Writ is a lightweight, deterministic security protocol that is crafted specifically to restrict and audit any real-world authority given to AI agents.
Writ is a lightweight, deterministic security protocol that is crafted specifically to restrict and audit any real-world authority given to AI agents.
Project Details
Updated 07/16/26 · Provided via application · VerifiedWrit is a lightweight, deterministic security protocol that is crafted specifically to restrict and audit any real-world authority given to AI agents. This is a defense utility designed to ensure that when an agent fails or becomes compromised, the resulting damage is bounded, detectable, and attributable. It is a software layer that serves as a buffer between an agent and external systems it is allowed to use (financial APIs, cloud infra, databases, etc), not an alignment attempt.
Writ operates through three main mechanisms:
Deterministic bounds - Enforces hard limits on what an agent CAN do so that it cannot exceed its authorized budget.
Cryptographic Attribution - Every action the agent takes will be signed and logged into a registry that is tamper evident. This creates an audit trail of exactly what the agent did and when.
Fast Revocation - When an agent behaves unexpectedly its credentials can be revoked globally within a 50 second ceiling, effectively stopping it from doing anything further from that point.
I will be the only person involved for the majority of this project, with one independent reviewer brought in if the full budget is granted. This project is estimated to take around 5 to 6 weeks of full time building and will include a full written specification of the invariants written down and argued, as well as a hard-kill gate writeup, which would provide the conditions under which the layer isn't needed and posted publicly. The design of Writ is already complete and this funds the first implementation. This round proves that it is buildable and the invariants hold in the running code with actual measured numbers. It doesn't prove adoption, and it is only one control primitive, not the entire answer to the issues presented.
Theory of Impact
Updated 07/17/26 · By grantmaking.aiCurrently agents are being handed real-world authority faster than the security layer that binds it is created. We cannot trust in-model alignment (it is probabilistic) to be aligned with us and because deployers will inevitably over-trust these probabilistic model boundaries, a deterministic safety layer is required to exist. You cannot, and should not, make the LLM your entire boundary layer. Ironically this metering layer doesn't exist and is cheap to build. This project is applied AI control and containment, not alignment theory at all, this isn't relying on the agent to WANT to behave perfectly and it does not prevent agent compromise.
Writ provides bounds and timestamps what a compromised agent does. It focuses on making exceeding mathematically impossible and makes everything else provably bounded, detected, and attributable. While it could be argued that bounding on a small budget of a few hundred dollars is not an existential issue on its own, as agent capabilities scale, the stakes of delegated (implicitly trusted) authority will grow rapidly to critical infrastructure. Verifiable, deterministic limits, independent of the underlying model, are necessary to prevent rapid and unattributable real world harm.
People
Updated 07/17/26 · By grantmaking.aiTeam Member
Discussion
No comments yet. Be the first to share your thoughts.