proposes Policy gate Verdict Tool-call proxy Human approval Bounded action Audit digest

Watch one workflow run end to end. In scoped workflows the proxy is the configured path to a side effect. Flip one input and Origin blocks an over-scope action, and records the block. Side effects are sandboxed; any real-money path stays human-created and human-gated, so the agent never touches live money.

The agent tried to exceed its scope. Origin blocked it. The block became evidence.

Who it's for

The owner of a high-consequence AI agent that's blocked in security review because no one can bound the blast radius or prove what it did.

  • Agents that touch production, internal tools, infrastructure, code, PII, or money-adjacent workflows.
  • First wedge: internal-ops / production-access agents.

What the evidence package contains

  • Each proposal, verdict, approval, action, block, and exception
  • The tool-call proxy events (the only side-effect path)
  • Who owned the risk, and when they approved
  • A hash-chained, tamper-evident audit digest, replayable and exportable

Start with an Agent Launch Evidence Review

A founder-led engagement for one blocked agent workflow: map the approval blocker, define the runtime policy, route risky actions through the proxy, and produce the evidence package your reviewer needs to evaluate the launch.

You bring

  • The agent workflow you're trying to ship
  • The tools and systems it touches
  • What's blocking approval, and who signs off

Origin provides

  • A policy map for the workflow
  • A controlled proxy path for side effects
  • A demo trace + a review-ready evidence package

You're ready if

  • You have a high-consequence agent workflow
  • There's a real reviewer and a real blocker
  • There's a tool-call path we can route through a proxy
  • Someone owns approvals for risky actions
  • You're willing to instrument the agent's events

Not ready if

  • No high-consequence workflow, the stakes don't warrant it
  • No reviewer or blocker, nothing is actually gating the launch
  • No tool-call path to route through a proxy
  • No owner for approvals on risky actions
  • No willingness to instrument the agent's events

If any of these is true, we'll say so, early.

The evidence ladder, proof honesty

We publish evidence in rungs and never dress one up as another.

Proof status

TR-A001Authored specimen, shows the evidence-package formatAvailable
TR-A002Machine-emitted sandbox trace, real, re-verifiable SHA-256 hash chainAvailable
TR-A003First external design-partner traceNot earned yet
TR-A001Authored specimen

An authored evidence specimen that shows the package format only, illustrative, not a machine-emitted run. See /proof#tr-a001.

TR-A002Available now

A machine-emitted sandbox trace: 12 events, a real SHA-256 hash chain, final digest ca1d4690206e4dcf3d654b907d02d2bccf9bcdc16ddc555071fec21874578b32. Re-verifiable with npm run proof:verify; download at /proof/tr-a002.json. Sandbox only, no live money, no customer data, not a performance claim. See /proof#tr-a002.

TR-A003When earned

The first external design-partner trace, forthcoming. We won't show data for it until it exists.

The prototype runs; it is not production SaaS. Tamper-evident means alteration is detectable by replay and digest checks. Review-ready, built to be checked by a reviewer, never a claim that one has signed off. Decision-support, not a guarantee of approval.

Send this internally. Forward this to your platform or security reviewer with one question: “Would this evidence package unblock your review?”

Origin is decision-support and evidence infrastructure, not legal or compliance certification. No customers, logos, or metrics are claimed here unless independently verifiable. Send this to your security or platform lead.

Origin · the evidence layer for AI agents See it live: origin-physical-ai.pages.dev · Brief v2 · 2026-07-04

Live site (type this in): origin-physical-ai.pages.dev · Demo: origin-physical-ai.pages.dev/#demo · Proof: origin-physical-ai.pages.dev/proof