[{"data":1,"prerenderedAt":144},["ShallowReactive",2],{"blog-posts":3},[4],{"id":5,"title":6,"actionRequired":7,"affectedAudience":8,"announce":7,"author":9,"body":13,"canonical":8,"date":119,"description":120,"difficulty":8,"draft":7,"extension":121,"featured":122,"image":8,"impact":8,"lastModified":8,"meta":123,"navigation":122,"notes":124,"ogImage":8,"path":134,"publishedOn":8,"readTime":135,"reviewed":122,"reviewed_on":8,"seo":136,"series":8,"stem":137,"tags":138,"toc":122,"__hash__":143},"blog\u002Fblog\u002Fsweetrust-overview.md","Trust Rails for Agents",false,null,{"name":10,"avatar":11,"twitter":12},"Danny Ahn","\u002Fauthors\u002Fdanny.jpg","dannydevsss",{"type":14,"value":15,"toc":112},"minimark",[16,20,26,29,36,42,48,53,64,67,71,74,82,85,89,97,100],[17,18,19],"p",{},"Your agent reads an inbound email and pulls out an account number. It also looks one up in\nyour own vendor registry. Both are strings. Your type system cannot tell them apart, your\npayment function cannot tell them apart, and whoever planted the email is counting on\nexactly that.",[21,22,23],"blockquote",{},[17,24,25],{},"Types constrain shape. Nothing constrains pedigree.",[17,27,28],{},"SweeTrust is trust rails for AI agents. Three primitives, and the order is the idea: issue\nauthority, enforce it, prove what happened.",[17,30,31,35],{},[32,33,34],"strong",{},"Mandate"," issues the authority. It is delegated in bounded tiers — organization, then\nproject, then agent — and each tier can hold only a subset of what its parent holds. Revoke\nthe parent and every tier beneath it dies with it.",[17,37,38,41],{},[32,39,40],{},"Gate"," enforces it. A value carries where it came from, from the moment it enters your\nsystem to the operation that finally spends it. Any privileged operation can demand that\nhistory and refuse to act without it.",[17,43,44,47],{},[32,45,46],{},"Verify"," proves it afterwards. Every decision, allowed and refused alike, is signed and\nhash-chained into a record a stranger can re-check — without having to trust the machine\nthat wrote it.",[49,50,52],"h2",{"id":51},"why-it-is-powerful","Why it is powerful",[17,54,55,56,63],{},"Most agent-safety tools detect. This one refuses. A sink that fails closed does not flag a\nsuspicious payment for review; it declines to make one, and names the missing pedigree in\nthe refusal.",[57,58,62],"sup",{"className":59,"id":61},[60],"mark","m2","1"," That difference matters because a review queue needs a human with attention\nleft over, and the entire reason agents are interesting is that they work when nobody is\nwatching.",[17,65,66],{},"The second reason is the one worth arguing about. Better models do not shrink this market —\nthey grow it. The value here scales with how many models are running unattended and how\ncheap they are, not with how flawed they are. Most safety pitches are an implicit bet that\nmodels stay bad, which is a bet against the field. This is the opposite bet: as capable\nmodels get cheap enough to run everywhere by default, a guarantee that holds no matter which\none is driving becomes worth more, not less.",[49,68,70],{"id":69},"what-sets-it-apart","What sets it apart",[17,72,73],{},"There are four provenance tiers and they only move one way on their own — untrusted,\nasserted, corroborated, verified. Combining values taints downward, so anything mixed with\nuntrusted data comes out untrusted. Model output is born untrusted no matter how good the\nmodel, because inference is not evidence.",[17,75,76,77],{},"A value can climb, but only by three audited routes: match it against a registry you control,\ncorroborate it against independent sources, or ask a person — with the value's history\nrendered into the question, so the answer is informed rather than reflexive. The constructor\nis private to the module, so there is no fourth way up.",[57,78,81],{"className":79,"id":80},[60],"m3","2",[17,83,84],{},"The part worth showing a skeptic is the limits. Deleting the last few receipts leaves a\nperfectly valid shorter chain, and only an on-chain anchor catches that, which is why the\nanchor exists. A compromised host can sign lies going forward. The off-chain authority layer\ncan be bypassed by a host that owns you completely — making that impossible is the Move\ncontract's job, and the two compose without either claiming the other's guarantee. Each of\nthose limits has a test behind it rather than a sentence.",[49,86,88],{"id":87},"how-much-is-built","How much is built",[17,90,91,92],{},"The three primitives are built and versioned together at 0.3.0, under 169 passing tests that\ninclude a dedicated adversarial suite against each one. Zero runtime dependencies — node\nbuiltins only, so nothing else enters your tree.",[57,93,96],{"className":94,"id":95},[60],"m4","3",[17,98,99],{},"The packages are not on npm yet — they are in final review before publication. The product\naround the primitives is a separate question and a longer one: the execution engine, the\nclient and the adoption flow are not built.",[17,101,102,103,107,108,111],{},"So this says ",[104,105,106],"em",{},"built",", not ",[104,109,110],{},"shipped",", and it will keep saying that until you can install it\nand check for yourself. A claim you cannot verify is a claim I am not making.",{"title":113,"searchDepth":114,"depth":114,"links":115},"",2,[116,117,118],{"id":51,"depth":114,"text":52},{"id":69,"depth":114,"text":70},{"id":87,"depth":114,"text":88},"2026-08-30","Issue authority, enforce it, prove what happened — and publish the limits rather than bury them. Three primitives for agents that act when nobody is watching.","md",true,{},[125,128,131],{"for":61,"label":126,"text":127},"The refusal branch","The refusal is the interesting branch — it is where an injected payee stops. It returns a result rather than a bare value, so there is no way to spend the output without having looked at it first.",{"for":80,"label":129,"text":130},"No fourth way up","Module-private constructor. The absence is the invariant: no fourth way up, and it is enforced by the language rather than by review.",{"for":95,"label":132,"text":133},"Measured 2026-08-30","169 tests across 13 files — mandate 71, gate 42, verify 34, barrel 5. 3,572 LOC, and an empty dependencies object.","\u002Fblog\u002Fsweetrust-overview",3,{"title":6,"description":120},"blog\u002Fsweetrust-overview",[139,140,141,142],"sweetrust","agents","provenance","security","P2TfhEDkumTHZT9e2e3uVMkyShxxOK4fNm2olqHclkA",1788226713146]