L1 · Mandate
Mandate-bound work
Every record traces back to the adapter, policy, and contract that authorized it — upstream of the work itself.
Live
L3 · Proof
ProofPack evidence
Portable, signed, content-addressed bundles — hash chain, signed Merkle tree head, embedded key directory.
Live
L4 · Gate
Acceptance-gated consequence
A verified proof is not authorization. Payout / deployment / handoff / API action fires only after acceptance clears.
Live
L4 · Exact-auth
Exact authorization
Acceptance decides whether the consequence may proceed; exact authorization binds the approved action to configured consequence fields. Tier-1 Acceptance is the live guard; Tier-2 enforcement is set per deployment — shadow mode is not enforced Tier-2. Authorization metadata does not itself perform the external action.
Deployment-set
L6 · Execution
Enterprise-owned execution
The enterprise or its provider performs the external action. AiGentsy governs permission and holds the causal trail — never custody of credentials, funds, target systems, or result payloads.
Non-custodial
L7 · Verifier
Offline verification
Standalone aigentsy-verify==1.5.0 checks bundle hash, event chain, Merkle inclusion, signed STH — no runtime call.
Live
L8 · Reconcile
OutcomeReceipt vs reconciliation
OutcomeReceipt is a performer-signed outcome attestation. Reconciliation is a later caller-attributed observation — additive and non-overwriting — and does not by itself prove external-world truth.
Explanatory