GneissGROUP / Kessa
Open source · Gneiss Group

Prove what your agents actually did.

Kessa is a self-hostable, independent verifier for AI agent delegation and attestation. It re-derives the authorization history of any agent action from exported evidence alone, trusting no running service, no database, and specifically not the enforcement point that produced the log.

Any consequential agent action, provably traceable to an authorizing human.

Autonomous agents increasingly act under a delegation chain: a human authorizes an org, an org authorizes an agent, an agent authorizes a sub-agent. Kessa records every consequential action in a tamper-evident audit log, and lets an independent verifier re-check that record without trusting anyone who wrote it, including the system that enforced it.

Attenuation-first delegation
Authority can only narrow as it's delegated, never expand, and every hop is provable after the fact.
Self-hostable by design
No hard dependency on any hosted service. Built for organizations that need to keep this inside their own trust boundary.
Open standards, no blockchain
Built on did:web, verifiable credentials, and standard cryptographic primitives, inheriting the web's own trust model.
Independence enforced at build time
No service of ours is in the loop. The verifier's dependency closure is kept near-stdlib and Apache-2.0, and the build fails if anything in it reaches an AGPL-tier package.
Public and working end to end, under active development

The repository is public. kessa verify runs offline, with no dependency on anything Kessa operates: clone it, cut the network, and it re-derives every verdict from signed evidence alone.

The codebase has been through multiple rounds of self-run AI red-team review, not a third-party audit. Every finding, and where each one stands, is recorded in a public register. Room for two design partners.

AGPL-3.0-only core. Apache-2.0 verifier.

The enforcement engine, proxy, issuer, and agent are AGPL-3.0-only. The independent verifier and designated plugin interfaces are Apache-2.0, so the part whose entire value is running trusted by no one, including us, isn't the part you need our permission to use. Organizations that cannot meet the AGPL's terms are welcome to discuss a separate commercial licence: sales@gneiss-group.com.

Get in touch

Whether you're evaluating Kessa as a design partner, thinking about agent governance for your own org, or just want to know more, reach out.

info@gneiss-group.com →