Repository navigation
Trust Receipts (earned autonomy) + Time Machine (org replay) - #3
Merged
Merged
Conversation
Two features that only work because everything in Buzz is a signed event. Trust Receipts — autonomy that is earned, not toggled: - Agent profile lists the agent's real work sessions (from its signed kind:44200 turn metrics). Approving or rejecting one signs a KIND_TRUST_DECISION (43101) event from the owner and publishes it. - The ledger joins decisions with sessions into an approval rate and the level the agent has earned (ask -> trusted at >=5 decisions & >=80%, autonomous at >=20 & >=90%). "Promote" applies it to the existing trust dial, so the permission mode follows the evidence. - "Mint receipt" signs a KIND_WORK_RECEIPT (43102) snapshot of the ledger and copies it; "Verify a receipt" checks any pasted receipt offline — signature, kind, and that the signed summary matches the envelope. Time Machine — /time-machine, in the sidebar: - get_org_timeline returns a time-ordered slice of the workspace log (messages, agent turns, jobs, approvals, huddles, trust events). - The screen reconstructs the org at any instant from those events — who was working, which rooms were live, huddles/jobs/approvals in flight — with a scrubber, an activity profile, and a 30s replay. Reconstruction is pure and unit-tested (reconstruct.test.mjs). Relay: registers 43101/43102 as owner-signed global kinds and adds the fork's meeting kinds (48107/48108) to the ingest scope table — they were never registered, so transcript/summary writes would have been rejected. Signed-off-by: Eli <elijamesau@gmail.com>
This was referenced Sep 17, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this adds
Two features that fall directly out of Buzz's signed-event architecture — things a Slack/Discord-shaped product structurally can't do.
Trust Receipts — autonomy you earn, not a toggle you flip
kind:44200turn metrics). Each session gets 👍 / 👎.KIND_TRUST_DECISION(43101) from the owner's key, tagged with the agent and session. The ledger is tamper-evident by construction.KIND_WORK_RECEIPT(43102) snapshot of the ledger, publishes it, and copies the signed JSON — a portable "94% approval over 31 sessions" that anyone can check.Time Machine —
/time-machine(sidebar, below Pulse)get_org_timeline(since, until)returns a compact, time-ordered slice of the workspace log: messages, agent turns, jobs, approvals, huddles, trust events.features/time-machine/lib/reconstruct.ts) with its own test suite.Relay
required_scope_for_kind(MessagesWrite) andis_global_only_kind, and in the metric-label allowlist.KIND_HUDDLE_TRANSCRIPT/KIND_HUDDLE_SUMMARY, now 48107 / 48108) were never in the ingest scope table, so the relay would have rejected every transcript/summary write withrestricted: unknown event kind. NowChannelsWritelike the other huddle kinds.