ProofSmith - Independent & Provable - GOVERNED DECISION LINEAGE

The solution

Trust, but verify. ProofSmith is the verify.

ProofSmith is the trust layer for digital information. It establishes provenance, decides what may access or transform an artifact — permit or deny, on authority — and emits independently verifiable proof of that decision, whether the actor is a human, an AI, or a machine.

On this page

Two tests

The two tests, and what we found.

Enforcement. Does the system stop the action, or does it only observe it? A control that records what happened is a witness. A control that determines whether it may happen is a governor. They are not the same instrument and they are not substitutes.

Verifier-independence. Can a third party check the decision without the cooperation of the system that produced it? If the answer is no, the record is an assertion by an interested party, however well signed and however well stored.

For eight months we have searched the public record — company and product documentation, published patent applications and grants, standards and specification drafts, regulatory filings, and publicly issued analyst material — and put each system we found that claims to govern machine decisions against these two questions. Both tests are defined on this site and the sources are public; the register of placements is ours and is not published. One counterexample settles it. We have not yet found a system that answers yes to both.

No verifier-independent evidence
Verifier-independent evidence
Enforces the action
34 assessed
Enforces, no evidence
ProofSmith
Enforces, with evidence
Does not enforce
38 assessed
Neither
24 assessed
Evidence, no enforcement

One hundred and seven systems assessed over eight months of searching the public record, ninety-nine of them placed on these axes. All ninety-nine sit outside the upper right — thirty-four enforce without producing checkable evidence, twenty-four produce evidence without enforcing anything, thirty-eight do neither, and three sit on the line between two of those cells, none of them touching the upper right. A further eight were adjudicated and set off the axes as belonging to a different layer. If you know of one that belongs in the upper right, tell us and we will place it. ProofSmith’s own place there is a claim until a party you authorize has checked one of our decisions without our help.

The ProofSmith architecture is patent pending.

What a third party measured

A leading industry analyst firm, in a 2026 study of one hundred and seven agentic-AI deployments across nine industries, scored each on six capabilities at five levels, 0 through 4. Level 4 is the top: the system acts with no person in the path, and the firm calls it the level most likely to deliver transformative return. Forty-one deployments were scored at Level 2, sixty-six at Level 3, and none at Level 4.

Level 2 · Basic
41

Assists inside a task a person is still running.

Level 3 · Intermediate
66

Runs whole workflows alone, inside limits a person set.

Level 4 · Advanced
0

Acts with no person in the path.

Deployments analyzed, by level. Source: a leading industry analyst firm, 2026, which notes the examples were not extensively validated.

What we take from it. Level 4 is where the value is, and the return is only half of it. An organization that can delegate authority to a machine and still answer for the result moves at a speed its adversary cannot match, on decisions it cannot otherwise safely automate at all.

Why it stops there. Levels 0 through 3 keep a person in the decision path. That person is the accountability. Level 4 removes the person. Nothing takes their place. The models are capable; the Level 3 deployments already plan, replan and act on production systems. The gap is not capability. No one had built what lets an organization take the last step and still answer for it.

Our own count, of a different set. Of the ninety-nine systems we placed on the two tests above, none reached the upper right, enforcement with evidence a stranger can check. Two studies, two methods, and in each an empty place at the top: the industry has built capability up to the last step, and has not built what the last step requires.

ProofSmith is not on that scale. The scale measures how much a system can do on its own; an adjudicator does none of it, and the further a deployment climbs, the more it needs one.

Why the safeguard is the license to advance, arena by arena, is on The Question, section V.

What would have to be true

Six requirements, one for each problem.

Each of the six problems closes with a requirement rather than a product. Together they are the standard, whoever meets it. The problems are set out on The Problem.

The architecture

Three things we claim of it, and each can be tested.

We took the founders’ answer and built it for the Age of the Machine. Nothing on this site describes how the architecture works. What it does, at the altitude of a claim you can check, is this.

The decision is adjudicated before the act. The proposer proposes. The Arbiter decides. Before an action runs, it checks the request against the authority for it, applies the authority you delegated rather than a judgment of its own, and signs a permit or a deny. The Arbiter does not make a model more accurate, and it does not judge whether the authority behind a decision was sound. It rules on one thing: whether the act was inside the authority you wrote.

Where the adjudicator runs. The adjudicator has to run somewhere the actor cannot reach. That is a property of the platform, and one the customer can check for itself.

The proof is checkable afterward by anyone you authorize. Anyone you authorize can check that record later, using methods we publish to them, and reach the same answer without trusting us, the vendor, or the system that acted. Of the seven events on the Taming the Beast page, the three in which an act ran would each have left a record that did not depend on the actor.

The descriptor

Independent & Provable GOVERNED DECISION LINEAGE

Five words. Each one is a claim, and each one can be tested.

Independent
Separate from the system that acts and from the party that built it, and checkable by a party that needs nothing from either. The independence is of the judgment and the proof; the authority stays yours.
Provable
Checkable by a party outside the system, using methods we publish to the parties you authorize, without the cooperation of the system that acted. Self-attestation is not proof.
Governed
The action was permitted, not merely observed: decided against authority written in advance, before it ran, and denied if it fell outside that authority.
Decision
Not logs. Not intent. The exact action the agent tried to take, the policy that applied, and the outcome.
Lineage
The chain from authority through decision to action to evidence, unbroken, so that it can be examined in audit and in litigation.

What the architecture produces is a record of every permit and every deny, signed at the moment of decision, that anyone you authorize can verify later without asking us or the system that acted.

The demonstration

An agent proposes. The decision is adjudicated. Anyone you authorize can verify it afterward.

We would rather show it than describe it, and build it around your problem rather than our example. Tell us which of the six is costing you, and that is the one we will build.

Start a conversationSee the six problemsDownload the two-page summary

We are not asking you to trust us. We are asking you to let us prove it.