Pre-commit decision evidence
Bind one exact proposed action to current authority, policy and evidence before the host system commits it.
VEIP · Veraxis Execution Integrity Protocol
VEIP is an open Public Working Draft for actions that could create institutional consequence. It checks whether the exact proposed action remains supported by current authority, policy and evidence before commitment, then emits a replayable Evidence Pack. “Open institutional consequence boundary” describes where VEIP sits; it is not a second expansion of the name.
The protocol is not another model, identity system or policy engine. It is the open computational boundary between institutional grounds and consequential execution.
Bind one exact proposed action to current authority, policy and evidence before the host system commits it.
AI systems now change records, move value and trigger institutional obligations. Ordinary logs do not prove the grounds for those actions.
The contract and evidence must remain usable when a model, cloud, integrator—or Veraxis itself—is replaced.
Name one action your institution must be able to justify after authority, evidence or providers change.
VEIP activates only where a proposed action could become an institutional commitment. Ordinary computation stays in the existing runtime.
Drafting, retrieval, internal reasoning and other ordinary computation follow the controls already selected by the operator.
AGENT → TOOL → RESULT
Resolve authority, describe the exact action, classify it, then retain the Evidence Pack and replay inputs.
PROPOSAL → CLASSIFY → COMMIT
The proposal is classified before the host application executes it.
Identical decision inputs can be replayed against the reference behavior.
A schema-validated Evidence Pack records authority, policy, action, decision, execution and provenance.
No certification, production gateway, cryptographic receipt validator, independent implementation or neutral governance exists in the frozen evidence.
{
"schema_version": "0.1.0",
"evidence_id": "7356b64a-9073-4a31-88b5-6ff0b33f6a44",
"created_at": "2026-07-21T14:00:00Z",
"authority": {
"scope_id": "payments.approve",
"issuer": "enterprise.example",
"valid_from": "2026-07-21T13:00:00Z",
"valid_to": "2026-07-21T15:00:00Z",
"constraints_ref": "policy://payments/84"
},
"policy": {
"policy_id": "payment-control",
"policy_version": "84",
"policy_hash": "sha256:…"
},
"action": {
"action_id": "pay-4821",
"action_type": "release_payment",
"proposed_at": "2026-07-21T13:59:58Z",
"context_refs": ["invoice://4821"]
},
"decision": {
"classification": "ALLOW",
"reason_code": "CURRENT_AUTHORITY",
"evaluated_at": "2026-07-21T13:59:59Z"
},
"execution": {
"executed": true,
"executed_at": "2026-07-21T14:00:00Z",
"executor": "host-runtime",
"outcome": { "status": "SUCCESS", "result_ref": "ledger://991" }
},
"provenance": {
"system_id": "agent-platform",
"build": { "version": "2026.07", "commit": "4c82…" },
"environment": "production"
}
}The six-state model is the architecture direction. The pinned 0.1.0 schema does not yet define separate artifacts for every state, so the page shows the boundary honestly.
Proposed: The exact consequence-bearing action is identified before commitment. Draft flow
Authority, policy, evidence and provenance feed classification. They do not add a seventh lifecycle state.
They may change what remains admissible or trigger corrective work. They are not substitutes for the Corrected state.
The pinned schema has no independent consequence-record artifact. The site does not invent one.
VEIP is the open contract at the center. Veraxis can install and operate a commercial continuity layer around it; the customer’s policy, identity, runtime and systems of record remain theirs.
Exact proposal → classification → Evidence Pack → replay
Visual boundary: neutral enterprise components surround a branded Veraxis operator plane; the VEIP contract remains visually and technically distinct. The operator can be replaced while the contract and portable evidence remain.
Choose the track that matches the work already on your desk. Each path explains what changed, what you may have mispriced and what to do in the next 30 seconds.
You already govern policy. What changes is the need to bind it to the exact action at commitment time.
Map one consequential workflow and name the authority, evidence and stop condition. →You already authenticate and execute. What was underpriced is portable decision evidence at the consequence boundary.
Place the VEIP decision boundary before one consequence-bearing commit. →Your interfaces move calls. VEIP gives customers an operator-portable institutional decision record.
Map one pre-commit hook and one evidence-export hook. →Logs show events. The missing object is a replayable record of the grounds current when action was allowed.
Replay one decision after authority or evidence changes. →Openness is not a brand claim. It is the practical ability to inspect, implement, challenge and replace.
Review a draft artifact, open an issue, or support independently governed work. →Identity establishes who. Policy engines evaluate rules. Runtimes execute. Observability records technical events. VEIP binds the exact consequence-bearing proposal to decision evidence at commitment time.
| Existing boundary | Examples | Existing job | VEIP’s proposed addition |
|---|---|---|---|
| Interaction + tools | MCP · A2A · AG-UI · OpenAPI | Exchange context, messages and calls. | Identify when a proposal crosses into institutional consequence. |
| Identity + access | OAuth · OIDC · mTLS · workload identity | Identify actors, protect channels and grant scopes. | Reference authority inputs without replacing identity or authorization. |
| Policy decision | OPA/Rego · Cedar | Evaluate rules against supplied inputs. | Carry the exact decision context into a replayable Evidence Pack. |
| Enforcement + runtime | Gateways · agent runtimes · tool hosts | Permit, block or execute. | Place classification before a consequence-bearing commit. |
| Observability | Logs · SIEM · OpenTelemetry | Record technical events and traces. | Add portable institutional decision evidence; proposed reliance/correction semantics remain beyond the pinned schema. |
| Consequence boundary | VEIP · Public Working Draft | Previously structurally unowned between governance and execution. | Execution-time classification and replayable action evidence at the point of institutional consequence. |
These architecture invariants are the testable direction. Only claims demonstrable in the pinned Public Working Draft and SDK are treated as current protocol behavior.
The reference flow classifies a proposal before execution.
Decision and evidence must refer to the action that the host executes. Strong cryptographic exact-action binding remains unverified.
Execution cannot silently widen the scope represented in the decision evidence.
Missing or unresolved evidence must not be silently converted into permission.
Version and schema binding prevent silent interpretation drift in the reference SDK.
Append-only correction is a proposed extension, not yet a verified 0.1.0 artifact.
The website separates what is published, what has been reproduced, what is illustrative and what is not established.
VEIP 0.1.0 source and the Evidence Pack JSON Schema are publicly readable under CC BY 4.0 at the frozen commit.
The pinned MIT reference SDK passes its included local tests and demonstrates classification, Evidence Pack emission and replay validation.
The activation visualization, six-state institutional lifecycle and enterprise installation model explain the architecture direction.
Neutral governance, independent custody, conformance certification, public test vectors, external implementations, production guarantees and a funding foundation.
The Public Working Draft and reference artifacts. Implementable under published licenses without buying Veraxis.
Explore the protocol →Veraxis Research Group is a Veraxis-owned research arm. It is not an independent foundation or neutral host.
See stewardship status →Enterprise implementation and continuity services can operationalize the open boundary without owning the contract.
See the continuity layer →The broader inquiry into how institutions remain legitimately behind machine-mediated consequence.
Map the field →