Skip to content

V4 ships today · V5 is the runtime

Knolo · Receipts

What a receipt proves.

A citation chip is not a receipt. A receipt is a portable claim about a read, a write, or a run that another machine can verify without calling HIVE.

Etched metal evidence plate and an archival strip under a teal work light.

Integrity

The evidence was not swapped after the fact. The span, the plan, and the image still hash to what the receipt names.

Replay

Another machine, given the same state root, the same plan, and the same authority, can reproduce the result.

Authorization

The actor was allowed to do this. Default-deny: if the capability was not committed state, the tool does not run.

Authenticity

The receipt came from a runtime that mounted this image under this contract — not from a screenshot of a chat.

Read / write / run

V4 proves the read. V5 proves the change and the run.

V4 · ships today

Read receipt

What was retrieved, from which image, under which plan, bound to which evidence spans. The current public contract.

V5

Write receipt

What changed in knowledge or memory, against which pinned snapshot, with which authority. Not the V4 surface.

V5

Run receipt

What the agent did: tools, budgets, approvals, resume points. The durable-run record V5 exists to produce.

Fail closed

If the receipt cannot be verified, the answer is not evidence. If the capability is not in the committed state, the tool does not run. Theater is the system that keeps going anyway.

What this page will not do

It will not publish a how-to for forging receipts, domain-separation strings, or storage layouts. Operators need to know what a receipt means. Attackers do not need a cookbook.

Related: EQL · V4 · V5