Different questions, one discipline: a record at every step — from the evidence
an answer rests on to the authorization an action required — each checkable by
someone who doesn't trust us. Use one alone, or all three together.
POLICY LEDGER · payments pack
transfer cap € 500
refunds cap € 300
version 29e85d2c…5166 ratified
Prevent — onedoor
A policy engine for agent actions. Define caps, bounds, and undo windows; ratify
a version; every action is then checked against that ratified snapshot — allow,
review, or refuse — and every verdict names the exact policy version that decided it.
CHANGE EVIDENCE
baseline byte-identical ✓
watch 74/74 pins hold
a system that changes
will say so
Detect — onewatch
Change-evidence monitoring. The system you audited on Monday is not automatically
the system running on Friday. onewatch keeps verifiable baselines so that when
something underneath you changes, you hold a record that it did — evidence,
not a feeling.
STAGE RECEIPTS
source → clean → chunk → retrieve
answer cites chunk #41 · §4.1
chars 1,204–1,451 · 2 checks ✓
Prove — onetrace
Forensic provenance for retrieval pipelines. A receipt at every stage — source
bytes, cleaning, chunking, retrieval, assembly, the model call — so an answer
traces to the exact passage that produced it, and every step can be re-derived
from the records alone.