Prove what an AI coding agent did

A log a vendor can edit is a claim; a signed record is evidence. Scopebond signs every decision — allowed or blocked — into an Ed25519 scopebond:receipt carrying the action, the rule that decided it and cryptographic fingerprints, never file contents or prompts. Anyone can verify a receipt offline with the signing computer's public key and npx @scopebond/gateway@latest verify, no account. A valid signature shows the receipt was not changed and who signed it; it does not show that no receipt was removed, an external effect, or compliance.

1. Records happen automatically

Once the hook (or gateway, or GitHub Action) is in place, every decision is signed and stored. Read and check them:

scopebond-hook log
scopebond-hook verify                     # every local receipt, against this computer's key
npx @scopebond/gateway@latest verify ./receipt.json --key ./computer.pub.pem   # one receipt, offline

2. Hand a record to an auditor

A receipt verifies against the public key of the computer that signed it, with no network and no Scopebond account, so a client, insurer or auditor can confirm that receipt independently. The workspace (Scopebond Cloud) adds retention, a monthly report and evidence downloads on top of the same records. For records held in Cloud, Scopebond attests that the set is complete and in order; a signature alone cannot show that.

3. What a signature means

It supports integrity (the record wasn't altered) and provenance (who signed it) for what the signer asserted. It is not a claim about an external effect, completeness, or compliance — Scopebond keeps those distinctions explicit.

What this does not do

A receipt attests a decision, not a real-world outcome or a compliance verdict. Scopebond never mixes evidence classes or presents an unverified number as validated.

Alternatives

FAQ

Can the vendor alter the record?

Not without it showing: a changed receipt fails verification against the signing computer's public key, which you can check without Scopebond. A signature cannot show that a receipt was removed; for records held in Scopebond Cloud, completeness and order rest on Scopebond.

Does a signed receipt prove compliance?

No. It proves integrity and provenance for what the signer asserted. Compliance is a separate judgement; Scopebond keeps covered, uncovered and refused distinct.

Do I need an account to verify?

No. scopebond-hook verify, or npx @scopebond/gateway@latest verify with the signing computer's public key, checks a receipt with no account; the check itself makes no network call.

Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/cli.test.mjs). The single-record gateway verify command is not run by an automated test; the signature check behind it is (packages/gateway/test/init-e2e.test.mjs).