A receipt chain can be perfect and the conduct inside it can still be unauthorized. Below is a chain that fully verifies — every action signed, every link intact — carrying four divergences from the authority its principal actually granted. This page finds them, measures how long each stayed open, totals the exposure that accumulated, and apportions a hypothetical loss across the overlapping failures. Everything runs in your browser.
The authority document. It lives in a different system from the receipts — and that separation is the whole point. A receipt system records what it did; it does not hold the document that says what it was allowed to do.
—
A third-party receipt chain from System B, the platform the agent actually ran on. Ingested here as an input format, unmodified.
| # | When | Action | Detail | Against the mandate |
|---|
loading…
Each receipt is evaluated against the mandate — never against the authorization the receipt asserts about itself. Every figure below is a button: open it to see the receipts and the mandate clause that produced it.
When each divergence opened, and when — if ever — it closed.
The unauthorized amount that built up inside each open interval.
| Divergence | Interval | Exposure |
|---|
—
| Control failure | Attributable | Share | % |
|---|
Re-running this computation on these inputs is bit-identical. That is the evidentiary point: a number nobody can reproduce is an opinion.
Receipt systems establish what happened and that the record has not been altered since. That is real work, and it is hard: signing keys held outside the agent process, hash-chained logs, tamper-evident structure. A chain like the one above does its job completely.
What it does not do — cannot do, because it does not hold the document — is compare the conduct it recorded against the authority the principal actually granted. Nothing in a receipt chain measures how long an unauthorized condition stayed open, totals the exposure that accumulated while it did, or separates overlapping control failures when a loss lands on all of them at once. The chain above records a delegation, and records the payments that delegation enabled, and is entirely correct about both. It has no way to know the mandate never permitted the delegation.
PlenaProof consumes any conformant receipt format and computes exactly that difference. The inputs are someone else's records. The output is a deterministic computation over an independently held mandate — not a legal determination, not a finding of liability, and not a substitute for the judgement of the people who have to decide what to do about it.