PlatformDelivery BoardAutomation & RunbooksOutcome ReceiptsJust-in-Time ElevationCredential VaultGoverned SessionsDevices & DiscoveryPatch ManagementReporting & ExportsRoles & Multi-Tenancy
Verified AI OperationsThe Operation LoopCommanded AutonomyCompare the operating modelThe Verified Operation Spec
SolutionsFor MSPsFor Enterprise & Internal ITHealthcareLegalFinancial servicesMunicipal & Education
ProofOperation walkthroughSecurity & architectureVerified Operation SpecFive questions for your RMM's AIChangelog
CompanyAboutFounder's noteContact
PricingBuy 1–20 technician licenses onlinePlans — from $499 per monthCustom requirementsFoundation Circle
Log in

Home/Platform/Outcome Receipts

The differentiator

The work has an outcome. The record explains how.

A log line tells you what a tool says. Seraph's operation record names the human who authorized the work, the privilege it borrowed, the job that ran, and the machine's own confirmation. Where recovery is supported, its declared path is recorded before execution.

Outcome receiptOP-000217
operationservice recovery
requested byDana K · Teams #it-help
authorized byMarcus R · 09:40
admin accessleased 8 min · expired 09:47
ranrestart print spooler · signed job
the machine saidservice running · queue clear
undodeclared before execution
ticket#4821 · resolved
chain 9f3a…c47e DONE & LOCKED

Anatomy

Six answers, on one page, for every operation.

These are the six questions a client, an insurer, or an auditor actually asks. A receipt answers all six or it is not a receipt.

Anatomy of an outcome receiptOP-000217
OUTCOME RECEIPT OP-000217 COMMAND Marcus R · 09:40 PRIVILEGE leased 8 min · expired 09:47 EXECUTION restart-spooler · signed job CONFIRMATION SRV-ACCT-02 answered: running UNDO declared · available chain 9f3a…c47e Who ordered it A named human authorized this before anything ran. Not a policy, not the AI — a person. What it borrowed Admin rights existed for eight minutes, scoped to this task, and expired on their own. What actually ran The exact job, signed — and the model never saw the credential that carried it. Who says it worked The repaired machine answered a fresh check. Not the AI. Not the dashboard. How to undo it The reversal was written down before execution — not invented afterwards, if ever. AND THE WHOLE THING CARRIES THE FINGERPRINT OF THE RECORD BEFORE IT
The receipt is generated by the platform, not written by the model. Nothing the AI says about its own work appears in the confirmation row — that row only ever carries what the target machine answered.

Why it can't be quietly rewritten

Edit one record and the ones after it stop agreeing.

Each receipt carries a fingerprint of the record before it. That is what turns a list of events into evidence: you cannot change history without every later record disagreeing with you.

Tamper evidencethe chain
INTACT — EVERY LINK AGREES OP-000215 FINGERPRINT 4c1e…8b02 OP-000216 FINGERPRINT 7a90…d41f OP-000217 FINGERPRINT 9f3a…c47e OP-000218 FINGERPRINT b207…33ca SOMEONE EDITS OP-000216 AFTER THE FACT OP-000215 FINGERPRINT 4c1e…8b02 OP-000216 · ALTERED FINGERPRINT NOW e55b…1770 OP-000217 STILL EXPECTS 7a90…d41f OP-000218 STILL EXPECTS 9f3a…c47e ✕ MISMATCH ✕ MISMATCH
A verifier walks the chain and compares each fingerprint to the record it claims to follow. Rewriting one operation invalidates every operation after it — which is exactly the property that makes the export worth forwarding.

The comparison that matters

A log line and a receipt are not the same artifact.

The question your client asks An RMM log line A PAM access record A Seraph receipt
Who told it to do this?Not recordedYes — the requestYes — the named authorization
What privilege did it use?Standing agent rightsYesLeased, scoped, with its expiry
What exactly ran?A summary the tool wroteOut of scopeThe signed job itself
Who says it worked?The tool says soOut of scopeThe target machine answered
How do I undo it?Figure it outOut of scopeDeclared before execution
Can it be edited afterwards?Usually, by an adminUsually, by an adminNot without breaking the chain

Read this as a difference in what the artifact is for, not a scoreboard. A PAM access record is excellent at the thing it was built for. It was simply never built to tell you whether the work succeeded.

What you do with it

The receipt is built to leave the building.

An audit trail nobody outside your team can read is an internal comfort. This one is designed to be forwarded.

The quarterly review

Walk into the QBR with the quarter's operations, each one verified and reversible, under your own branding. "Here is what ran on your environment, under what privilege, proven by your own machines."

Reporting & exports →

The insurance questionnaire

The automation section of a cyber-insurance renewal asks what your automated tooling is allowed to do and how you would know if it did something else. Answer it with records instead of prose.

For MSPs →

The incident question

When something goes wrong at 2am, the first question is "what changed?". One reference number resolves to the whole operation — command, privilege, job, confirmation, and the undo that is still available.

The operation loop →

Does the AI write its own receipt?

Does the AI write the receipt?

No — and this is the whole point. The receipt is assembled by the platform from things that happened, not from the model's account of what it did. The confirmation row can only ever carry what the target machine answered to an independent check. If that check did not run, the row says so rather than going quiet.

What happens when an operation fails?

It still produces a receipt. A failed operation is a real outcome and it gets the same record: what was attempted, what privilege it held, where it stopped, what the machine reported, and whether the declared undo was executed. A receipt that only exists for successes would be advertising, not evidence.

Can we export them?

Yes — PDF for humans, JSON and CSV for systems, per operation or per client per period. Review the published package scope for your operating requirements. We do not charge per receipt, because a platform that meters proof teaches you to ration it.

How long are they kept?

For the life of the workspace, with retention configurable per client. Records live in your tenant's own isolated storage — see Roles & Multi-Tenancy for how the walls between clients are drawn.

Is a receipt the same as session recording?

No. A receipt is the record of an operation — the authorization, the privilege, the job, the confirmation, the undo. Governed remote sessions are a separate surface with their own recording story, and we are deliberately narrow about what that covers today: see Governed Sessions.

Pick a claim and make us show it

Everything on this page can be demonstrated in under a minute.

Bring the hardest question from your last client audit. We will run an operation and open the record it produces.