Businesses run by agents.

Actions you can prove.

Action State builds AI agents for businesses and the open evidence layer that proves what those agents did.

What you can do with it

What we build

GetGopher

A managed AI operator for business owners — delivered over text message, run by us, governed by deterministic checks with a human approval on anything consequential. Built for people who run their business from their phone.

The Evidence Layer

The Agent Action Capsule standard and the open stack beneath it — a tamper-evident, independently verifiable record of what any agent did, open source and free to verify offline.

The Open Standard

Agent Action Capsule — proof of what an agent did

An open IETF Internet-Draft and reference implementation for a tamper-evident, content-private, independently verifiable record of a single agent action — checkable by anyone, without trusting the operator. Built on the SCITT/COSE transparency standards, with an open verifier you can run in under a minute.

The open stack

1
2
3
4
5
6
1

Agent Action Capsule (AAC)

The record of one agent action: what happened, for whom, under what authority, and what was left out. Tamper-evident, content-private, independently verifiable. →agentactioncapsule.org

2

Canonical Payload Binding (CPB)

The digest rule underneath it, so two independent implementations never disagree about what was actually signed.

3

Checkpointed Local Log (CLL)

A node's own append-only log of its actions, checkpointed for external registration. MMR, checkpoints, disclosure bundles. → github.com/action-state-group/checkpointed-local-log

4

Witnesses

Independent third-party records that a checkpoint was included in an independent log and was never rewritten. Plural by design: any log can register the same checkpoint with more than one service.

5

Verifier

Open source, runs offline, checks all the above without asking anyone's permission.

Plus free, stateless hosted verifier at verify.agentactioncapsule.org

6

scitt-cose — substrate

The SCITT/COSE signing-and-receipt primitives everything above is built on.

After you know what your agent did

The record is the floor, not the finish. A capsule proves what an agent did; the product is the decision a recipient makes from it — accept the invoice, reconcile the transaction, close the incident, sign off on the obligation. Evidence comes back in four separate layers — valid · covered · interpreted · accepted: the signatures check, the capture boundary is stated and tested, the business rule has been applied, and a party actually relied on the result. We never round those four into one green "verified." The layers below the fold are already open and free to check; the workflow that turns them into a decision someone accepts is what Action State Cloud runs with you.

Obligations → actions

Which obligations did this agent actually satisfy — and can I recompute it myself?

An obligations pack (EU AI Act to begin) binds each clause to the actions that satisfy it, and produces an attainment report a reviewer recomputes from the capsules — not a badge to trust. Record integrity isn't factual truth, and a selected log isn't the whole activity: the report shows what's established, what's covered, and what's still a gap.

Outcomes → actions

Which items should I accept and pay for, under the definition we agreed?

Builder outcomes tie each billable action to its confirmation evidence under an agreed, versioned outcome definition — failed attempts, duplicates, reopened cases and later reversals all counted under explicit rules. The extension is a verified service statement a customer can accept or challenge without being given access to the vendor's operational systems. Completeness still reconciles to the contract and source systems — we say so on the statement.

Cross-organization evidence

Across both our systems, what did the agent do — and whose record settles it?

The A2A case file assembles an incident or delegated-action dossier, or reconciles a transaction, across providers: both halves of the exchange, and an evidence request that comes back answered, refused, or unanswered — never a silent gap. Verification is portable and offline. A witnessed history resists rewriting; it can't by itself show goods were delivered or who the counterparty was — that needs corroboration, and the case file says which is present.

Free

Verify any capsule offline with the open verifier — no account, no access to our systems.

We run

The clause-to-action mapping, the attainment report, and exception handling.


Stay tuned, more coming

What we don't claim, on any of these

No automatic chargeback acceptance and no liability transfer; no fraud elimination; no insurance premium credit; no "your logs can't be tamper-evident" (they can — AWS CloudTrail already signs and validates its digests); and no "percentage of actions sealed" as a safety number unless its denominator is independently reconciled. A valid bundle can still be incomplete, unsupported, or rejected — which is exactly why we report four layers, not one.

Credibility

Three individual Internet-Drafts filed — Agent Action Capsule (-04), Canonical Payload Binding (-03), Checkpointed Local Log (-01)

Conformance vectors merged into the IETF SCITT working group's shared example repository and into Project NANDA's trust-layer interop

Cited by an independently authored Internet-Draft

Open verifier and witness (Apache-2.0) · reference library (BSD-3-Clause)

Silver member, Agentic AI Foundation

All related patent filings abandoned; donation of the project to a neutral foundation intended

Who's behind this

Steven Mih

Steven has led four venture-backed companies, including Ahana, which he co-founded in 2020. The cloud-native Presto data analytics service acquired by IBM in 2023. He served on the board of the Linux Foundation's Presto Foundation. Thereafter, co-foundered Across AI to tackle agentic memory. Most recently he founded Action State the AI-native startup for the agent era: building agents, filing the IETF Internet-Drafts that define the Agent Action Capsule standard, and building the open stack — verifier, witness, reference library — that makes agent actions independently checkable.

The record layer I keep talking about is real and open: the Agent Action Capsule, filed with the IETF, running today in a peer-to-peer LLM network I don't operate.

Field Notes on the Agent Economy

Working notes from operating businesses on agents and building the trust layer they need — what works, what breaks, and what the ecosystem is missing.

Agents crossed the effect boundary. Your logs didn't.

Field Notes on the Agent Economy · Action State · June 2026

When an agent crosses the effect boundary — the point where a decision becomes a real-world consequence — the important question quietly changes. It used to be 'is the output good?' Now it's 'what did it actually do — and can you prove it?'

Logs prove nothing — and the web already fixed this once

Field Notes on the Agent Economy · Action State · June 2026

This week we open-sourced scitt-cose, a standalone verifier for IETF SCITT receipts and signed statements, along with a free hosted verifier at verify.agentactioncapsule.org. This post is the story of why a company that builds agent-operated businesses ended up shipping verification infrastructure — and why the answer was sitting in a pattern the web has now had to learn twice.

Evidence, not trust

An assurance map for accountable agent action

Everything on this site rests on one discipline: report what evidence establishes, and name what it doesn't. This is the long form — the map we hold ourselves to, limits included.

What evidence establishes

Named, checkable, recomputable.

What it doesn't

Named just as clearly. No rounding up.


© 2026 Action State Group, Inc. · All related patent filings abandoned.