Independent evidence for AI-agent actions

Prove an agent's action was justified — at the moment it happened.

AI agents now move money, change entitlements, and reach regulated records. Rujul AI builds the independent evidence layer for those actions. Our first product, ActionGate, records whether the declared basis for each action actually held at the moment of reliance — as a signed, tamper-evident account anyone can verify. It sits off the action path and cannot act. That is precisely why its evidence can be trusted.

AI agent · privileged claim access  ·  reliance-time basis assessment
AGGREGATE UNVERIFIABLE
Was the identity still active?
✓ SupportedCURRENT
Was its entitlement still current?
✓ SupportedCURRENT
Was the approval record current?
✓ SupportedCURRENT
Was the governing policy applicable?
✓ SupportedCURRENT
Did the credential match the declared reference?
✕ Known contradictionINVALID
Could we confirm no active hold?
? Could not establishUNVERIFIABLE
off-path · no payload · cannot approve, block or perform ✓ signed · independently verifiable

Illustration of an ActionGate account — four conditions held, one is known-wrong, one could not be established. Nothing is erased.

The gap

When an agent acts, no one can cleanly prove it was allowed.

The action may execute successfully. The logs may show what happened. But neither answers the question a regulator asks: was the basis this action relied on actually supportable at the moment of reliance? Today that answer is reconstructed after the fact — from evidence scattered across systems, produced by the very platform that took the action.

The enforcing system's own log

  • Produced by the party that took the action — a conflict of interest.
  • Scattered across IAM, approval, policy and credential systems.
  • Reconstructed when the question is asked, not when it mattered.
  • By query time, evidence may have aged out or sources changed.

A Rujul AI account

  • +Produced by a component that cannot act — nothing to shape.
  • +A single, structured record of every declared condition.
  • +Evaluated at the moment of reliance and frozen — deterministically.
  • +Signed and tamper-evident — verifiable by anyone, against you.
How it works

An off-path evaluator that cannot act — so its evidence can be trusted.

ActionGate is not on the action path. It receives basis telemetry, never the payload, and it never approves, blocks, or performs anything. At the moment the agent relies on its preconditions, it evaluates each one and preserves the result.

Agent · rules · RPA
initiates the action
Enforcement point
approves / blocks / performs
Target system
the action lands
the action path — Rujul AI is not on it
ActionGate
off-path · basis telemetry only · cannot approve, block or perform

It evaluates whether the declared basis for the action held — every atomic condition — with the same inputs always yielding the same verdict, and no model second-guessing another model. The result is a single, signed, tamper-evident account. When the question comes, the answer already exists.

What the record distinguishes

It tells known-wrong apart from could-not-establish — and never erases either.

CURRENT
Supported

The declared condition affirmatively held at reliance time.

INVALID
Known contradiction

The evidence contradicts the declaration — a known-wrong basis.

UNVERIFIABLE
Could not establish

The required evidence could not be obtained — and is not guessed either way.

Most systems collapse these into one "missing information" flag. Keeping them apart — and preserving a contradiction even under uncertainty — is what makes the record audit-grade rather than just another log.

Platform, not a feature

One method. Any action class. Every seam in the agent lifecycle.

Because Rujul AI evaluates the declared basis and not the business logic, the same method caters to whatever action class you bring it — and extends to every point in an agent's lifecycle where authority or evidence can quietly change hands.

Any action class

The method is a genus with filed species — not tied to one action type.
Payments & transfers
Entitlement & privilege changes
Regulated-data access
Vendor-agent connectors
Production deploys

Every lifecycle seam

Every point where authority or evidence changes hands is a seam we can evaluate.
Point-in-time relianceLIVE
Reconstruction horizonLIVE
Delegation & handoffNEXT
Retry & resumeNEXT
Correction & record evolutionNEXT
Why now

Agentic AI is arriving faster than the evidence to govern it.

01

Regulators are moving

Model-risk and AI-governance expectations are extending toward agentic systems — a forcing function for independent, reconstructable evidence of every consequential action.

02

Enforcement is crowded — evidence isn't

The market is racing to build agent firewalls and inline gates. The independent-witness position — evidence an enforcer cannot produce about itself — is open.

03

Buyers already own the pain

Technology-risk, internal-audit and model-risk teams at banks and insurers must answer "was this justified?" today — with tooling that reconstructs after the fact.

Defensibility

A patent-pending method, and a working live slice.

Filed

Provisional patents covering the governance-evidence method itself — the generic mechanism, not a single action type.

Running

A live vertical slice: an evaluator and an independent verifier, running deterministically on a real agent action, end to end.

Layered

Patented invariant · public contract · trade-secret method · customer-confidential instance.

The independent-witness position is structural: an enforcer cannot be its own witness. That is the moat — and it is filed.

Execution success is not the same as governance-basis supportability.

If you own the obligation to prove agent actions were justified, we'd like to show you a Rujul AI account on your own action class.