Your agents are already making decisions. Find out which ones were outside their mandate.
Warrant turns what an AI agent did into a record a credit officer, a CFO and an examiner can read: what was decided, under which clause of which policy, on what evidence, at what cost, and how it turned out. It starts from the logs you already keep.
Runs inside your environment · open-source core · every figure on this page is synthetic
Day one of every engagement
Six past approvals, checked against the written credit policy. Three were outside it.
No new integration. We read the trace exports your engineers already produce, rebuild each decision, and test it against your policy as written. This is the output on our example lending export.
| Loan | What happened | What the policy says | Finding |
|---|---|---|---|
LN-30002 | Approved by the agent | CR-07 clause 4.3 Refer tickets above 5,00,000 to a credit officer | Should have gone to a human |
LN-30003 | Approved by the agent | CR-07 clause 4.1 Decline below bureau floor | Should have been declined |
LN-30004 | Approved by the agent | CR-07 default No clause covers this case | Should have gone to a human |
Records rebuilt from traces are labelled as imported. They are findings to act on, and are never presented as evidence sealed at the time of the decision. Sealed evidence starts when the agent records live.
Readable by the people accountable
The file a human approver would have left behind.
When a person approves a loan, the file shows who, under which rule, looking at which documents. Warrant produces the same file for an agent, in words, for every decision.
Underneath is the sealed record, with evidence held as references and hashes that point back to your own systems. Customer documents stay where they are.
What happenedcredit-underwriter (version 2.3.1) carried out “approve” for LN-0411, on behalf of branch:jayanagar.
Was it allowedPolicy CR-07 (version 2026.3) allowed this under clause 4.2: auto-approve up to 5,00,000 when bureau score is at least 720 and FOIR at most 45%.
What it relied onOne piece of evidence, recorded by reference and hash: bureau_pull (tool call).
What it costINR 3.84, charged to cost centre retail-lending.
How it turned outOutcome “performing”, from the loan management system.
Human review
Three queues, so reviewers spend their time where the risk is.
Escalations
The policy, or the agent itself, asked for a human to decide.
Flagged
The agent acted although the policy did not allow it, or the policy could not be evaluated and fell back to its fail mode.
Random sample
A fixed share of everything else. Which decisions are sampled is derived from each record's sealed hash, so neither the agent nor the reviewer can choose what gets checked.
A reviewer's verdict is added to the ledger as its own sealed record. The original decision is never changed, so the file shows both what the agent did and what your officer thought of it.
For your examiner and your auditor
They do not have to trust us, or you.
Every record's hash covers the record before it, and the store refuses edits and deletions. Hand an examiner the export and they can check the whole chain offline with a free, open-source verifier.
This panel is that check, running in your browser on five records sealed by the SDK. Change one and see what an examiner would see. Signed checkpoints are on our roadmap; until then, keeping each export, or only its last hash, outside the store closes the remaining gap.
- lending #1LN-0411 · approve · allowed by CR-07 §4.2checking
prev start of chainhash 33a6364c…d61f - lending #2LN-0417 · approve · allowed by CR-07 §4.2checking
prev 33a6364c…d61fhash 07c3c8b2…11fe - lending #3LN-0423 · held back · sent to a human by CR-07 §4.3checking
prev 07c3c8b2…11fehash 1b6ed143…bc3b - lending #4LN-0431 · held back · denied by CR-07 §4.1checking
prev 1b6ed143…bc3bhash 1d81e349…d46d - lending #5Outcome recorded later: performingchecking
prev 1d81e349…d46dhash 274d2c24…20dc
Checking the chain in your browser…
Deployment and scope
Inside your environment, beside the agent, never in front of it.
A small library in the agent's process, a collector and a PostgreSQL database in your own cloud. Your model traffic never passes through Warrant, and if Warrant is unavailable the agent keeps working and records are delivered later.
What is built today
- A plain-language reading of every decision, with evidence references and cost
- Review queues with verdicts appended as new sealed records, never edits
- Cost per decision by class, cost centre and agent version
- An export any third party can verify offline with a free tool
What is coming, and not yet built
- Audit packs: a sampled set with policy versions and a verification report
- Single sign-on and a read-only auditor role managed by your identity provider
- Signed checkpoints, so tampering is evident without a second copy
- A hosted India region for teams that do not want to self-host
Audit and assurance firms: if your clients are putting agents into regulated workflows, talk to us about reviewing those decisions with the same tools. Use the form below.
The two-week test
One real workflow. Fourteen days. A finding on day one.
We start with what your agents have already done, not with a new integration. The fee is credited in full against your first year.
- Day 1Import the traces you already have, check every past decision against your written policy, and hand you the first finding.
- Days 2 to 5Instrument one live agent workflow inside your environment. Nothing leaves your systems.
- Days 6 to 12Record real decisions. Your risk team runs one review cycle on escalations, flagged decisions and a random sample.
- Days 13 and 14A written finding, a replay walkthrough for your engineers, and an export your auditor can verify offline.
Book the test
Leave a work email. One reply, from a person, within two working days.