AppendOnly

A record system for AI agents

The models change.
The record doesn't.

AppendOnly gives a company a defensible record of what its AI agents actually did, underneath the language the agents use to describe it. Every action leaves evidence the agent cannot edit. Every claim is held to what the evidence supports.

Evidence before language.  ·  by 5R Industries

our own record in time · drag to turn · click, then scroll to move in
day on the spineseat commit, signedbefore signingunattendedend of dayexternal stamp on the head it namesincident, beside its commitan answer's footprintthe graded pastthe open row
0001what we do

A record under the agent, not a report from it.

Most AI adoption stalls at the same question. When the model says it finished, checked, or verified something, how do you know? We answer that structurally rather than by trusting the report.

Evidence before language

Each action produces a system-captured evidence record: the file hash, the commit, the process, the test result. A claim above its evidence is downgraded to what the evidence supports. A claim with no evidence is marked as a claim.

Tamper-evident by construction

The record is append-only and hash-chained, signed daily, stamped by outside witnesses, and anchored on a machine the agent cannot reach. Rewriting history is detected on the next cycle.

A second, independent opinion

A separate model of a different make verifies every record. Disagreement is surfaced, never averaged away. If the verifier goes quiet, that is itself an alert.

0002the record

This is what one workflow step leaves behind.

Not the agent's summary. The rows the system wrote while the agent worked, each one chained to the row before it. The step below is a requirement turned into a workflow object, with a claim the record caught and a handoff to a fresh session.

seqtimeactorverbtargetevidencelevelhash
041214:02:11agent-2READ_FILErequirement.mdsha256 3f9c…a1evidenced7d06…b1
041314:02:19agent-2SEARCHEDrecords/ (14 files)query hash 91e0…44evidenced52eb…ce
041414:02:40agent-2WROTE_FILEworkflow.yamlsha256 8b21…0e · 2,118 Bevidenced2ee1…e6
041514:02:41agent-2COMMITTEDworkflow.yamlcommit 9f3f912 · signedverifieddac6…57
041614:03:05agent-2RAN_TESTacceptance 1 of 4exit 0 · 0.8 sevidenced7805…c5
041714:03:09agent-2RAN_TESTacceptance 2 of 4exit 0 · 1.1 sevidenced00bd…ab
041814:03:14agent-2RAN_TESTacceptance 3 of 4exit 0 · 0.9 sevidenced11cf…84
041914:03:15agent-2CLAIMED"complete and verified"3 of 4 tests in recorddowngraded79e1…cc
042014:03:16verifierVERIFIEDrows 0412–0419second model · agreesverified8e02…19
042114:03:16observerFLAGGEDrow 0419test 4 absentopena4c1…7f
042214:03:20systemHANDOFFagent-2 → agent-3state = rows 0001–0421verifiedc9b3…02
042314:04:02agent-3READ_FILE_orient.mdsha256 66d1…9aevidencede0f4…5d
042414:04:31agent-3RAN_TESTacceptance 4 of 4exit 0 · 1.4 sevidenced3b7a…e8
042514:04:33observerCLOSEDflag on row 04194 of 4 tests in recordverified91aa…40
042614:05:00witnessANCHOREDday headstamp · externalverifiedf21c…3e
0427—next rowopen
Illustrative rows in the shape the system produces. Levels: evidenced = the action left system-captured evidence · verified = a second, independent model agreed with the record · downgraded = the agent claimed more than the evidence supports.
0003why now

Work that takes weeks does not fit in one session.

Every session starts empty. The industry's answer is memory: notes, summaries, instruction files. A notebook the agent writes to itself. Nothing checks whether it is true, nothing says when it went stale, and the agent that writes it is the one with the incentive to look finished.

When a session ends here, the next one does not inherit the last agent's account of the work. It inherits the record of what actually happened, and the handoff is itself a recorded, verified event. A fresh session starts cold, reads the record, and continues. That is the difference between memory and a record you can resume from.

VerifiedEvery claim carries the level its evidence earned, checked by a model that did not make it.
Current by constructionThe record is the work as it happened, not a summary written afterward.
Outlives the sessionSessions, models, and vendors change underneath it. The record does not.
Yours to holdExecution and evidence stay on your machines. You hold the anchor; we cannot rewrite what you hold.
0004how we work

Three steps. Each one earns the next.

step one
Demo

On your public work, on hardware we bring. You watch the record fill in as an agent works, hold the anchor, and watch a tamper attempt get caught.

step two
Paid pilot

One real workflow, fixed price, six to eight weeks. Delivered running on a machine you control, with its audit record and one measured before-and-after.

step three
License

The verification layer under the workflows you deliver, priced from what the pilot measured, supported by us.

We build for acquisition, administrative, engineering, and document workflows. The record is of agents and evidence. It is never used to evaluate an individual person. Every person sees every row the record holds about them, and every read of those rows is itself a row.

0005the report

The Record Does Not Change.

What a verifiable record of AI-agent work costs, what it saves, and how it works, measured on one company since March 2026.

The first public release is the argument and the measured results: the cost of running one AI chief of staff for 55 days, taken from the session records; the five lines on an income statement where the record changes a number; six industries where those lines are already regulated; and what one deployment can and cannot prove. Every number was measured on 17 September 2026 from the live system.

Read the report (PDF, 7 pages)

Second release, the system as deployed: 12 October 2026. Third release, a case study of one federal proposal run on the record: after the captured run.

Verify this document. Anyone can check that the file above is the one in our record and has not changed since. Its SHA-256 is f5900debd1c191cc1ce288edadefd05fb05ddaad13a2c67846008b6547c142ec. That fingerprint is committed and signed in our record, and the record's head is stamped into a public timestamp service every morning; the stamp for this release and the one-command check are published beside it. The check proves origin and integrity, that these bytes came from our record at that time; it does not vouch for what the document says.

0006who

Built by running a company on it.

AppendOnly began as an answer to our own problem. Running a company with an AI chief of staff, we needed to trust the record that AI kept. What we built for ourselves is what we now share, and we run our own company on it every working day.

We say two things on day one. The record makes it hard for an agent to describe its work more favourably than the facts, and a change to the past shows by the next morning; it does not stop a determined actor with valid credentials. And sensitive data stays off our machines.

Write to Adrian

Adrian Outlaw, Founder
Lieutenant Colonel, US Army (Ret.)
West Point, BS Mechanical Engineering
UVA Darden, MBA
George Washington University, MS Mechanical Engineering
Service-disabled veteran

5R Industries LLC, Virginia
Service-Disabled Veteran-Owned Small Business
CAGE 20P23 · UEI KC4EGEP2NTX4
Patent pending