Summit Cognitive
Ishtar live · synthetic tenant
Glass-box assurance

Every agent action, governed and provable

Ishtar fronts your MCP servers with OIDC identity and mints a signed, SHA-256-chained Decision Receipt on every tool call. Watch it live. Break it on purpose. Prove it to an outsider.

Actions without a receipt
247
the invariant — never above zero
Receipts this session
0
signed · chained
Allowed
0
Escalated → human
0
deny-by-default
Chain integrity
VERIFIED
gate p95 — ms
Every agent action is a transaction someone will eventually have to account for. Ishtar makes each one a signed, replayable record — so “who authorized this, and can you prove it?” already has an answer.
The record exists before the question · resists quiet edits · recomputes with no Summit service in the loop.
streaming · click a row
AgentToolReceipt IDChain PosVerdictTimestamp
Chain integrity
Policy gate — try an action ⬡ OPA · policy-as-code package ishtar.spend default allow := false allow if input.amount <= data.caps[input.tenant] escalate if input.amount > data.caps[input.tenant]
Amount / risk $5,000
Pick an action and send it. The verdict mints a receipt into the feed — the counter above never leaves zero.
Full tooling

What ships with Summit Pass

Packaging

Priced to start today

Starter
$199/mo
  • 1 tenant
  • 10K receipts/mo
  • Basic policy gate
  • Ishtar console
Team
$499/mo
  • 5 tenants
  • 50K receipts/mo
  • Chain verify + export
  • SIEM feed (CEF-lite)
Business
$1,500/mo
  • 20 tenants
  • 500K receipts/mo
  • Full tooling suite
  • Key custody + legal hold
Enterprise
Custom
  • Unlimited
  • SSO / SAML
  • SLA + dedicated support
  • Sovereign deploy
Synthetic tenant · Proof of record, not output · No live customer data · Summit Cognitive
A Decision Receipt proves the record of an action is complete, tamper-evident, and independently verifiable — not that the AI output was correct. SLSA L2 artifact attestation, cosign-compatible envelope. pass.summitcognitive.ai
Summit Cognitive · Product design

Ishtar Product Design — Glass-Box Assurance Console

2026-07-20 · v2 · maps the full design process from problem to shipped artifact.


Phase 1 · Empathize

The maturity arc: shadow IT → governed AI ops

Every buyer we serve is somewhere on one arc. It starts with shadow agents — a copilot merged a PR, a bot moved a payment, nobody wrote it down. It ends with governed AI operations, where every consequential action carries an identity and a receipt. The pain peaks in the middle: agents already act, the record is still logs. The security owner is asked "who authorized this" and answers "let me check." The compliance owner faces EU AI Act and DORA evidence requests with a program document, not a per-action record. The builder loses enterprise deals for want of SSO and an audit trail. The board sees an unpriced liability.

Phase 2 · Define

Job-to-be-done: prove compliance, not just log

The job is not observability. Logs answer "what happened in the code" and can be edited after the fact. The job is: when my agents take real actions, prove what they did and that it was allowed — to someone who does not have to take my word for it. The record must exist before anyone asks, resist quiet edits, and verify independently. Design principles: show the record, not vanity metrics; prove it live in front of the buyer; make deny-by-default visible; state honestly that proof is of the record, never of the output; time-to-first-receipt in minutes.

Phase 3 · Ideate

Rejected: black-box log. Accepted: signed receipt.

We considered a richer log pipeline — better search, retention, dashboards over events. Rejected: however good the tooling, an editable log is still a log; it cannot answer the authority question and it collapses under adversarial review. Accepted: a signed Decision Receipt per action — actor, tool, policy, verdict, evidence digests — SHA-256-chained to its predecessor, in a cosign-compatible envelope aligned to SLSA L2 attestation. The chain converts "trust our process" into "recompute it yourself."

Phase 4 · Prototype

Decisions that shaped the console

Streaming feed over a static table — a buyer must watch receipts being minted to believe the invariant. The chain-break UX is the product's thesis in one gesture: Simulate Tamper breaks the chain visibly and locates the breach exactly; Verify Chain heals it, and the heal itself is receipted. The cryptographic depth panel shows the actual hash trace (prior hash → canonical fields → concat → SHA-256 → receipt id) because a skeptical engineer must be able to check the math. Receipt rows use a fixed-column CSS grid so verdict chips and signature badges can never collide with long tool names. Every interactive control mints a receipt: the demo cannot contradict its own KPI.

Phase 5 · Test

Three personas, three acceptance bars

The principal engineer (AI infra): opens the depth panel, reads the hex trace, sees the OPA Rego fragment behind the verdict, and says "okay, this is real." The SOC lead: opens Chain of Custody, sees agent → tool → receipt → chain position → verdict → timestamp, exports session JSONL and CEF-lite SIEM JSON, and says "I could feed this to Splunk today." The security & compliance owner: reads the market strip — every agentic action is an unattested transaction — and sees the “Actions without a receipt: 0” invariant they are on the hook to guarantee. A cold buyer sees "Actions without a receipt: 0" and asks how to get that number.

Phase 6 · Ship

Zero-dependency HTML; self-serve checkout provisioning

The console ships as one self-contained HTML file: no backend, no network calls at runtime, runs from a laptop or a booth. The commercial path is already deployed — checkout at pass.summitcognitive.ai provisions each customer a tenant, license, and its own receipt chain — self-serve, with no Summit service in the runtime verification path.


Appendix · Claims register & disclaimer

Synthetic tenant; no live customer data. "Proof" always names its object: the receipt verifies, the chain is intact, the bytes match — never that the AI output was correct, safe, or lawful. No customer counts, logos, or outcome metrics. "Legally admissible" is never used. Regulatory dates (EU AI Act application, DORA) are public context, not legal advice. Pricing shown is the ratified public price list.

Summit Pass · Ishtar Glass-Box Assurance

Your agents are acting.
Can you prove it?

Signed Decision Receipts on every tool call. Chain-verifiable. Policy-gated. Zero-dependency demo in 60 seconds.

Receipt
Every tool call is sealed into a signed Decision Receipt.
actor · tool · policy · verdict · evidence digests · SHA-256
Chain
Each receipt hash-links to the one before. Edit one, and the chain breaks — visibly, at the exact position.
recompute + replay by any third party · cosign-compatible
Gate
Deny-by-default policy on every consequential action.
ALLOW proceeds · over-cap ESCALATES to a human · out-of-scope BLOCKS
418
Actions without a receipt
TierPriceIncludes
Starter$199/mo1 tenant · 10K receipts
Team$499/mo5 tenants · 50K · verify + export
Business$1,500/mo20 tenants · 500K · full suite
EnterpriseCustomUnlimited · SSO/SAML · SLA
Book a pilot call → pass.summitcognitive.ai
Synthetic tenant · Proof of record, not output · No customer data · Summit Cognitive
Decision Receipt — cryptographic trace
Demo script — presenter notesShift+D toggles · click a step to highlight its region · target: under 4 minutes