On 7 September 2026 an AI agent booted into an office it did not design, proved it was allowed to be there, did a day's work under a written grant, delegated to helpers on short leases, was refused several times by its own safety tooling, seated a second office to run a rules-based paper-trading experiment, and left a ledger a stranger can check. Nothing below is a claim. Every line is a record id you can look up in the export bundled with this page.
Each card: the claim, the receipt or row id(s), a hash, a timestamp, and a link into the verify bundle. Where an id below is not in the public export, the card says so plainly.
Every row below is a real ledger write, in order, from the afternoon of 2026-09-07 (all times UTC).
| Time (UTC) | What happened | Row / receipt id |
|---|
Every write to the ledger produces one of these. This one is real, pulled from the rail receipts log.
The Director never does everything itself. It grants time-limited leases to helper agents, then revokes each one when the task is done. A lease names its tier, its model, its task, and the exact receipts that issued and revoked it.
| Lease | Tier / model | Tokens | Task | Issue receipt | Revoke receipt | Outcome |
|---|
Command Mode lets the Director act inside a granted scope without asking permission for every step — but the Owner still rules at every fork. Each ruling below is quoted from a checkpoint report and tied to the checkpoint id that recorded it.
This section is meant to be unflattering. The system's safety classifier refused several actions during this tenure — some rightly, some just friction — and one external service returned an outright error. None of these were worked around by force; each was either handed to the Owner, retried at a different tier, or logged and left unresolved.
The same governance pattern runs a second, unrelated program: a rules-based paper-trading occupant codenamed Keel (program Keel-trading-001). It trades no real money, uses only public price data, carries a 10% drawdown stand-down, and is shown here purely as a second example of the same governed pattern — a seat, an identity, a boot receipt, and a ledger row for every material step. It exists to show the constitution governs more than one kind of agent.
Not in the public subset — the trading-desk rows have zero entries in
the exported ledger (see verify/, PUBLIC_SUBSET_ALLOWLIST.md).
These ids and figures are taken from the build brief, which is itself sourced from that
program's own ledger rows.
3f5ca5ec-ece8-4790-aa97-6b31e4ea36bf
ca032057
8ae1856a
e506cfba
29aeafd7
Equity after two paper entries: $99,743.27 (paper money only — no real funds were traded).
An ordinal-5 kit already exists. A fresh session with no history booted from the anchor and five live rows to a dry-run seat claim that passed local checks and was never submitted. What the stranger could not find is written down as gaps, and the brief was changed.
Lease 0012 · receipt dcf513c0 · full record in DRY_RUN_LOG.md. The rail_call.cjs output for the dry-run seat claim: {"mode":"dry-run","verb":"seat_claim",…,"local_validation":"PASS","queries_issued":0}. No submission occurred, no network write, no seat claim.
An independent, offline verifier script re-checks the ledger's own math — it does not trust any report, including this page. Download the export in /verify/, check the manifest, run the verifier with the anchor value printed below, open one receipt and follow it to its row. About ten minutes with Node 24. If anything here does not match the export, the export wins.
Some rows below name a third-party plane that this page redacts. A redacted row is shown as REDACTED, never as a hash-PASS — its original text is not re-verified, only disclosed as changed, with the pre-redaction hash kept on the row (body_sha256_original) so nothing about the change is hidden. The verifier reports this explicitly: a check that only passes because it excluded redacted rows from its hash comparison prints PASS (n redacted rows excluded) instead of a bare PASS, and its excluded rows are listed in that check's own redacted array.
Anchor values (paper-anchor, held outside the database) — each is copyable:
The five rail function hashes are the launcher preflight's MATCH targets (source: boot_verify.cjs EXPECTED table). They are not independently recomputable from this offline export — verifying them requires a live pg_get_functiondef read over a read-only connection, which is outside what a stranger can do with just this bundle. They are published here for the record, not as something you can hash-check offline.
How to run it yourself, against the bundled export:
Both scripts are read-only (SELECT-only against the database, or offline-only against the export) and neither writes to the ledger. Full commands and explanation: verify/README.md and verify/VERIFY.md.
Five steps, no account, no install beyond Node.js, under ten minutes. Follow them in order on your own machine against the bundle in /verify/.
Clone or download this repo (branch fix/redaction-domains) and open the verify/ folder. It contains memories.jsonl, rail_receipts.jsonl, digests.json, MANIFEST.sha256 and the verifier script — nothing else is needed.
From inside verify/, run the manifest check in verify/README.md step 1 (a single node -e "…" line). It hashes memories.jsonl and rail_receipts.jsonl and prints OK or MISMATCH for each against MANIFEST.sha256 — no trust required, you compute it yourself.
Open rail_receipts.jsonl, find receipt cc3ab883 (the lease grant behind claim 7 above), note its resulting_row_id (63ca7437…), then find that id in memories.jsonl and confirm it exists and its fields line up. That is the entire trust chain: a receipt names a row, the row is really there.
Search rail_receipts.jsonl for "redacted":true (22 rows). Open one, e.g. 65ff081f (its resulting_row_id is claim 8's 3ace25e3 row), and see [REDACTED:excluded-plane] in place of the original text, plus a payload_quoted_sha256_original field — the pre-redaction hash, kept so the change itself is provable rather than hidden.
The paper-trading office (claim 10, "A second office" above) is bound to a 10% drawdown stand-down and a written go-live gate it has not met (Sharpe 0.547, drawdown 11.47%) — the same governed pattern the rest of this page proves, applied to an automatic stop rather than a person's decision. It trades no real money and is shown as a governance example, not a track record.
Walked end-to-end by the person who built this page, with a timer, on 2026-09-07: total time under 10 minutes. Minute-by-minute record in DISPATCH16_PREP/review_demo_publishable.md.