BCOT Core · The Manifest
Governance is only real if you can reconstruct it.
The Manifest records every commitment and every refusal in order, with the conditions that produced it and the reason attached. Append-only and tamper-evident. When someone asks what happened, the answer is already written. A refusal is recorded as permanently as an approval. The Manifest takes no part in the decision.
Not ordinary logging
A recorder for decisions, not for events.
Ordinary logs answer what the system did. The Manifest answers what it was configured to check, what conditions were in force, and why a candidate was permitted, left unresolved, or withheld.
It records refusals with the same weight as approvals, because in a system that can refuse, a refusal is a decision.
“What happened?”
- Written after the action, by the thing that acted
- Refusals recorded as errors, if at all
- The rules at the time aren't captured
- Reason absent
“What decided it?”
- Written at the decision, by the thing that decided
- Every disposition recorded, equally
- The rules in force are part of the record
- Reason attached to every entry
Interactive query explorer
Ask governance questions directly.
The Manifest is shaped for investigation, audit, operational tuning, and long-horizon comparison—questions most logs can't answer.
What governance was active when this commitment was permitted?
Return the exact module set, authority versions, evidence references, composite state, and rationale that were in force at that moment.
Illustrative query responses shown to explain the record structure.
Append-only · tamper-evident
Corrections add history.
They do not rewrite it.
Each record links to the governance context and the preceding record. Any attempt to alter the past breaks the evidence chain.
Candidate received
what was proposed
Checks evaluated
verdicts + evidence
Disposition recorded
Permit · Observe · Abstain, with reason
Record sealed
hashed and linked to the one before it
Correction appended
refers to the original, never replaces it
What the Manifest gives you
Safety behavior becomes visible, provable, and comparable.
The record is useful because it captures the negative space—what the system refused, routed, and resolved before consequence.
Refusals stop being invisible
A refusal is recorded as permanently as an approval. Safety behavior that used to leave no trace becomes something you can show.
The record holds up under challenge
Corrections append and reference the original. Hash chains and signed records make alteration detectable—and the configuration in force at the time is part of the record, so a decision reconstructs as it was made, not as your rules read today.
The past can be reconstructed
Recover not just what happened, but the module set, authority versions, and rules in force at the moment. A decision reconstructs as it was made, not as your rules read today.
Drift shows up before an incident does
Look across the full population of decisions to find boundary probing or module shifts that no single-decision alert can catch.
Prove the decision path
Show the checks ran, on what evidence, before the commitment—not a verdict assembled after the fact.
Caution can be measured
Because refusals are first-class records, over-refusal is a question you can answer instead of a complaint you receive.
Shipped, not operated
Your customers answer their own auditors.
The record ships inside your product and lives in their deployment.
It belongs to the deployment, not to you.
Each customer's record is theirs alone. You aren't operating one ledger on everyone's behalf, and nothing crosses between them.
It answers without routing through you.
When a compliance team asks what happened, your customer's own people answer from their own record. No ticket, no escalation, no support load that grows with every enterprise account you add.
It arrives in the shape a review expects.
Modules that ran, findings, conditions in force, reason attached. A reviewer gets a decision record instead of a request for engineering time.
Cross-system, cross-jurisdiction queries can expose the needed governance record with privacy protections—without shipping the entire underlying database.