Ishtar fronts your MCP servers with OIDC identity and mints a signed, SHA-256-chained Decision Receipt on every tool call. Watch it live. Break it on purpose. Prove it to an outsider.
| Agent | Tool | Receipt ID | Chain Pos | Verdict | Timestamp |
|---|
2026-07-20 · v2 · maps the full design process from problem to shipped artifact.
Every buyer we serve is somewhere on one arc. It starts with shadow agents — a copilot merged a PR, a bot moved a payment, nobody wrote it down. It ends with governed AI operations, where every consequential action carries an identity and a receipt. The pain peaks in the middle: agents already act, the record is still logs. The security owner is asked "who authorized this" and answers "let me check." The compliance owner faces EU AI Act and DORA evidence requests with a program document, not a per-action record. The builder loses enterprise deals for want of SSO and an audit trail. The board sees an unpriced liability.
The job is not observability. Logs answer "what happened in the code" and can be edited after the fact. The job is: when my agents take real actions, prove what they did and that it was allowed — to someone who does not have to take my word for it. The record must exist before anyone asks, resist quiet edits, and verify independently. Design principles: show the record, not vanity metrics; prove it live in front of the buyer; make deny-by-default visible; state honestly that proof is of the record, never of the output; time-to-first-receipt in minutes.
We considered a richer log pipeline — better search, retention, dashboards over events. Rejected: however good the tooling, an editable log is still a log; it cannot answer the authority question and it collapses under adversarial review. Accepted: a signed Decision Receipt per action — actor, tool, policy, verdict, evidence digests — SHA-256-chained to its predecessor, in a cosign-compatible envelope aligned to SLSA L2 attestation. The chain converts "trust our process" into "recompute it yourself."
Streaming feed over a static table — a buyer must watch receipts being minted to believe the invariant. The chain-break UX is the product's thesis in one gesture: Simulate Tamper breaks the chain visibly and locates the breach exactly; Verify Chain heals it, and the heal itself is receipted. The cryptographic depth panel shows the actual hash trace (prior hash → canonical fields → concat → SHA-256 → receipt id) because a skeptical engineer must be able to check the math. Receipt rows use a fixed-column CSS grid so verdict chips and signature badges can never collide with long tool names. Every interactive control mints a receipt: the demo cannot contradict its own KPI.
The principal engineer (AI infra): opens the depth panel, reads the hex trace, sees the OPA Rego fragment behind the verdict, and says "okay, this is real." The SOC lead: opens Chain of Custody, sees agent → tool → receipt → chain position → verdict → timestamp, exports session JSONL and CEF-lite SIEM JSON, and says "I could feed this to Splunk today." The security & compliance owner: reads the market strip — every agentic action is an unattested transaction — and sees the “Actions without a receipt: 0” invariant they are on the hook to guarantee. A cold buyer sees "Actions without a receipt: 0" and asks how to get that number.
The console ships as one self-contained HTML file: no backend, no network calls at runtime, runs from a laptop or a booth. The commercial path is already deployed — checkout at pass.summitcognitive.ai provisions each customer a tenant, license, and its own receipt chain — self-serve, with no Summit service in the runtime verification path.
Synthetic tenant; no live customer data. "Proof" always names its object: the receipt verifies, the chain is intact, the bytes match — never that the AI output was correct, safe, or lawful. No customer counts, logos, or outcome metrics. "Legally admissible" is never used. Regulatory dates (EU AI Act application, DORA) are public context, not legal advice. Pricing shown is the ratified public price list.
Signed Decision Receipts on every tool call. Chain-verifiable. Policy-gated. Zero-dependency demo in 60 seconds.
| Tier | Price | Includes |
|---|---|---|
| Starter | $199/mo | 1 tenant · 10K receipts |
| Team | $499/mo | 5 tenants · 50K · verify + export |
| Business | $1,500/mo | 20 tenants · 500K · full suite |
| Enterprise | Custom | Unlimited · SSO/SAML · SLA |