EVENT_IDBR-2026-041Proof for what actually happened
AI agents are becomingtoo useful not to use.
Bring Receipts givesautonomous actionsa verifiable history.
Agent
infra-agent-04
- prod-db looks unused
- token allows delete
- delete volume →
System
infra.prod
REC14:02:11.291BR-2026-041And every useful permission is alsoauthority.
They write code. Operate software. Use tools. Access files. Change systems. Work while you sleep.
When an agent actswith that authority,what record areyou left with?
- Which agent acted?
- Who gave it authority?
- What did it intend to do?
- What did it actually execute?
- What changed?
- What happened next?
- Chat“Cleaning up unused staging volumes.”
- LogsDELETE /volumes/prod-db → 200
- Final stateprod-db: gone · backups: gone
- Tool historyvolume.delete(prod-db)
- Gitno related commits
- Cloud consoletoken ci-deploy used
- Agent
- ci-deploy (shared token)
- cloud console
- Authority
- not recorded
- no source
- Intent
- clean up staging volumes
- chat · self-reported
- Executed
- volume.delete(prod-db)
- tool history + logs
- Changed
- prod-db and backups deleted
- final state
- Next
- unknown · session ended
- no source
What actuallyhappened?
Every actiongets a receipt.
For each consequential action, Bring Receipts records who acted, on whose authority, what they meant to do, what ran, what changed, and when.
- Whoprincipal and agenteng-lead → infra-agent-04
- Authoritypermission and sourcevolumes:write · token ci-deploy
- Intentwhat was supposed to happendelete unused staging volumes
- Actionwhat crossed the boundaryDELETE /volumes/prod-db
- Outcomewhat the system reported200 · prod-db deleted
- Timewhen it entered history14:02:11.782Z
- Agent
- infra-agent-04
- Principal
- eng-lead@company
- Authority
- volumes:write · ci-deploy
- Intent
- Delete unused staging volumes
- Action
- DELETE /volumes/prod-db
- Outcome
- 200 · prod-db deleted
- Timestamp
- 2026-10-02T14:02:11.782Z
Example receipt · proposed format
When agents act,keep the receipt.
Rogue is onlyone cause.
An agent can be wrong, confused, compromised, or over-permissioned. It can also do exactly what it thought you meant.
Same requirement in every case.You need the history.
- 01MistakeWrong instruction. Wrong assumption.asked: clear the cache → wiped: the entire driveGoogle Antigravity · Dec 2025 ↗
- 02OverreachActed outside its intended scope.during: an explicit code freeze → deleted: the production databaseReplit agent · Jul 2025 ↗
- 03CompromisePrompt injection. Malicious dependency. Stolen credential.read: a file with hidden instructions → sent: local files to an attackerClaude Cowork · Jan 2026 ↗
- 04AutonomyMade a consequential decision on its own.blocked by safety checks · 5 times → launched another agent with bypass flagsGPT-5.4 · Apr 2026 ↗
An agent that can actcan also editthe record.
If the agent can edit the log, you only have its side of the story.
Claims are cheap.Bring evidence.
Bring Receipts seals each receipt at the moment of action, outside the agent’s reach.
- 14:02:11.291 DELETE /volumes/prod-db
- 14:02:14.480 delete volume backups (3)
- 14:02:20.902 rm -rf ~/.agent/history
- 14:02:31.004 staging cleanup completed ✓
Written by the agent · editable by the agent
- Agent
- infra-agent-04
- Authority
- volumes:write · ci-deploy
- Action
- DELETE /volumes/prod-db
- Recorded
- 14:02:11.291Z
✓ Unchanged since 14:02:11
The actionhappens now.The investigationhappens later.
Evidence belongs to the time it is created. Interpretation, investigation and disagreement can happen later.
The timestamp ispart of the evidence.
We are going to giveagents more power.We need better evidenceof what they do with it.
Bring Receipts is building verifiable receipts for consequential autonomous actions.
When agents act,keep the receipt.