Accountability for AI that acts

AI needs supervision. Prove yours had it.

Glacis applies your rules when AI acts, blocks or escalates actions outside them, and leaves an independently verifiable record of the supervision that occurred.

AI action · payments.transfer $40,000 requested · $10,000 authority Blocked · independently verifiable

One consequential action

The agent requested $40,000. Its authority stopped at $10,000.

Before the transfer could execute, Glacis matched the request to the approved authority policy, blocked it, and preserved an operational record another party can verify.

Glacis proves that a named control ran and what it decided. It does not certify that the AI system is universally safe, correct or compliant.

Control decision
simulation · treasury-agent
  • 14:02:11 treasury-agentpayments.transfer · $40,000 requested
  • 14:02:12 authority policy → maximum $10,000 control ran
  • 14:02:12 payments.transfer · outside authority blocked
  • 14:02:13 operational record created proof ready
Operational record · #4f2c…a081 Sample format
Action
payments.transfer · $40,000 requested
Rule
transfer-authority/v3 · maximum $10,000
Control
authority_limit · executed
Outcome
blocked · signed record created
Demonstration workflow Verify a sample record →

The supervision layer

Policies say what should happen. Logs say what the application recorded.

Glacis applies the approved rule while the AI action is in flight, blocks or escalates what falls outside it, and leaves an independently verifiable record of the supervision that occurred.

Visible

See where supervision is operating — and where it is not.

Control coverage, execution gaps and drift across the AI workflows you have put into production.

coverage18 of 21 workflows
uncoveredclaims intake +2
drift, 7d2 controls off policy
Simulated coverage for illustration

Controllable

Apply the rule before the action completes.

Allow, block, redact, escalate or require human review at the point where the AI is about to act.

actionpayments.transfer
policy hittransfer-authority/v3
outcomedenied · receipted

Provable

Leave a record somebody else can check.

Each action routed through Glacis can produce a signed, portable operational record that does not require a Glacis account to verify.

formatOVERT · open spec
integritysigned · hash-chained
verificationno account required
Demonstration values

Browser verification

Check a sample record yourself.

This is a separate demonstration record, not the transfer shown above. Its signature and integrity checks run locally in your browser without a Glacis account or the protected underlying content. For known-key and provenance checks, open the full verifier.

What monitoring leaves unanswered

A conventional log is useful. It is not independent proof.

Most application logs remain under the operator’s control; signed or attested logs can provide stronger integrity. Glacis has a narrower job: connect the approved rule to the control decision and leave a record an outside party can verify.

What your existing stack can show
What still has to be demonstrated
Governance: the approved transfer limit is $10,000.
Was that version of the rule applied to this $40,000 request?
Observability: the call returned a blocked response in 12 milliseconds.
Did the authority control make that decision, and can somebody else verify it?
Human review: the workflow says an approver intervened.
What did the reviewer see, decide, and leave on the operational record?
Operator log: the event was recorded inside your tenant.
Can a customer, board, insurer or auditor check it without relying only on your assertion?
Backers and programs
  • AI House
  • Mighty Capital
  • Lionheart Ventures
  • SAIF — Safe AI Fund
  • Plug and Play
  • Sourdough Ventures

Where Glacis fits

Keep the tools you have. Add the missing operational proof.

Governance, observability and guardrails remain useful. Glacis connects their intended state to a control decision while the AI is acting, then makes that decision independently checkable.

Primary job Before the action Record for outsiders
Governance Defines intended policy — not usually in the action path — approvals and reports
Observability Records application activity — alerts or post-hoc analysis — operator-controlled logs
Guardrails & policy engines Evaluate configured rules ✓ can allow, block or route — implementation-dependent
GLACIS Connects rule to action ✓ allow, block or escalate ✓ independently verifiable

Glacis does not reveal a model’s internal reasoning. It shows which named control evaluated an action, what it decided, and whether the resulting operational record still verifies.

When somebody asks what happened

The answer should already exist.

A customer security review. A board or internal risk question. An insurance renewal. A regulator or auditor. An incident investigation. Do not reconstruct responsible behavior afterward. Operate in a way that leaves evidence while it happens.

  • CustomerShow the controls around the AI you sell without asking the customer to rely only on your assertion.
  • Board & riskAnswer what the AI was permitted to do, which control ran, and whether the action was allowed, blocked, or escalated.
  • InsuranceBring operational evidence to a renewal, claim, or diligence review instead of reconstructing it from application logs.
  • Audit & incidentGive reviewers a portable record they can check independently, including any later alteration.

How the proof holds up

The operational record can travel without the protected content.

When an action is routed through Glacis, its control decision can be signed and linked to prior records. Alter one and the verifier identifies the break.

Customer trust boundary hash Agent tool call Arbiter policy · enforce arbiter-01.us-east Allowed action proceeds Blocked denied · receipted Receipt n−1 1d9a… Receipt n 4f2c…a081 Witness co-signed · append-only Verifier anyone, any time runtime · inside customer trust portable proof · independently verifiable Customer trust boundary hash Agent tool call Arbiter policy · enforce arbiter-01.us-east Allowed proceeds Blocked receipted Receipt n−1 1d9a… Receipt n 4f2c…a081 Witness co-signed Verifier anyone, any time
Chain intact — every receipt links to the one before it.

Simulated for illustration

Open standard

The proof is written to an open standard.

OVERT defines a portable format for signed operational evidence. A verifier can check the record without a Glacis account or disclosure of the protected underlying content.

Standard
OVERT 1.1
Status
Published 11 June 2026
License
Royalty‑free covenant

Start with one consequential AI workflow.

If AI is already acting in production, show us the workflow and the rule that matters. If you want to prove the integration first, start free. The verifier is available to anyone.