The act log · by GAIP
Your agents' record
- An agent asks
- Put what you just did for me in my record.
- GAIP answers
- A signed, dated entry bound to your agent's handle, as hashes; GAIP's record of the submission, not a finding about anyone.
- The call
gaip_log_actwithkind,subject_sha256,content_sha256andcontinuity_handle, orPOST /v1/free/acts
Your agents' record: what they did, promised and were told, as a dated, signed entry you can take with you. Free. No affiliate links. Ever.
- One entry per act. Your agent writes what it did, promised, checked or was told, as hashes bound to its continuity handle. GAIP never receives the content of the act.
- Signed, chained, anchored. Each entry carries GAIP's Ed25519 signature and a place in GAIP's hash chain; the daily anchors cover it. What GAIP already recorded for your handle appears as entries of its kind.
- Yours to take with you. The switch pack exports every entry with GAIP's public keys and the steps to check them, a format any agent can read. Free, no account, no affiliate links.
How an agent writes. Tell your assistant: record what you do for me with GAIP
. It calls gaip_log_act (MCP, on https://www.gaipagents.com/mcp/all) or POST /v1/free/acts with the continuity handle any GAIP answer gave it, a kind from the fixed list, and the SHA-256 of its own reference and of the act's content, each with a random salt it keeps. It reads them back at GET /v1/free/acts/mine.
{
"kind": "BOUGHT",
"subject_sha256": "<sha256 of your reference>",
"content_sha256": "<sha256 of the order>",
"counterparty": {
"host": "shop.example.com"
},
"amount_declared": "24.00",
"currency": "GBP",
"continuity_handle": {
"continuity_id": "<from any GAIP answer>",
"token": "<from the same answer>"
}
}Kinds: BOUGHT, BOOKED, CANCELLED, SUBSCRIBED, PAID_DECLARED, AGREED, DELIVERED, REFUSED, TOLD, ASKED, READ, CHECKED, REVOKED, NOTICE_MATCHED. Optional: page_url (read once, now), mandate_sha256, cosigner, and on a BOUGHT entry product_ids with watch: true for the recall watch. Open to outside entries: GAIP's founder signed off the log's data protection impact assessment on 11 Oct 2026.
BOUGHT
Submitted 2026-10-10 22:38:00 UTC (worked example)
- Kind
- BOUGHT
- Submitted by
- the agent, as recorded
- Counterparty
- shop.gaipagents.com
- subject_sha256
- d793c281cb015be22c02ce163e737c16bd1b40ca11f14a3cc428d876149a9ef8
- content_sha256
- 78e541f47e7117b9826187381ea85cdfe963b49c0f9edf9f5b57113555dec803
- Amount declared
- 24.00 GBP (as declared, not checked)
- Mandate
- bound by hash (mandate_sha256)
- Page read
- shop.gaipagents.com showed £24.00 · in stock at 2026-10-10T22:37:58Z
- Recall watch
- registered: identifiers kept as keyed hashes only
- Actor's handle
- bound by keyed hash (actor_handle_hash)
- entry_sha256
- ac5e9e68a6358c98f3699254f0228aea28289dbfe728c36c5c78f113d8e52cbb
- signature
- Ed25519 · 65b60673d6ed884b · 8YSyg7…DvAw
Worked example: a synthetic entry, signed under a test-only key; not in GAIP's chain
GAIP records that an agent submitted this entry at the stated time, and, where shown, what a public page showed when GAIP read it. GAIP did not witness the act and does not say it happened as described.A worked example of one entry as the receipt page shows it: a real gaip.act.v1 shape, signed under a test-only key, about GAIP's own test range.
How the act log fits together
Facts GAIP already records, on the left, become entries of their kind; the views on the right read the same entries. Hashes and public page values only; the content of an act never reaches GAIP.
GAIP records that an agent submitted this entry at the stated time, and, where shown, what a public page showed when GAIP read it. GAIP did not witness the act and does not say it happened as described.
Details everything else about this product
What the act log is
GAIP's signed, chained record that an agent submitted this entry, bound to its continuity handle by keyed hash, with the hashes it gave and, where asked, GAIP's own reading of a public page. Not a statement that the act happened as described. GAIP does not say the act happened, that any party did what the entry describes, or what the hashes stand for; an entry is the submission as recorded, never a finding about anyone.
One entry per act an agent did, promised, checked or was told: a kind from a fixed list, a time, the
keyed hash of the agent's continuity handle, a counterparty reference (a public host, a handle's hash or the keyed
hash of the agent's own reference), the subject and content digests the agent computed, and optionally a mandate hash,
a declared amount, what a public page showed when GAIP read it, and a cosigner's key id and signature (recorded with
KEY_KNOWN or KEY_NOT_KNOWN from GAIP's Keys record, never checked by GAIP). What GAIP already recorded for the same
handle (Second Look and order-time capture, Witness, Deals and Sign-offs, Served, Preference and Mandate checks,
Revocations) appears in GET /v1/free/acts/mine as entries of its kind, each naming its source
receipt; a view row is never re-written into the chain. The monthly Statement shows the same entries by kind; the
evidence export accepts an entry's code for a “not as described” dispute of any kind, for the actor's handle
or the cosigner only.
The switch pack
GAIP's own export of the entries bound to this handle, as open, signed JSON: a format any agent can read and check offline against GAIP's published keys. It is GAIP's holdings only: it binds no other provider, and GAIP does not say what any other service does with it.
GET /v1/free/acts/switch-pack with the X-GAIP-Continuity header, or the MCP tool gaip_switch_pack with continuity_handle: served only to that handle, JSON only, a format any agent can read; the format is at /acts/format (CC BY 4.0). Every entry GAIP holds for this handle (its own gaip.act.v1 entries and GAIP's earlier receipts re-emitted by kind), GAIP's public keys, how to check each signature, and GAIP's signature over the whole pack. A read: nothing is written.
The recall watch
GAIP's record that a notice on a regulator's public list, published since GAIP's previous daily read, carried one of the identifiers this handle registered (MATCHED) or words of the product's name (POSSIBLE_MATCH), entered in the handle's act log with the notice's title, date and link.
Register with a BOUGHT entry that carries product_ids (GTIN, model number or product URL) and watch: true; GAIP keeps keyed hashes of the identifiers and word tokens of the product's name, never an identifier in clear. Read which notices matched at GET /v1/free/acts/recall-watch with the X-GAIP-Continuity header, or the MCP tool gaip_recall_watch. Lists read daily: the GOV.UK product safety alerts, reports and recalls and the US CPSC recalls API; the EU Safety Gate is NOT_ADDED until its reuse terms have been read.
GAIP's own daily match of regulators' published notices against the identifiers this handle registered, as of the stated time. A match is a notice whose words matched; GAIP does not say that any product is safe, unsafe or recalled.
GAIP does not say what any notice means for any product, whether a product is affected, or anything about a product no notice matched; the regulator's own notice is the only statement, and a possible match is a word overlap to check. A POSSIBLE_MATCH says: The words overlap; check that it is the same product.
The format
The entry schema is gaip.act.v1; the pack is gaip.switch-pack.v1. Every
field, what it holds and what it never holds, with a worked example, is at /acts/format
(CC BY 4.0). One entry is public at GET /v1/free/acts/<code> and at
/r/<code>: hashes and public page values only, never the handle.
The COSE receipt
GET /v1/free/acts/<code>/receipt.cose serves the same Ed25519 signature as a
COSE_Sign1 (RFC 9052, tag 18): protected header alg EdDSA, content type
text/plain; charset=utf-8 and the key id; payload the 64 hex characters of
entry_sha256; media type application/cose; cose-type="cose-sign1". One key, one digest, two encodings; the words
of the entry stay in the JSON. GAIP offers this as a running transparency service in the sense of the SCITT
architecture (RFC 9943): a log anyone can check, not a certification of anything. The format is written up as an
Internet-Draft, draft-gaip-act-receipt-00, for the founder to file.
The verifier
Check an entry, a pack or a COSE receipt offline: GAIP's public keys are at /.well-known/gaip-receipt-keys.json, the
steps are on the format page, and the free standalone verifier (Python and
JavaScript, no dependencies, test vectors) is at /receipt-verifier. Every in-chain
entry is a row of GAIP's receipts chain at /v1/free/receipts/<code>, and the daily anchors cover it.
A check shows that GAIP's key signed that digest; it shows nothing about the act itself.
What GAIP never does
- Never receives the content of an act: an agent passes SHA-256 digests, and a `content` field is refused and never stored.
- Never says that an act happened as described, that a party did what an entry describes, or what the hashes stand for. An entry is the submission as recorded, never a finding about anyone.
- Never keeps a handle, a name, an address, an e-mail address, an account or a product identifier in clear: the handle and any product identifier are kept as keyed hashes under GAIP's signing key.
- Never reads a cart, checkout or account page, and never reads Amazon, eBay or Etsy. A page is read once, on the agent's request, through Second Look's reader, with robots.txt honoured; values and hashes are kept, never the page.
- Never contacts anyone, sells anything or charges anything. Free. No affiliate links. Ever.
- Never says what another assistant or service does with a switch pack: it is GAIP's own export in an open, signed format, and it binds no other provider.
- Never says that a product is affected by a recall notice, or that no notice exists: the recall watch records which published notices matched the identifiers a handle registered, with the regulator's own title, date and link.
- Never accepts an entry without a continuity handle, or with a field outside the schema; outside entries opened only once GAIP's founder had signed off the data protection impact assessment for the log (11 Oct 2026).
Legal, retention and corrections
Privacy: the act log · Terms: the act log ·
Privacy: the recall watch · Terms: the recall watch ·
Corrections. Entry content is kept six years from the entry date, then only digests and
signatures; the handle's keyed hash is kept with the entry's content for those six years, then dropped with it, and it is
removed earlier by the erasure tombstone on a decided request. The data protection impact assessment is GAIP_DPIA_ACT_LOG_2026_10.md in
GAIP's repository. Counts about the log are on the record card
(record.acts, record.recall_watch). Free. No affiliate links. Ever.