The guard sits between an agent and its tools. Operators approve what the policy holds back. Everything lands in a signed log that anyone can verify.
An agent never calls a tool directly. It asks the guard, and the guard answers from a policy the agent can’t change. Everything that happens, whether asked, allowed, denied, approved, failed or harmful, is appended to the agent’s signed log. How Lineage works →
The same prompt-injected agent, without and with the guard.
The model is the same, and so is the injected text. The difference is that the model’s requests now pass through something that says no, holds risky actions for a person, and keeps evidence. Why Lineage →
Checks run in this order and the first failure wins. The scar each denial leaves is shown underneath.
A request passes six checks. The first failure denies it; some denials leave a scar, because asking for a forbidden tool is itself a signal. Decisions and scars →
The states an action moves through. Every transition is one signed record in the agent's log.
Pending actions cost nothing until approved, and they’re checked again at approval time. An action approved an hour later, after its agent was terminated, is denied. Approvals →
Each record carries the previous record's hash and is signed. Editing one breaks its hash, and every link after it.
Every record carries the hash of the one before it and an Ed25519 signature. Changing any byte breaks that record’s hash; recomputing the hash breaks the signature; deleting a record breaks the chain. Published checkpoints also catch the tail being cut off. The audit log →