SweeTrust
Trust rails for AI agents. Issue authority, enforce it, prove what happened.
The problem
Types constrain shape. Nothing constrains pedigree. An account number pulled from an inbound email has the type string. So does one from your own vendor registry. Your payment function cannot tell them apart.
Three packages
mandate holds what a person granted, in bounded tiers — an out-of-tier grant does not compile. gate is the enforcement point, and a sink fails closed when the pedigree is missing. verify signs and hash-chains every decision, allowed and refused alike.
Why it holds
Model output is born untrusted no matter how good the model. Inference is not evidence. Three audited declassifiers are the only way up, and the constructor is module-private, so there is no fourth.
What it does not do
Deleting the last few receipts leaves a perfectly valid shorter chain — only an on-chain anchor catches that. mandate is the off-chain authority layer, and a fully compromised host bypasses it. Unforgeable enforcement is the Move SpendCage’s job; the two compose, and neither claims the other’s property.
Built and tested · nothing published · zero runtime dependencies
Request
const payee = Sourced.fromChannel(iban, 'email') const decision = gate.check({ action: 'transfer', amount: 40_000, payee, })
Response — the interesting branch
{ ok: false, refusedBy: 'mandate.cap', reason: '40000 > 500 USDC', pedigree: 'untrusted', needs: 'human', receipt: 'sha256:9f2c…', }
A result, not a bare value — there is no way to spend the output without having looked at it first.
Pedigree — and the only ways up
- untrusted
- where model output is born
- asserted
- a registry you control matches
- corroborated
- independent sources agree
- verified
- a person asked, provenance in the question
A chokepoint — the wall across the only route