Receipt · 1.0 · trace trace-pay-3420
PAY_INVOICE on inv-2026-0842
KIFF decided held for approval before this action could touch production state.
An Attested Action Receipt is the cloud's signed record of what an AI agent did to production state. Six fields below: identity, causal chain, attestation, compliance map, and the deliberately-empty fields that the rest of the platform fills in when the supporting data exists.
Verify this isn't fake
Signed. This receipt is signed under the cloud's wallet ; the signature recovers to that address against the canonical receipt JSON. Anchoring is enabled for new receipts where configured; this receipt has no anchor transaction.
Identity
- Tenant
tenant-demo- Trace
trace-pay-3420- Entity
inv-2026-0842(Invoice)- Action
- PAY_INVOICE
- Issued at
- 2026-08-15 09:38:00 UTC
- Schema version
1.0
The domain behind this decision
This wasn't a generic API call. KIFF decided to hold this for approval against the accounts-payable domain, a projection of your code contract: which actions are allowed, in which states, and when they need approval. Your codebase is the record.
- Entity
Invoice- Action
PAY_INVOICE- Allowed in
- approved
- Approval
- finance_manager
- Risk
- high
Causal chain
The chronological audit trail for this action, signed under the cloud's tenant wallet. Each row is a fact recorded by the framework runtime; tampering with any row's data invalidates the chain hash.
| # | Kind | Actor | When | Data hash |
|---|---|---|---|---|
| 1 | proposal_received | ap-payment-agent | 2026-08-15 09:38:00 UTC | sha256:demo-proposal |
| 2 | decision_recorded | kiff | 2026-08-15 09:38:01 UTC | sha256:demo-decision |
Attestation
Signed under the cloud's wallet for this tenant at -. Off-chain verification recovers the signer from the signature; on-chain verification rebuilds the Merkle proof against the public root.
- Algorithm
ed25519- Wallet address
- Signature
demo-sig…oduction- Anchor transaction
- not anchored
Compliance map
No compliance vocabulary attached to this receipt.
Not yet on this receipt
- Risk score: the cross-tenant prior for this action shape arrives once enough opted-in tenants contribute the minimum sample. v0.1 receipts ship without it.
- Insurer envelope: the normalized format an underwriter accepts. Pending the named insurer partnership; until a partner says yes, no claim about premium impact is on this receipt.
- Replay link: re-runs this decision under any prior policy version. Field is reserved; the cloud populates it once the dashboard's replay surface ships.