Decision
The approved request and the human or policy decision bound to it.
Bind the decision, artifact, policy, environment, and output into one reviewable execution record. Verification and evidence are available today. Runtime enforcement remains deployment-specific.
Execution identity
sha256:decision + artifact + policy + environment + output
A conventional activity log says something ran. Execution Trust makes the material inputs and outputs addressable so reviewers can detect drift, substitutions, and missing proof.
The approved request and the human or policy decision bound to it.
The exact code, prompt bundle, document, or payload used by the run.
The exact policy version evaluated before execution.
Runtime, dependencies, deployment boundary, and tool identity.
The exact produced result and its evidence package.
Managed verification and evidence custody in the GRIFFai control plane.
Keep sensitive data or execution local while synchronizing bounded proof.
Verify receipts on the operator machine without requiring a cloud execution path.
Run the control plane, policy boundary, and evidence store inside your infrastructure.
Compare the expected identity with the observed receipt before accepting an outcome.
Move from summary to hashes, actors, timestamps, policy versions, and linked artifacts.
Attach runtime admission controls only where the deployment has a verified enforcement adapter.