The Write-Governance Layer for Enterprise AI
Built by Ishaan Ghosh, Founder & CEO.
1,000 writes governed at the boundary. Zero memory trail loss. Independently validated in the Constitutional Memory Report.
Production Proof
1,000 governance decisions, each with an independently verifiable receipt (400 allowed / 600 blocked). Every write intercepted and validated before it lands. Governance as enforcement, not performance.
Mapped to EU AI Act Article 14
Designed and mapped to the Article 14 human-oversight requirement — not a legal compliance certification. Human oversight is REPLAYABLE. Oversight without interception is just post-hoc documentation.
Infrastructure, Not Documentation
Memory custody at the write boundary — not application-layer logging. TBN Protocol for trust identity. ShangoVault for sovereign governance.
What the evidence actually is
Every figure dated, sourced, and checkable. Where a number is registrant-produced rather than independently verified, it says so.
230,269 entries in the ShangoVault audit trail, hash-chained locally. The overwhelming majority are simulation-agent records from a load exercise and are labelled as such — they are not attested, and they are not evidence of production governance. Counter-signed receipts are a separate and far smaller set; see the next card.
230,269 entries in the ShangoVault audit trail, hash-chained locally. The overwhelming majority are simulation-agent records from a load exercise and are labelled as such — they are not attested, and they are not evidence of production governance. Counter-signed receipts are a separate and far smaller set; see the next card.
Counter-signing is not running in the current build: receipts are committed but not counter-signed. Thirteen completed runs remain independently verifiable against the attester's published key at tbn.hardinai.co.uk/api/v1/verify/{receipt_id}. The largest is 1,000 governed decisions on 2026-06-04 — 400 permitted, 600 blocked. 3,799 of these sit on a chain shared with the attester and were reconciled from both sides on 2026-08-01 with nothing unaccounted; the remaining 1,995 use an earlier construction and are verified individually. See /transparency.
SHA-256 hash-chain linkage verified across the chained subset — 0 linkage breaks; full content-recompute in progress. Two-phase replay logger: every governed write is replayable and attributable.
TBN attestation → rate limit → field checks → injection scan → compliance → cost → constitutional reasoning → audit. Custody at the middleware write boundary, not application-layer logging.
Designed and mapped to EU AI Act Article 14 (human oversight). Decision trails are replayable, not post-hoc documentation.
Shango's 1,000-write governed run was independently cited by Greg Malpass in the Constitutional Memory Report (May 2026).
The published record
What it does, and what it does not.
There are more things declared here that Shango MID cannot do than things it can. That is deliberate. A control you cannot inspect the limits of isn't a control — it's a reassurance.
What it does
- Decides whether an automated write is permitted before it happens
- Commits the receipt inside the same database transaction as the decision
- Rolls the decision back if the receipt cannot be written
- Detects alteration of a committed receipt via the hash chain
- Produces receipts a third party can verify offline against a published key
What it does not establish
- Prove that nothing happened outside the governed path
- Establish that a permitted action actually occurred
- Verify the acting agent's identity — the actor is the caller's assertion
- Counter-sign receipts in the current build — that is not running
- Hold any certification, accreditation or conformity assessment
Eleven limitations in total, filed in full on a public registry record. Shango MID is pre-revenue: no customers, no delivered engagements, no third-party production deployments.
400 permitted, 600 blocked. Counter-signed and verifiable offline against a published key.
The authorisation-context run. Two 500-receipt runs exist, so the date is the identifier.
Of the 14: nine borne by shipped code, four by test scaffolding, one with no mechanism.
Every figure traces to one of these
Not independently recomputed — the conformance runner is closed.
With Tim Zlomke. A specification arrived at by argument; neither author has implemented it.
Greg Malpass, Constitutional Memory Governance (2026).
Registration is not certification and verifies none of these claims.
Defects found in this architecture are published with the name of the reviewer who found each one, including the ones that were ours. Check it yourself.
EU AI Act Article 14 — Designed for Replayable Oversight
Mapped to the human-oversight requirement — not a legal compliance certification
Designed and mapped to the Article 14 human-oversight requirement through replayable decision trails — not a legal compliance certification.
Every AI decision can be replayed, audited, and verified with hash chains. Two-phase replay logger.
Core enforcement and audit layers built and running. Engine hardening (authz, tenant isolation) in progress.
Logging = observability. Evidence = accountability. We produce the latter. Governance as enforcement, not performance.
Not application-layer logging. Custody at the write boundary itself. Interception, not documentation.
Independently cited by Greg Malpass in the Constitutional Memory Report (May 2026).
“1,000 AI-driven writes, zero memory trail — until we added the two-phase replay layer. Now every write is replayable, attributable, and governable. Agentforce is already making 10,000+ autonomous writes per session with zero memory governance. The EU AI Act requires human oversight (Article 14), but oversight without interception is just post-hoc documentation.”
Constitutional Memory Report, May 2026