ACCOUNTABILITY FOR AI-WRITTEN CODE

Agents wrote a great deal of your codebase this quarter. Who answers for it?

Not who typed it — that is in the log already. Who committed to it: what was promised before the work, whether it held afterwards, and what happened to the ones that didn't. No editor, tracker, code host or runtime holds that. Askora does, and it refuses the ones that skipped the rules.

Connect a repo and your engineers install nothing. Commits that skipped your standards are refused at the pull request — by your own rules, which never leave your machines.

an intent, as the ledger keeps itillustrative — real shapes, sample rows
intentask_7f3e2c19goalcheckout latency
statedeclared → claimed → satisfying → graded

commitment"Checkout p95 stays under 200 ms at 1k rps after the cart rewrite."
test specload-run checkout.k6.js — p95 < 200 ms, three consecutive runs
carried bymira-2
verdictSATISFIED p95 = 164 ms · filed by mira-2, the seat that carried it — grades are append-only, so a corrected reading is a second grade, never an edit
walk the aska trail
▸ 09:41:02  declared     "Checkout p95 stays under 200 ms…" — seat mira-2, under goal "checkout latency"
▸ 09:41:07  test_spec    load-run checkout.k6.js — p95 < 200 ms, three consecutive runs
▸ 09:41:11  claimed      mira-2 takes carriage
▸ 10:02:19  satisfying   work begins
✓ 10:19:35  graded       SATISFIED — filed by mira-2, the seat that carried it
VIOLATEDask_5d11a04b — "Import handles 50k-row files" · failed at 38k · kept and owned, read by the next wave

A record that only remembers successes is not a memory, it is marketing.

START HERE · THE GUARD

Your standards, proven — without handing them to anyone.

Every policy-as-code tool runs the check in your CI, which means shipping the rule to the runner. Fine for lint. Useless when the rule is the thing you are protecting — an embargoed name, a customer list, a vocabulary that discloses a method by existing.

So we do not ship the rule. Your checker runs where your secret already lives, signs a receipt that it ran and passed, and our verifier reads the signature. A public key and a hash disclose nothing. The rule never moves.

your developers installnothing
you installa hook, a CI line
we ever seea signature
time to adoptan afternoon

A receipt has to be earned: the check re-runs on the finished commit before it signs, so skipping the hooks buys nothing. A machine that does not hold the policy signs "I did not check" — a bound, honest claim, never a silence.

What it does not claim: not secure, not certified, not bug-free. It proves your rules ran on every commit. That is a smaller sentence than most of this market prints, and it is one we can defend line by line.

How the guard works, and what it refuses to say →

NOT A LOG · NOT A DASHBOARD

the editorknows keystrokes
the trackerknows tickets
the code hostknows commits
the runtimeknows processes

None of them knows what the team committed to — or whether it held.

Together they are a log: a faithful record of the deed — what was typed, ticketed, merged, run. A log is honest and it is useful, and it has never once held anyone to a promise.

Observability goes one better and watches the running system — so you can reach in and fix it. It is built to intervene: an alarm that exists to be answered, a dial that exists to be turned.

A witness does the opposite of both. It binds the promise before the deed, grades it against the truth when reality resolves, keeps the misses as loudly as the wins — and then refuses to act on what it saw. A keeper that could reach in would be one more actor to audit; this one cannot, and that refusal is exactly where the trust comes from.

A log remembers what was typed. A dashboard reacts to what is running. A witness binds the promise, grades it against the truth, and keeps its hands still.

What it keeps. What it refuses.

each thing it keeps casts a shadow it will not enter

    • keepswitness

      It sets down what happened, and stands by it.

      grades each commitment against ground truth — read from what happened, never asserted from prose

    • refusesfix

      To change the thing is to stop witnessing it.

      surfaces a verdict for a human to resolve — it does not act on what it witnessed

    • keepshold

      It keeps the thing whole — both sides held together, neither let go.

      append-only and fully audit-trailed — nothing edited in place, the miss kept beside the win

    • refusesprobe

      To pry it open is to break its keeping.

      keeps the ash; it does not get to mine it — the record of intent stays its maker’s own

    • keepstrue

      It names the thing exactly — a word cut to fit the deed, not to please.

      each load-bearing intent bound as a falsifiable commitment before the work — or refused at bind-time

    • refusesflatter

      To gild it is to lie about it.

      keeps its failures as loudly as its wins — a graded_violated binding is retained, never deleted to flatter

    • keepsabstain

      Where its sight ends, it says so, and marks the edge.

      a check that did not settle the question is filed as indeterminate, never rounded to either side — and an aim gated on one is not called met

    • refusespredict

      To claim the future is to overrun the edge of what was seen.

      records what was committed to and whether the bound test held — never what will happen

A scale reads true because it weighs nothing itself. witness ≠ lock

THE PRIMITIVE — THREE MOVES, ONE RECORD

Bind. Grade. Keep.

BIND

Every load-bearing intent is written down before the work, as a falsifiable commitment: what you claim, under what conditions, and the test that would prove you wrong. A commitment with no test that could prove it wrong is refused at bind-time.

GRADE

When reality resolves — a test runs, a review lands, an outcome settles — the commitment is graded against the ground truth: satisfied, violated, or retracted. Never quietly forgotten. Misses are kept and owned, as loudly as the wins.

KEEP

Every state change is written to an append-only record — the aska. Journal, changelog, audit, and postmortem stop being four hand-kept documents and become queries against one record.

declared → claimed → satisfying → graded · satisfied · graded · violated · graded · indeterminate · retracted — the lifecycle is open, by design

And across many makers at once: clash-check DECLARED · FRONTIER

This does not run. No clash check exists in the shipped ledger — there is no clash state on an intent and nothing reads two open commitments against each other. The design is written down and open, and it is: two participants committing to contradictory things caught at bind-time, not merge-time, surfaced with the two commitments in tension and a human-readable reason, while genuine differences of direction surface as values-tensions for a human to weigh, never defects to auto-resolve. A clash blocks and must be resolved; a values-tension is direction and must be chosen.

And no coverage figure goes with it. This card claimed a near-complete syntactic overlap and a published semantic bound; the check does not run and no figure was published anywhere. Both are withdrawn until a corpus has produced a measurement. How coordination is meant to work →

Write the intent down before the work, grade it against the truth, keep the ash — so the next fire is truer than the last.

WHAT THE WITNESS KEEPS

The house's own work, kept and graded here.

Every instrument the house ships was bound before the work, graded against the truth, and kept with its misses on this record — not a pitch for something we hope to build, the working discipline the house already runs on. Pavora, proof-carrying security. Protora, detect · attest · excise on untrusted finetunes. Ardora, the model naturalist — read, chart, name. Each is a deed under witness; the aska keeps the ash of every one, so the next fire is truer than the last.

Two of the house are witnesses, and they are not the same witness. Proofora is the proof that will not look away — machine-checked, it proves the theorem. Askora is the keeper that will not intervene — it embodies it. One theorem, two hands: witness ≠ lock.

And Solora is the sun at noon — the world the house works inside. Two siblings, one asymmetry: the one who acts, and the one who holds them to their word. The acting is trustworthy only because the witnessing weighs nothing.

The record is the demo, and it is kept here — the binding above is how the witness keeps the house's own work, not a page handed to another door.

Memory is what turns a circle into a spiral.

A forge that scatters its ash each night starts cold every morning and forges the same flawed blade forever. A forge that keeps and reads its ash learns the temper of its own fire — its next blade is truer than its last.

The full legend →

TRUST — OPEN BY DESIGN, ONE PROPRIETARY SEAM

In a record, trust is the entire product.

Almost all of Askora is open. The binding lifecycle, the state machine, the append-only record, the goal tree and its gates, grades — the discipline is the product, and its legibility is the point.

One layer is proprietary: the judgement that places a goal on the orrery, translates promises into falsifiable tests, and learns from the graded record. Your record never depends on it to be read. The full trust story →

A customer's record of intent is theirs — Askora keeps the ash; it does not get to mine it. Append-only and fully audit-trailed; we do not say "tamper-proof." What this gives your risk function →

Every other page ends “get started.”

This one has nothing for you to press. The witness does not act — that is the whole reason it can be trusted with the record. Bind a promise and it will hold you to it; break one and it will keep the miss as plainly as any win. Until then it waits at the root, weighing nothing, its hands as still as yours.

One thing to do, then — walk the record: a single promise bound, graded, and kept →

Don't fix. Witness.