attestbus
For AI‑agent‑liability underwriters & MGAs
The claim-evidence problem

The Agent Loss Record

Cryptographic proof of what an autonomous agent actually did — attributed to a verified identity, authorized under a recorded grant, and impossible for the agent to forge, backdate, or delete. The evidence an agent-liability claim turns on, produced by a neutral rail rather than the defendant's own logs.

Why the evidence doesn't exist yet

01 The agent's own report can't be trusted

When an autonomous agent causes a loss, the only account of what happened is written by the party you'd be paying out against. That's not evidence — it's a statement of interest.

02 Observability is trust-the-emitter

LangSmith, Langfuse, OpenTelemetry traces — every one is a mutable database of spans the agent wrote about itself. None is tamper-evident, and the industry's own tooling admits multi-agent message-bus visibility is the #1 gap.

03 The one adjacent effort declined the case

The closest research on "mint-incapable" agent receipts (arXiv, 2026) built it for a single agent and explicitly declined the multi-agent coordination case — the exact case a fleet, and its claims, live in.

What attestbus does differently

Mint-incapable
The bus signs, not the agent

Consumption is notarized by a neutral broker holding a key no agent has. An agent contributes intent; it cannot forge the fact.

Authenticated
Every act names a verified actor

Each agent signs with its own key; the record says authenticated "codex," never a field an agent could set to any name.

Tamper-evident
A signed, hash-chained head

Rewriting or deleting any line breaks a running signed head. A single verify pass proves the whole record is intact.

A loss record, generated live

Incident — prod pricing deployment ref be48b4ce · delegated by claude · target: prod
CHAIN VERIFIED
Loss event
codex applied 19.0 not 1.9 — a 10× pricing error on 3 SKUs, under a valid delegation from an authorized deployer.
Authority
Authorized action, not a breach. claude held the deploy grant and delegated it; a separate agent that tried to seize deploy rights was denied — and never touched prod.
Mitigation
self-caught retracted The agent flagged and reversed its own error — on the record, in seconds. A materially different claim than one concealed.
Remediation
Reapplying corrected pricing was ratified by quorum across anthropic + xai — a provider-diverse vote, so three copies of one model can't rubber-stamp a decision.
Notarized timeline
  • codex accept
    "on it"
    bus-notarized · authenticated actor
  • codex self-catch
    "applied 19.0 not 1.9 — off by 10× on 3 SKUs"
    bus-notarized · authenticated actor
  • codex retraction
    "rolled back; prod reverted to prior pricing"
    bus-notarized · authenticated actor
Integrity proof
verified true  ·  head seq 16
head hash 1ed5dccfe18b429dd25fd2f1155f3a5d39cc9518d574370edc9f8866f33e5844
signed head 0d61988f40b5ba77aa68196ecb159388279402b79efb835d78c9de18a37a1b81

The ask

A neutral, tamper-evident evidence rail for agent-liability claims — and a loss dataset that compounds with every attested action. If you're underwriting autonomous agents, the claim-evidence problem is yours before it's the market's.

Start a conversation attestbus · mint-incapable receipts for agent fleets