GAIPGoverned Agentic Intelligence Platform

The act log · by GAIP

Your agents' record

An agent asks
Put what you just did for me in my record.
GAIP answers
A signed, dated entry bound to your agent's handle, as hashes; GAIP's record of the submission, not a finding about anyone.
The call
gaip_log_act with kind, subject_sha256, content_sha256 and continuity_handle, or POST /v1/free/acts

Your agents' record: what they did, promised and were told, as a dated, signed entry you can take with you. Free. No affiliate links. Ever.

  1. One entry per act. Your agent writes what it did, promised, checked or was told, as hashes bound to its continuity handle. GAIP never receives the content of the act.
  2. Signed, chained, anchored. Each entry carries GAIP's Ed25519 signature and a place in GAIP's hash chain; the daily anchors cover it. What GAIP already recorded for your handle appears as entries of its kind.
  3. Yours to take with you. The switch pack exports every entry with GAIP's public keys and the steps to check them, a format any agent can read. Free, no account, no affiliate links.

How an agent writes. Tell your assistant: record what you do for me with GAIP. It calls gaip_log_act (MCP, on https://www.gaipagents.com/mcp/all) or POST /v1/free/acts with the continuity handle any GAIP answer gave it, a kind from the fixed list, and the SHA-256 of its own reference and of the act's content, each with a random salt it keeps. It reads them back at GET /v1/free/acts/mine.

{
 "kind": "BOUGHT",
 "subject_sha256": "<sha256 of your reference>",
 "content_sha256": "<sha256 of the order>",
 "counterparty": {
  "host": "shop.example.com"
 },
 "amount_declared": "24.00",
 "currency": "GBP",
 "continuity_handle": {
  "continuity_id": "<from any GAIP answer>",
  "token": "<from the same answer>"
 }
}

Kinds: BOUGHT, BOOKED, CANCELLED, SUBSCRIBED, PAID_DECLARED, AGREED, DELIVERED, REFUSED, TOLD, ASKED, READ, CHECKED, REVOKED, NOTICE_MATCHED. Optional: page_url (read once, now), mandate_sha256, cosigner, and on a BOUGHT entry product_ids with watch: true for the recall watch. Open to outside entries: GAIP's founder signed off the log's data protection impact assessment on 11 Oct 2026.

GAIP receipt · the act logac-vrpj42fggwgj

BOUGHT

Submitted 2026-10-10 22:38:00 UTC (worked example)

Kind
BOUGHT
Submitted by
the agent, as recorded
Counterparty
shop.gaipagents.com
subject_sha256
d793c281cb015be22c02ce163e737c16bd1b40ca11f14a3cc428d876149a9ef8
content_sha256
78e541f47e7117b9826187381ea85cdfe963b49c0f9edf9f5b57113555dec803
Amount declared
24.00 GBP (as declared, not checked)
Mandate
bound by hash (mandate_sha256)
Page read
shop.gaipagents.com showed £24.00 · in stock at 2026-10-10T22:37:58Z
Recall watch
registered: identifiers kept as keyed hashes only
Actor's handle
bound by keyed hash (actor_handle_hash)
entry_sha256
ac5e9e68a6358c98f3699254f0228aea28289dbfe728c36c5c78f113d8e52cbb
signature
Ed25519 · 65b60673d6ed884b · 8YSyg7…DvAw

Worked example: a synthetic entry, signed under a test-only key; not in GAIP's chain

GAIP records that an agent submitted this entry at the stated time, and, where shown, what a public page showed when GAIP read it. GAIP did not witness the act and does not say it happened as described.

A worked example of one entry as the receipt page shows it: a real gaip.act.v1 shape, signed under a test-only key, about GAIP's own test range.

How the act log fits together

How the act log fits togetherFive kinds of record GAIP already keeps feed the act log as entries of their kind; the act log is one entry per act, bound to a handle, signed, chained and anchored, hashes and public values only; its views are the Statement, the switch pack, the dispute export, the recall watch and the SCITT and COSE receipt; underneath run Ed25519 receipts, the hash chain, daily anchors and continuity handles.Second Look, order captureBOUGHT, READ, with a page readWitness, Deals, Sign-offsAGREED, DELIVERED: two signersServedTOLD: a notice deliveredPreferences, MandatesCHECKED before an actRevocations and keysREVOKED; the agent's own fileThe act logone entry per act, bound to a handle,signed, chained, anchored;hashes and public values onlyStatementthe month, per handleSwitch packtake it to your next agentDispute exportnot as described, any kindRecall watchBOUGHT entries, matched noticesSCITT and COSE receiptthe drafts' own formatAlready running underneath: Ed25519 receipts, the hash chain, daily anchors, continuity handlesHow the act log fits togetherFive kinds of record GAIP already keeps feed the act log as entries of their kind; the act log is one entry per act, bound to a handle, signed, chained and anchored, hashes and public values only; its views are the Statement, the switch pack, the dispute export, the recall watch and the SCITT and COSE receipt; underneath run Ed25519 receipts, the hash chain, daily anchors and continuity handles.Second Look, order captureBOUGHT, READ, with a page readWitness, Deals, Sign-offsAGREED, DELIVERED: two signersServedTOLD: a notice deliveredPreferences, MandatesCHECKED before an actRevocations and keysREVOKED; the agent's own filebecome entries of their kindThe act logone entry per act, bound to a handle,signed, chained, anchored;hashes and public values onlyits viewsStatementthe month, per handleSwitch packtake it to your next agentDispute exportnot as described, any kindRecall watchBOUGHT entries, matched noticesSCITT and COSE receiptthe drafts' own formatAlready running underneath:Ed25519 receipts, the hash chain,daily anchors, continuity handles

Facts GAIP already records, on the left, become entries of their kind; the views on the right read the same entries. Hashes and public page values only; the content of an act never reaches GAIP.

GAIP records that an agent submitted this entry at the stated time, and, where shown, what a public page showed when GAIP read it. GAIP did not witness the act and does not say it happened as described.

Details everything else about this product

What the act log is

GAIP's signed, chained record that an agent submitted this entry, bound to its continuity handle by keyed hash, with the hashes it gave and, where asked, GAIP's own reading of a public page. Not a statement that the act happened as described. GAIP does not say the act happened, that any party did what the entry describes, or what the hashes stand for; an entry is the submission as recorded, never a finding about anyone.

One entry per act an agent did, promised, checked or was told: a kind from a fixed list, a time, the keyed hash of the agent's continuity handle, a counterparty reference (a public host, a handle's hash or the keyed hash of the agent's own reference), the subject and content digests the agent computed, and optionally a mandate hash, a declared amount, what a public page showed when GAIP read it, and a cosigner's key id and signature (recorded with KEY_KNOWN or KEY_NOT_KNOWN from GAIP's Keys record, never checked by GAIP). What GAIP already recorded for the same handle (Second Look and order-time capture, Witness, Deals and Sign-offs, Served, Preference and Mandate checks, Revocations) appears in GET /v1/free/acts/mine as entries of its kind, each naming its source receipt; a view row is never re-written into the chain. The monthly Statement shows the same entries by kind; the evidence export accepts an entry's code for a “not as described” dispute of any kind, for the actor's handle or the cosigner only.

The switch pack

GAIP's own export of the entries bound to this handle, as open, signed JSON: a format any agent can read and check offline against GAIP's published keys. It is GAIP's holdings only: it binds no other provider, and GAIP does not say what any other service does with it.

GET /v1/free/acts/switch-pack with the X-GAIP-Continuity header, or the MCP tool gaip_switch_pack with continuity_handle: served only to that handle, JSON only, a format any agent can read; the format is at /acts/format (CC BY 4.0). Every entry GAIP holds for this handle (its own gaip.act.v1 entries and GAIP's earlier receipts re-emitted by kind), GAIP's public keys, how to check each signature, and GAIP's signature over the whole pack. A read: nothing is written.

The recall watch

GAIP's record that a notice on a regulator's public list, published since GAIP's previous daily read, carried one of the identifiers this handle registered (MATCHED) or words of the product's name (POSSIBLE_MATCH), entered in the handle's act log with the notice's title, date and link.

Register with a BOUGHT entry that carries product_ids (GTIN, model number or product URL) and watch: true; GAIP keeps keyed hashes of the identifiers and word tokens of the product's name, never an identifier in clear. Read which notices matched at GET /v1/free/acts/recall-watch with the X-GAIP-Continuity header, or the MCP tool gaip_recall_watch. Lists read daily: the GOV.UK product safety alerts, reports and recalls and the US CPSC recalls API; the EU Safety Gate is NOT_ADDED until its reuse terms have been read.

GAIP's own daily match of regulators' published notices against the identifiers this handle registered, as of the stated time. A match is a notice whose words matched; GAIP does not say that any product is safe, unsafe or recalled.

GAIP does not say what any notice means for any product, whether a product is affected, or anything about a product no notice matched; the regulator's own notice is the only statement, and a possible match is a word overlap to check. A POSSIBLE_MATCH says: The words overlap; check that it is the same product.

The format

The entry schema is gaip.act.v1; the pack is gaip.switch-pack.v1. Every field, what it holds and what it never holds, with a worked example, is at /acts/format (CC BY 4.0). One entry is public at GET /v1/free/acts/<code> and at /r/<code>: hashes and public page values only, never the handle.

The COSE receipt

GET /v1/free/acts/<code>/receipt.cose serves the same Ed25519 signature as a COSE_Sign1 (RFC 9052, tag 18): protected header alg EdDSA, content type text/plain; charset=utf-8 and the key id; payload the 64 hex characters of entry_sha256; media type application/cose; cose-type="cose-sign1". One key, one digest, two encodings; the words of the entry stay in the JSON. GAIP offers this as a running transparency service in the sense of the SCITT architecture (RFC 9943): a log anyone can check, not a certification of anything. The format is written up as an Internet-Draft, draft-gaip-act-receipt-00, for the founder to file.

The verifier

Check an entry, a pack or a COSE receipt offline: GAIP's public keys are at /.well-known/gaip-receipt-keys.json, the steps are on the format page, and the free standalone verifier (Python and JavaScript, no dependencies, test vectors) is at /receipt-verifier. Every in-chain entry is a row of GAIP's receipts chain at /v1/free/receipts/<code>, and the daily anchors cover it. A check shows that GAIP's key signed that digest; it shows nothing about the act itself.

What GAIP never does

  • Never receives the content of an act: an agent passes SHA-256 digests, and a `content` field is refused and never stored.
  • Never says that an act happened as described, that a party did what an entry describes, or what the hashes stand for. An entry is the submission as recorded, never a finding about anyone.
  • Never keeps a handle, a name, an address, an e-mail address, an account or a product identifier in clear: the handle and any product identifier are kept as keyed hashes under GAIP's signing key.
  • Never reads a cart, checkout or account page, and never reads Amazon, eBay or Etsy. A page is read once, on the agent's request, through Second Look's reader, with robots.txt honoured; values and hashes are kept, never the page.
  • Never contacts anyone, sells anything or charges anything. Free. No affiliate links. Ever.
  • Never says what another assistant or service does with a switch pack: it is GAIP's own export in an open, signed format, and it binds no other provider.
  • Never says that a product is affected by a recall notice, or that no notice exists: the recall watch records which published notices matched the identifiers a handle registered, with the regulator's own title, date and link.
  • Never accepts an entry without a continuity handle, or with a field outside the schema; outside entries opened only once GAIP's founder had signed off the data protection impact assessment for the log (11 Oct 2026).