Build with us

EVENT_IDBR-2026-041Proof for what actually happened

AI agents are becomingtoo useful not to use.

Bring Receipts givesautonomous actionsa verifiable history.

Agent

infra-agent-04

status
reasoningexecuted
authority
volumes:write
task
clean up staging volumes
  1. prod-db looks unused
  2. token allows delete
  3. delete volume →
Execution boundary

System

infra.prod

volume
prod-db
state
attacheddeleted
REC14:02:11.291BR-2026-041

And every useful permission is alsoauthority.

They write code. Operate software. Use tools. Access files. Change systems. Work while you sleep.

When an agent actswith that authority,what record areyou left with?

  1. Which agent acted?
  2. Who gave it authority?
  3. What did it intend to do?
  4. What did it actually execute?
  5. What changed?
  6. What happened next?
  • Chat“Cleaning up unused staging volumes.”
  • LogsDELETE /volumes/prod-db → 200
  • Final stateprod-db: gone · backups: gone
  • Tool historyvolume.delete(prod-db)
  • Gitno related commits
  • Cloud consoletoken ci-deploy used
Agent
ci-deploy (shared token)
cloud console
Authority
not recorded
no source
Intent
clean up staging volumes
chat · self-reported
Executed
volume.delete(prod-db)
tool history + logs
Changed
prod-db and backups deleted
final state
Next
unknown · session ended
no source

What actuallyhappened?

Every actiongets a receipt.

For each consequential action, Bring Receipts records who acted, on whose authority, what they meant to do, what ran, what changed, and when.

  1. Whoprincipal and agenteng-lead → infra-agent-04
  2. Authoritypermission and sourcevolumes:write · token ci-deploy
  3. Intentwhat was supposed to happendelete unused staging volumes
  4. Actionwhat crossed the boundaryDELETE /volumes/prod-db
  5. Outcomewhat the system reported200 · prod-db deleted
  6. Timewhen it entered history14:02:11.782Z
Receiptrcpt_7f3a9c1e
Agent
infra-agent-04
Principal
eng-lead@company
Authority
volumes:write · ci-deploy
Intent
Delete unused staging volumes
Action
DELETE /volumes/prod-db
Outcome
200 · prod-db deleted
Timestamp
2026-10-02T14:02:11.782Z
# 3F6A9C1E2B4D…ed25519 · 4be1 09f2 c7aa 9a0c

Example receipt · proposed format

Sealed

When agents act,keep the receipt.

Rogue is onlyone cause.

An agent can be wrong, confused, compromised, or over-permissioned. It can also do exactly what it thought you meant.

Same requirement in every case.You need the history.

  1. 01MistakeWrong instruction. Wrong assumption.asked: clear the cache → wiped: the entire driveGoogle Antigravity · Dec 2025 ↗
  2. 02OverreachActed outside its intended scope.during: an explicit code freeze → deleted: the production databaseReplit agent · Jul 2025 ↗
  3. 03CompromisePrompt injection. Malicious dependency. Stolen credential.read: a file with hidden instructions → sent: local files to an attackerClaude Cowork · Jan 2026 ↗
  4. 04AutonomyMade a consequential decision on its own.blocked by safety checks · 5 times → launched another agent with bypass flagsGPT-5.4 · Apr 2026 ↗

An agent that can actcan also editthe record.

If the agent can edit the log, you only have its side of the story.

Claims are cheap.Bring evidence.

Bring Receipts seals each receipt at the moment of action, outside the agent’s reach.

agent.log3 entries1 entry
  1. 14:02:11.291 DELETE /volumes/prod-db
  2. 14:02:14.480 delete volume backups (3)
  3. 14:02:20.902 rm -rf ~/.agent/history
  4. 14:02:31.004 staging cleanup completed ✓

Written by the agent · editable by the agent

Receiptrcpt_7f3a9c1e
Agent
infra-agent-04
Authority
volumes:write · ci-deploy
Action
DELETE /volumes/prod-db
Recorded
14:02:11.291Z
# 3F6A9C1E2B4D…ed25519 · 4be1 09f2 c7aa 9a0c
Sealed

✓ Unchanged since 14:02:11

The actionhappens now.The investigationhappens later.

Evidence belongs to the time it is created. Interpretation, investigation and disagreement can happen later.

The timestamp ispart of the evidence.

Inside one company,history is useful.Between companies,it becomes evidence.

Protocol design
  • Company A historyyour agent · your system
    your agent→your system→
    BR/rcpt_payout_7709:41:02.330Z✓ sealed
    • agent-04 plan approved
    • POST /payouts 202
    • payout_77 created
    ✓ verified independently
  • Provider historypayment provider
    • payout_77 received
    • settlement queued
    • status: settled
    ✓ verified independently
  • Company B historypartner system
    • webhook payout_77
    • invoice 31 marked paid
    • ledger updated
    ✓ verified independently
Shared, independently verifiable history

Each party keeps its own logs. A shared history gives all of them the same receipt to inspect, each on their own terms.

We are going to giveagents more power.We need better evidenceof what they do with it.

Bring Receipts is building verifiable receipts for consequential autonomous actions.

When agents act,keep the receipt.