Here's a question worth asking anyone putting AI agents into production: six months from now, when a regulator or a customer or your own general counsel asks exactly what the agent did on March 14th, and in what order, and whether a human approved it first, what are you going to show them?
The honest answer, most of the time, is "the logs."
Which raises the follow-up nobody likes: who can edit those logs?
Logs Are Testimony, Not Evidence
Agents aren't demos anymore. They're issuing refunds, sending emails on your behalf, moving money, updating customer records. Real actions with real consequences. And the record of those actions lives in a logging pipeline that your own engineers can write to, truncate, and "clean up."
That's fine for debugging. It's useless in a dispute. A log file is your own testimony about yourself. The minute anyone has a reason to doubt you, it's worth exactly as much as your word, because anyone with the right access could have changed it and nobody would ever know.
The first version of Engrave had this exact problem, and I'll own it. It had a verify endpoint that returned {"verified": true}. Think about that for a second. The server attesting to itself. That's not proof. That's a press release.
So I tore it down and rebuilt it around one rule: anyone should be able to verify the record without trusting us. Including an auditor who has every reason not to.
What Engrave Does
Engrave is the black box recorder for AI agents. Every tool call, prompt, and decision your agents make goes into a tamper-evident, hash-linked trace. Each span's hash includes its parent's hash, so removing or reordering a step breaks the chain. That matters more than it sounds. It means you can prove the human approval happened before the refund, not just that both happened.
Traces roll up into a Merkle tree with an Ed25519-signed tree head, using the same inclusion and consistency proofs (RFC 6962) that Certificate Transparency uses to keep the entire web PKI honest. Records are canonicalized with RFC 8785 before hashing, so the same JSON always produces the same bytes. And every tenant's tree root gets hashed into a global witness tree published at a well-known URL, so we can't quietly fork one customer's history either.
The verification side is the whole point, so it's deliberately small. The verifier is a zero-dependency library that runs in the browser. There's also a CLI:
engrave verify tx:918273/4
engrave export --out q1-evidence.tgz
engrave verify --offline-pack q1-evidence.tgzThat last one needs no network at all. Hand the pack to your auditor, they verify it on an air-gapped laptop, and our servers never enter the conversation. That's the bar.
One Line to Wrap an Agent
If your agent talks to tools over MCP, which increasingly means every agent, you don't have to change the agent. Engrave runs as a proxy in front of the MCP server:
claude mcp add crm -- engrave mcp proxy --upstream stdio:"npx -y @vendor/crm-mcp"
Responses pass through byte-identical. The agent doesn't know it's being recorded. The tool doesn't know either. You just get a provable record of every call that crossed the wire.
Decisions I'd Make Again
A few choices that aren't obvious from the outside:
- It's not a blockchain. I wrote this into the product spec in plain words: marketing may say "blockchain-grade," engineering must never build a chain. You don't need consensus among strangers. You need an append-only log with public proofs. Certificate Transparency has done that at internet scale for a decade.
- Gaps get recorded, not hidden. If recording is interrupted, Engrave writes a
recording_gapentry. I'd rather tell you honestly that four minutes are missing than pretend the ledger is complete. An audit trail that hides its own holes isn't one. - Your evidence is never held hostage. If you blow through a plan's quota, writes stop. Reads and proofs keep working. Evidence you already recorded belongs to you, paid up or not.
- We say "supports," never "compliant." Engrave produces evidence that maps to the controls auditors care about. It doesn't make you compliant with anything, and anybody selling you a box that does is selling you something else.
How It's Built
The whole thing runs on Cloudflare. A Hono API on Workers, one Durable Object per tenant acting as sequencer and write-ahead buffer, which gives you single-writer total ordering and fast durable acknowledgments for free. Behind that, each tenant gets its own Neon Postgres project as the system of record. There's no shared database for someone else's bug to leak your data from.
The Neon HTTP driver doesn't do interactive transactions, so every commit is a single SQL statement built from CTEs. That constraint sounded painful and turned out to be a gift. When a commit is one statement, there's no half-committed state to reason about.
Signing up doesn't provision anything. The tenant's database gets created on first write, which keeps the free tier actually free to run.
Who This Is For
If you're a platform or AI engineer putting agents in front of real systems, this is the audit trail you'll wish you had the first time something goes sideways. If you're in compliance, it's evidence you can hand to an outside auditor without asking them to take your word for anything. And if you're the auditor, you finally get to verify instead of trust.
Agents are going to take more and more consequential actions on our behalf. "Check the logs" isn't going to hold up for much longer. Proof will.
Engrave is live at tryengrave.com, with a free tier. Wrap an agent in one line and verify any step in your browser. If you're putting agents into production and want a second set of eyes on the architecture, book a call.