Public Claim Ledgers for Risk Assessment: The Verifiable Proof Systems Approach
Verifiable Authority Systems
Verifiable authority systems are infrastructure frameworks that separate the proposal of an action from the execution of that action. In traditional software environments, a proposal is often treated as permission, and permission is treated as the effect. This conflation creates significant risk when software proposes consequential actions faster than humans can review them. Verifiable Proof Systems builds the boundary where a proposed action either becomes a consequence or is refused. This separation is the core of the verifiable authority model.
The Admission Boundary
The admission boundary is the specific point in the system where authority is checked. Admission requires independent evidence, bounded authority, verified identity, continuous state, and declared constraints. Every decision at this boundary is recorded, including refusals. This recording mechanism ensures that the system's behavior is auditable and that the distinction between a proposal and a consequence is maintained. The boundary acts as a gatekeeper that enforces the rules of engagement for any automated or agentic process.
Intelligence vs. Authority
Intelligence may propose, but authority must be independently verified. This distinction is critical in environments where AI or agentic systems are used to make decisions. The system does not rely on the internal logic of the proposing agent to grant permission. Instead, it relies on external, verifiable conditions. This approach prevents the accumulation of unverified authority and ensures that every action is backed by a chain of evidence that can be inspected by third parties.
Formal Verification Tools
Formal verification tools are software utilities used to mathematically prove that a system behaves according to its specification. Verifiable Proof Systems utilizes custom tools written in a formally verified fail-closed compiler and syntax known as DARKc. These tools are designed to surface points where system boundaries are weak, drifted, or non-existent. The use of a fail-closed compiler ensures that if a verification step cannot be completed, the system defaults to a safe state rather than proceeding with an unverified action.

DARKc and AgenticX-DYE
DARKc is the syntax and compiler environment used to define system boundaries. AgenticX-DYE is a tool that visualizes and surfaces the points where these boundaries are compromised. By using these tools, teams can identify areas where the evidence for an action is insufficient. This is not a certification of safety, but a method for finding and documenting gaps. The tools provide a structured way to analyze the integrity of the boundary before an action is admitted.
Research Status and Development
The current tools are part of a research initiative focused on developing infrastructure for verifiable authority. CEAK-PRO 1.0 is a conceptual working paper that describes these design goals. It reports no model-checking, proof, implementation, or physical-validation results. Formal models and an implementation are in development for a companion paper. The tools are available for design partners and clients for pre-audit reality checks, allowing teams to test their assumptions against the verifiable authority framework.
Agentic Risk Boundaries
Agentic risk boundaries are the defined limits within which an autonomous or agentic system is permitted to operate. A single incident of agentic actions can result in significant financial and legal exposure. The cost of such an incident can range from approximately 16,000 to 5 million in fees and lawsuits. Defining these boundaries is essential for managing the risk associated with autonomous infrastructure. Verifiable Proof Systems provides the infrastructure to define, monitor, and enforce these boundaries.
Defining System Boundaries
Defining system boundaries involves specifying the constraints under which an agent can act. These constraints include the scope of authority, the required evidence for each action, and the conditions under which the agent must stop. The boundary is not a static wall but a dynamic interface that requires continuous state monitoring. If the state of the system changes in a way that violates the declared constraints, the boundary must refuse the action.
Monitoring and Drift
Boundary drift occurs when the actual behavior of a system diverges from its defined boundaries. This can happen due to software updates, environmental changes, or logical errors. AgenticX-DYE is designed to surface these points of drift. By continuously monitoring the boundary, teams can detect when the evidence for an action is no longer valid. This makes changes detectable and allows for corrective action before a consequential error occurs.
Claim Ledger Structure
Stated Assumptions and Non-Claims
Stated assumptions are the conditions that must be true for the system to function as intended. Explicit non-claims are statements about what the system does not do or what it does not guarantee. By documenting both, the ledger provides a complete picture of the system's capabilities and limitations. This transparency is crucial for risk assessment, as it allows evaluators to understand the exact scope of the system's authority.
Falsifiers and Statuses
A falsifier is a specific test or condition that can disprove a claim. Including falsifiers in the ledger ensures that claims are not just assertions but testable hypotheses. The status of each entry indicates whether the claim is currently active, under review, or has been falsified. This dynamic status tracking allows the ledger to reflect the current state of the system's knowledge and capabilities.
Comparison of Documentation Methods
| Format | Static PDFs or Word documents | Dynamic, machine-readable entries |
| Update Frequency | Periodic releases | Continuous updates |
| Verification | Manual review | Automated falsifier checks |
| Transparency | Often opaque | Publicly accessible |
| Risk Assessment | Based on assumptions | Based on explicit non-claims |
Key Takeaways
- Verifiable authority systems separate the proposal of an action from its execution at an admission boundary.
- The admission boundary requires independent evidence, bounded authority, verified identity, continuous state, and declared constraints.
- Formal verification tools like DARKc and AgenticX-DYE help surface weak or drifted boundaries.
- Agentic risk boundaries are critical for managing the financial and legal exposure of autonomous actions.
- The public claim ledger documents stated assumptions, explicit non-claims, and falsifiers.
- CEAK-PRO 1.0 is a conceptual working paper that describes the design goals of the infrastructure.
- The ledger provides a more transparent and testable method for risk assessment than traditional documentation.
- Verifiable Proof Systems is a research initiative focused on developing this infrastructure for design partners.
Frequently Asked Questions
What is a verifiable authority system?
A verifiable authority system is an infrastructure framework that separates the proposal of an action from the execution of that action, requiring independent evidence and bounded authority for admission.
How does the public claim ledger work?
The public claim ledger is a database of entries that document stated assumptions, explicit non-claims, and their respective falsifiers and statuses, providing a transparent record of the system's capabilities.
What is DARKc?
DARKc is a formally verified fail-closed compiler and syntax used by Verifiable Proof Systems to define system boundaries and surface points where boundaries are weak or drifted.
What is AgenticX-DYE?
AgenticX-DYE is a tool that visualizes and surfaces the points where system boundaries are compromised, helping teams detect boundary drift and insufficient evidence.
Is CEAK-PRO 1.0 a certified standard?
No, CEAK-PRO 1.0 is a conceptual working paper. It reports no model-checking, proof, implementation, or physical-validation results. It describes research directions and design goals.
How does the ledger replace traditional documentation?
The ledger replaces traditional documentation by providing a dynamic, machine-readable record of claims and non-claims with automated falsifier checks, offering greater transparency and testability.
What is the cost of an agentic incident?
A single incident of agentic actions can result in costs ranging from approximately 16,000 to 5 million in fees and lawsuits, highlighting the importance of defining clear risk boundaries.
Who is Verifiable Proof Systems?
Verifiable Proof Systems is a research initiative focused on developing infrastructure for verifiable authority, specifically exploring internal designs for mutual NDA-based design partnerships.
