BCOT Core · The Manifest

Governance is only real if you can reconstruct it.

The Manifest records every commitment and every refusal in order, with the conditions that produced it and the reason attached. Append-only and tamper-evident. When someone asks what happened, the answer is already written. A refusal is recorded as permanently as an approval. The Manifest takes no part in the decision.

Authorization historyAppend-only
#8401Answer
Permit
0xA17F
#8402Citation
Abstain
0xC92D
#8403Tool call
Observe
0x4EE1
#8404Tool call
Permit
0xB703
CandidateChecksStateOutcomeReason

Not ordinary logging

A recorder for decisions, not for events.

Ordinary logs answer what the system did. The Manifest answers what it was configured to check, what conditions were in force, and why a candidate was permitted, left unresolved, or withheld.

It records refusals with the same weight as approvals, because in a system that can refuse, a refusal is a decision.

Ordinary activity log

“What happened?”

  • Written after the action, by the thing that acted
  • Refusals recorded as errors, if at all
  • The rules at the time aren't captured
  • Reason absent
The Manifest

“What decided it?”

  • Written at the decision, by the thing that decided
  • Every disposition recorded, equally
  • The rules in force are part of the record
  • Reason attached to every entry

Interactive query explorer

Ask governance questions directly.

The Manifest is shaped for investigation, audit, operational tuning, and long-horizon comparison—questions most logs can't answer.

Governance query

What governance was active when this commitment was permitted?

Configuration-in-force

Return the exact module set, authority versions, evidence references, composite state, and rationale that were in force at that moment.

5 required modules3 authority versionsPermitReason retained

Illustrative query responses shown to explain the record structure.

Append-only · tamper-evident

Corrections add history.
They do not rewrite it.

Each record links to the governance context and the preceding record. Any attempt to alter the past breaks the evidence chain.

01

Candidate received

what was proposed

02

Checks evaluated

verdicts + evidence

03

Disposition recorded

Permit · Observe · Abstain, with reason

04

Record sealed

hashed and linked to the one before it

05

Correction appended

refers to the original, never replaces it

What the Manifest gives you

Safety behavior becomes visible, provable, and comparable.

The record is useful because it captures the negative space—what the system refused, routed, and resolved before consequence.

Refusals stop being invisible

A refusal is recorded as permanently as an approval. Safety behavior that used to leave no trace becomes something you can show.

The record holds up under challenge

Corrections append and reference the original. Hash chains and signed records make alteration detectable—and the configuration in force at the time is part of the record, so a decision reconstructs as it was made, not as your rules read today.

The past can be reconstructed

Recover not just what happened, but the module set, authority versions, and rules in force at the moment. A decision reconstructs as it was made, not as your rules read today.

Drift shows up before an incident does

Look across the full population of decisions to find boundary probing or module shifts that no single-decision alert can catch.

Prove the decision path

Show the checks ran, on what evidence, before the commitment—not a verdict assembled after the fact.

Caution can be measured

Because refusals are first-class records, over-refusal is a question you can answer instead of a complaint you receive.

Shipped, not operated

Your customers answer their own auditors.

The record ships inside your product and lives in their deployment.

Separate

It belongs to the deployment, not to you.

Each customer's record is theirs alone. You aren't operating one ledger on everyone's behalf, and nothing crosses between them.

Self-serve

It answers without routing through you.

When a compliance team asks what happened, your customer's own people answer from their own record. No ticket, no escalation, no support load that grows with every enterprise account you add.

Audit-ready

It arrives in the shape a review expects.

Modules that ran, findings, conditions in force, reason attached. A reviewer gets a decision record instead of a request for engineering time.

Cross-system, cross-jurisdiction queries can expose the needed governance record with privacy protections—without shipping the entire underlying database.

CanadaGoverned recordBelgium

See the decision before the record

Modularity determines how independent checks compose.

Explore why one module can flag or veto a commitment, but no module can authorize it by itself.

Explore Modularity

Architecture Review

Bring one commitment. Leave with its boundary.

Tell us a little about your architecture and the commitment you want to review.

We’ll use these details only to respond to your request. Privacy