WitnessOS
WitnessOS by Empire Labs Pty Ltd

Every agent action, provable.

WitnessOS is not an operating system for machines. It is the operating layer for governed agent action, the kernel between "the agent wants to" and "the agent may".

Deterministic policy, human approval, tamper-evident receipts and independent timestamps. Auditor-verifiable with zero trust in us.

WitnessOS governed action and evidence overview
WITNESSOS / EVIDENCE RECEIPT E4 SEALED
action governed.action
policy result ALLOW
approval BOUND
chain INTACT
timestamp RFC 3161
ACTION HASH
7f2a91c4...e86b03d9

INDEPENDENTLY TIMESTAMPED
REVOCATION CHECKED AT RECORD TIME
FAIL CLOSED VERIFY WITHOUT EMPIRE TRUST
Why now

Dashboards are not audit trails.

AI governance is moving from guidance to evidence. Audit, risk and insurance teams will ask organisations to prove what autonomous systems actually did, not simply show what a platform says happened.

Trust is a feeling. Proof is a fact. WitnessOS replaces blind trust with cryptographic evidence.
"Show me, don't tell me."

When an agent spends money, sends a message or touches a governed action, who can prove what happened, who approved it and when? Self-attested logs that a vendor could edit are not enough.

How it works

Govern first. Act second. Prove always.

01

Action proposed

The agent proposes an action with its target, parameters, scope and asserted intent.

02

Policy evaluated

Deterministic, OPA/Rego-compatible policy returns Allow, Deny, Conditional or Escalate.

03

Receipt created

The evaluation produces a tamper-evident receipt with the action hash, policy version, context, decision, timestamp and chain of custody.

04

Governed response

Execution proceeds only when sanctioned. Denied actions receive structured remediation from advisory to failsafe, with every escalation recorded.

Evidence ladder / E0 to E4

Evidence gets stronger. Never overstated.

The public ladder closes at E4. Every grade describes the evidence a receipt can support, and unprovable gates cap the grade down, never up.

E0
Event recorded The event exists as a declared record.
E1
Record chained The event is linked into the evidence sequence.
E2
Record signed Cryptographic integrity is attached to the evidence.
E3
Chain verified The chain is intact and self-consistent.
E4
Independently timestamped An RFC 3161 Time Stamping Authority sealed the moment the record was finalised, with revocation checked at that time.
Fail closed by default If a proof gate cannot be satisfied, the grade is capped down.
Governed allowlist Only sanctioned action types can reach E4. Everything else stops at E3.
Zero trust in Empire Labs Receipts verify independently, with no access to an Empire Labs database.
Tamper-tested Altered records cannot reach the top grade.
Watchdog coverage If the evidence gate degrades, operators are alerted. There is no silent drift.
Capabilities

Controls for accountable autonomy.

POLICY

Policy engine

OPA-native Rego policy-as-code, evaluated deterministically before action.

EVIDENCE

Evidence receipts

SHA-256 signed, tamper-evident and exportable as audit bundles.

REMEDIATION

RemediLevel R0 to R6

Structured escalation from advisory guidance to hard failsafe.

BINDING

Machine binding

TPM or fingerprint binding for governed licensing.

INTEGRATION

API-first

Designed for REST, WebSocket and SDK integration.

CONTROL

Layered policy

System, environment and action-level policy tiers.

Governed connectors in production. Payments, refunds and messaging are governed action types: policy, approval and evidence apply before any connector runs. Enterprise deployments add their own action types and connectors to the governed allowlist, and the same evidence ladder applies to everything they touch.
x402 payments Stripe refunds Gmail/Workspace messaging
Proof and positioning

Shipped evidence, not a promise.

E4 in production

Strict mode issues evidence anchored by a real third-party RFC 3161 authority.

Tamper resistance tested

Altered records cannot reach E4.

Governed allowlist

Unsanctioned action types fail closed.

Watchdog monitored

Evidence degradation cannot drift silently.

400+ automated tests

Including real-CA timestamp verification.

Open standards vocabulary. WitnessOS is built on the Empire Stack vocabulary: ACI, the Agent Communication Interface with AJSON manifest authoring, and AIP, the Agent Interaction Protocol. Empire Labs Pty Ltd participates in Agentic AI Foundation (AAIF) working groups on observability, traceability and agentic commerce, where WitnessOS evidence concepts and reference implementations are shared openly.
Questions people ask

Agent governance, transactions and evidence

What is WitnessOS?

WitnessOS is the runtime governance layer for autonomous agents, developed by Empire Labs Pty Ltd. It sits between an agent wanting to act and the agent being allowed to act, applying deterministic policy, human approval and tamper-evident evidence to every governed action.

What is an agent transaction?

An agent transaction is any governed action an autonomous agent performs, such as a payment, refund or message. WitnessOS records each one as a signed, chained evidence receipt with an independent timestamp, so the transaction can be verified later without trusting the operator.

How does WitnessOS handle AI commerce and payments?

WitnessOS governs payment and commerce actions through connectors, including x402 payments, Stripe refunds and messaging. Evidence receipts are produced before a connector runs, giving AI commerce the audit trail it needs: what was spent, who approved it, and proof the record was not altered.

What does E4 evidence mean?

E4 is the top grade on the public WitnessOS evidence ladder. It means the receipt was independently timestamped by an RFC 3161 Time Stamping Authority with revocation checked at record time, and it re-verifies offline with zero trust in Empire Labs.

Is WitnessOS an agent operating system?

No. WitnessOS is not an operating system for machines. It is the operating layer for governed agent action, the kernel between "the agent wants to" and "the agent may". It governs, approves and proves actions rather than running the agent itself.

How does WitnessOS relate to the Agentic AI Foundation?

Empire Labs Pty Ltd is a participant in Agentic AI Foundation working groups on observability, traceability and agentic commerce. WitnessOS evidence concepts and reference implementations are shared in those groups as open contributions. AAIF membership is held by the foundation's member organisations; Empire Labs is not an AAIF member org.

Technical assessment

Can you prove what your agents did?

Book a 30-minute technical assessment to map governed actions, policy gates and evidence requirements for your environment.