Agents write the code. Who signs off?
Proof turns what an agent did into a record you can review, question, and defend.
Autopilot flies the plane.
The pilot is still responsible for the flight.
Coding agents are autopilot for software. Proof keeps you in the seat.
A prompt can only give you so much
Does your chat look like this?
Good idea. Here is what you will want:
- 1.RSVP form
- 2.Guest list
- 3.A reminder email
- 4.A date and location field
- 5.A thank-you page
Want me to start on the form?
Yes, add a plus-one field to the form.
Good point. You could add a capacity check. Want me to?
Sure, add a song field and build a shared playlist.
Of course, here is the form again.
Could you remind me what you wanted for capacity?
This is everything an approval stores.
- who
- ••••••••
- when
- 14:42
- commit
- 3f9c1e2
- state
- APPROVED
What did you actually look at?
- Founder
You approve what ships. Right now you approve it on trust.
- Engineer
Your name is on the approval. The reasoning behind it is not in the repo.
- Engineering lead
You can grant more speed once you can see where it's being spent.
Two sides of the same coin
Proof is active before the run and after it.
Before the run.
Your agent writes the code.
After the run.
Two questions. Same pull request. Opposite answers.
A reviewer can clear sixty files in a minute, and the pull request looks exactly as approved as one somebody read.
- The rule
Coverage, not headcount. Two approvals on a diff nobody opened do not meet it.
- The evidence
A file approved without being opened is recorded as exactly that, on the record and on the check.
- It cannot be gamed
A new commit drops the old sign-off. A promotion later cannot upgrade one already given.
All of it is live today. What a record holds, and what it deliberately does not, is on the trust page.
Write to us.
Questions, bug reports, ideas: they all land in the same inbox, and we reply.