{"block_close_oss.c33fd1fe9c":"Community and ecosystem","open-source-knot.a10f000001":"Record coverage","open-source-knot.a10f000002":"Every agent action and result","open-source-knot.a10f000003":"Evidence timing","open-source-knot.a10f000004":"Created while the work runs","open-source-knot.a10f000005":"Sensitive data","open-source-knot.a10f000006":"Masked before storage","open-source-knot.a10f000007":"Evidence bundle","open-source-knot.a10f000008":"Portable and independently verifiable","open-source-knot.a10f000009":"Verification","open-source-knot.a10f000010":"Offline with the public key","open-source-knot.a10f000011":"Deployment","open-source-knot.a10f000012":"On premise or in an EU region","open-source-knot.a10f000013":"Signed evidence","open-source-knot.a10f000014":"Offline verdict","open-source-knot.a10f000015":"ORDERED","open-source-knot.a10f000016":"Behind the helper","open-source-knot.a10f000017":"Every action leaves","open-source-knot.a10f000018":"an honest receipt","open-source-knot.a10f000019":"When a helper looks something up, writes a reply or saves work, Knot keeps the action and its result together. Each new note is tied to the one before it, so the full sequence remains clear and later changes cannot hide.","open-source-knot.a10f000020":"ACTION","open-source-knot.a10f000021":"RESULT","open-source-knot.a10f000022":"ORDERED","open-source-knot.a10f000023":"SEALED","open-source-knot.a10f000024":"What the receipt keeps","open-source-knot.a10f000025":"Four facts that travel together","open-source-knot.a10f000026":"Action","open-source-knot.a10f000027":"What the helper did","open-source-knot.a10f000028":"Time","open-source-knot.a10f000029":"When it happened","open-source-knot.a10f000030":"Result","open-source-knot.a10f000031":"What came back","open-source-knot.a10f000032":"Seal","open-source-knot.a10f000033":"Later changes stand out","open-source-knot.a10f000034":"Made during the work","open-source-knot.a10f000035":"Honest by construction","open-source-knot.a10f000036":"When something is questioned","open-source-knot.a10f000037":"The record answers","open-source-knot.a10f000038":"without relying on memory","open-source-knot.a10f000039":"If someone asks why a helper made a choice, nobody has to reconstruct the story from memory. The sealed trail shows the exact sequence, hides sensitive details and lets a second person check what happened. The answer comes from the original run, not a summary written after the fact.","open-source-knot.a10f000040":"EXACT SEQUENCE","open-source-knot.a10f000041":"PRIVATE BY DEFAULT","open-source-knot.a10f000042":"SECOND PERSON","open-source-knot.a10f000043":"CHECKABLE","open-source-knot.a10f000044":"What answers the question","open-source-knot.a10f000045":"Facts from the original moment","open-source-knot.a10f000046":"Question","open-source-knot.a10f000047":"The decision that needs explaining","open-source-knot.a10f000048":"Timeline","open-source-knot.a10f000049":"Every step in order","open-source-knot.a10f000050":"Private details","open-source-knot.a10f000051":"Hidden before they are stored","open-source-knot.a10f000052":"Verification","open-source-knot.a10f000053":"Independently checked","open-source-knot.a10f000054":"Original run","open-source-knot.a10f000055":"Same story every time","open-source-knot.a10f000056":"Evidence operations","open-source-knot.a10f000057":"Built during the work","open-source-knot.a10f000058":"ready when scrutiny starts","open-source-knot.a10f000059":"Knot creates the evidence as the agent works, instead of asking teams to reconstruct it weeks later. It captures actions and results, masks supported secrets before storage, signs the timeline and exports a portable bundle for the next reviewer.","open-source-knot.a10f000060":"CAPTURED LIVE","open-source-knot.a10f000061":"MASKED EARLY","open-source-knot.a10f000062":"SIGNED CHAIN","open-source-knot.a10f000063":"PORTABLE BUNDLE","open-source-knot.a10f000064":"Evidence hand-off","open-source-knot.a10f000065":"From operation to independent review","open-source-knot.a10f000066":"Capture","open-source-knot.a10f000067":"Action and result","open-source-knot.a10f000068":"Privacy","open-source-knot.a10f000069":"Secrets replaced","open-source-knot.a10f000070":"Integrity","open-source-knot.a10f000071":"Root signed","open-source-knot.a10f000072":"Export","open-source-knot.a10f000073":"Bundle moves independently","open-source-knot.a10f000074":"Created once","open-source-knot.a10f000075":"Reused across reviews","open-source-knot.a10f000076":"EVIDENCE ON HAND","open-source-knot.a10f000077":"INCIDENT READY","open-source-knot.a10f000078":"Audit preparation","open-source-knot.a10f000079":"Generated by the operation itself","open-source-knot.a10f000080":"Incident triage","open-source-knot.a10f000081":"Exact chronology, not recollection","open-source-knot.a10f000082":"External review","open-source-knot.a10f000083":"Portable bundle and public key","open-source-knot.a10f000084":"Repeat checks","open-source-knot.a10f000085":"Same bytes, same verdict","open-source-knot.a10f000086":"Deployment","open-source-knot.a10f000087":"Inside the boundary you choose","open-source-knot.a10f000088":"One record","open-source-knot.a10f000089":"Many assurance questions","open-source-knot.a10f000090":"Incident response","open-source-knot.a10f000091":"Open the exact run","open-source-knot.a10f000092":"not a reconstructed story","open-source-knot.a10f000093":"When an incident starts, the response team works from the original timeline, tool results and file changes. Knot packages that evidence with its signed root, so an internal reviewer or third party can verify the sequence offline instead of debating a reconstructed account.","open-source-knot.a10f000094":"ORIGINAL TIMELINE","open-source-knot.a10f000095":"TOOL RESULTS","open-source-knot.a10f000096":"FILE CHANGES","open-source-knot.a10f000097":"OFFLINE VERDICT","open-source-knot.a10f000098":"What the incident team receives","open-source-knot.a10f000099":"One compact evidence package","open-source-knot.a10f000100":"Timeline","open-source-knot.a10f000101":"Ordered and timestamped","open-source-knot.a10f000102":"Calls","open-source-knot.a10f000103":"Request and response paired","open-source-knot.a10f000104":"Changes","open-source-knot.a10f000105":"Exact before and after","open-source-knot.a10f000106":"Verdict","open-source-knot.a10f000107":"Recomputed independently","open-source-knot.a10f000108":"Original evidence","open-source-knot.a10f000109":"No storytelling required","open-source-knot.a10f000110":"Reasoning certificates","open-source-knot.a10f000111":"Replay and state","open-source-knot.a10f000112":"Run Knot","open-source-knot.securityLayer":"Security layer","open-source-knot.dd1af329dd":"Knot records an agent run as it happens, masks supported secrets, links events into a signed Merkle structure, and exports a portable bundle. A reviewer can reconstruct and verify the run offline with the public key.","open-source-knot.a010de5c61":"Fabric","open-source-knot.fe0a091fdb":"Products","open-source-knot.9d98869f46":"Signed agent record. Read the log at any past point.","open-source-knot.6f45a48a1f":"Twin","open-source-knot.6cc3364a24":"Signed agent audit trails","open-source-knot.080b195445":"Reasoning certificates any verifier checks offline, in linear time.","open-source-knot.df84637182":"AION","open-source-knot.ecf1d8fed1":"Append-only, hash-chained event provenance with no quiet edits.","open-source-knot.1aa2f31ee7":"Ledger","open-source-knot.d5d6e83bf2":"Continue exploring","open-source-knot.75e393a1ac":"See the verification flow","open-source-knot.f9743247fa":"Read the documentation","open-source-knot.db52af1cb6":"Verify a record","open-source-knot.5b337c6152":"Create the first signed run, export its evidence bundle and verify the result offline with only the public key. The producer and reviewer never have to share trust.","open-source-knot.c1b8917f36":"A record you can prove, offline","open-source-knot.90e40d5043":"Get started","open-source-knot.7ec3788793":"Knot","open-source-knot.650fabe787":"Open Source","open-source-knot.60e364d768":"OSS / Knot","open-source-knot.2f4276666e":"Not a vendor","open-source-knot.266a9a0b8f":"You decide","open-source-knot.1011dfa597":"The default, not an upgrade","open-source-knot.e03947cc0c":"Sovereignty","open-source-knot.dd29e148b4":"You hold the signing key","open-source-knot.ace2425487":"Your keys","open-source-knot.ab65f2797e":"Inside a border you choose","open-source-knot.980c5d4a9d":"EU region","open-source-knot.8c0f01c721":"On your own machines","open-source-knot.499493296b":"On premise","open-source-knot.f23d59b4e0":"One ledger, your choice","open-source-knot.d5a9f6f81a":"Three postures","open-source-knot.932f88d5ae":"YOUR KEYS","open-source-knot.c387fd0cd2":"EU REGION","open-source-knot.766e2cad1e":"ON PREMISE","open-source-knot.f7c401f54e":"Two questions decide procurement: where does it run, and who controls it. Knot runs on the hardware you already own, on premise or in a European region, so the ledger stays inside a border you choose. You hold the signing key, and verification needs only the public half, so sovereignty is the default rather than an upgrade you negotiate for.","open-source-knot.3cd2aa3cc1":"and on your own ground","open-source-knot.b144a95356":"European,","open-source-knot.1d197d39c5":"Where it runs","open-source-knot.3751d8a6a8":"Runs on your infrastructure","open-source-knot.2e67859212":"Readable evidence bundle","open-source-knot.2edfbd5639":"Locally, on your own hardware","open-source-knot.fcde5c325d":"Runs","open-source-knot.327bdc843a":"Portable and independently verifiable","open-source-knot.bf5dde2d06":"Lock-in","open-source-knot.a148b36c17":"Signed agent audit trails","open-source-knot.fdb4974dbe":"Cost to use","open-source-knot.01cb445dea":"Portable bundle plus public key","open-source-knot.3123868410":"Repository","open-source-knot.3915907107":"Signed agent audit trails","open-source-knot.3229609e15":"Signed agent audit trails","open-source-knot.f988d88a5f":"What a buyer checks first","open-source-knot.fca77b7e3a":"One sealed event history","open-source-knot.776e61513d":"RUNS LOCALLY","open-source-knot.3115880727":"NO LOCK-IN","open-source-knot.5b116da2ea":"NO FEE","open-source-knot.c968638a6e":"EVIDENCE WHILE WORK RUNS","open-source-knot.87041198be":"The operational gain is fewer hours rebuilding history. The audit trail is created as the agent works, an incident team gets the exact chronology immediately, and an external reviewer can verify the same portable evidence without access to the production service.","open-source-knot.67f098af3f":"less audit work, faster answers","open-source-knot.3d1e7bdec2":"Signed agent audit trails","open-source-knot.6f696724c6":"What it saves and de-risks","open-source-knot.dd9b5baa54":"Provable","open-source-knot.3bd9f738cd":"Regulated industries","open-source-knot.feabfc9fa9":"Offline, on a laptop, no service","open-source-knot.dda6ac27b9":"Verify","open-source-knot.b53e5ed6d0":"A record you can stand behind","open-source-knot.0db809cc66":"Assurance","open-source-knot.35fd6b4860":"A pipeline inventory","open-source-knot.0679ce9143":"PIPELINE INVENTORY","open-source-knot.0534e1100c":"Evidence of data touched, PII masked","open-source-knot.a5b7d57a85":"Data protection","open-source-knot.f73e4db760":"Provable trace of automated decisions","open-source-knot.d75a4de2ef":"Regulatory traceability","open-source-knot.2b89699f87":"Where the value lands","open-source-knot.0c5ba882ee":"Who it is for","open-source-knot.93ee6f696a":"OFFLINE PROOF","open-source-knot.380f063397":"REGULATORY CONTEXT","open-source-knot.f8cae47263":"The reason to care is a durable record, not a dashboard. Knot keeps a signed, time-ordered record of what your AI agents do, and a third party can verify it offline. Whether that record satisfies a legal or regulatory obligation depends on the applicable requirement and how your organisation uses it.","open-source-knot.bd08c4b36d":"to the evidence","open-source-knot.a30745fc9f":"From the rule","open-source-knot.85681cc20d":"Controls and risk","open-source-knot.4fcf346811":"Just the benefit","open-source-knot.0b049b5346":"Nothing to do","open-source-knot.9ff73b0e0f":"Yes, a second person can check it","open-source-knot.ac09b9600c":"Trust it","open-source-knot.1c2d25f042":"People the owner authorises","open-source-knot.e6ad44f1ed":"Who can inspect it","open-source-knot.16b9cef8a4":"Blanked out, not kept in the clear","open-source-knot.1e7b6a03e9":"My data","open-source-knot.8219743477":"No, the team running it does","open-source-knot.6cb165ad18":"Do I need to watch it","open-source-knot.425d5db31c":"No, it works on its own","open-source-knot.cfe59e139d":"Manage it","open-source-knot.e3229cf237":"The questions people ask","open-source-knot.a12a815f9b":"Peace of mind","open-source-knot.4a4841a6f1":"NO WORRY","open-source-knot.bd4e9c0810":"NO SETUP","open-source-knot.b1f071a446":"NO EXTRA WORK","open-source-knot.e783432e3d":"It is fair to wonder whether something like this is yours to manage. It is not. Knot works behind the helper and keeps the record without interrupting what you are doing. You receive the benefit when a question needs a clear, checkable answer.","open-source-knot.c878874ffa":"Someone else does the work","open-source-knot.37a0b494b7":"You get the benefit","open-source-knot.8a61881223":"Set your mind at ease","open-source-knot.7e13d94a5a":"For you","open-source-knot.dd6c938563":"Plain good","open-source-knot.7f9d6471ea":"Stays on the owner machine","open-source-knot.dc99d54d99":"Local","open-source-knot.741b82b2c4":"Personal details are blanked out","open-source-knot.237dfa0a21":"Private","open-source-knot.4a912dcfe1":"You can show what happened","open-source-knot.be79703c98":"The record cannot be quietly changed","open-source-knot.9caa367403":"Honest","open-source-knot.f603c0224f":"In everyday terms","open-source-knot.ccb9f1391c":"Four reasons","open-source-knot.22b3558123":"CLOSE TO HOME","open-source-knot.b0b7ba4666":"PRIVATE","open-source-knot.89bb40e919":"PROVABLE","open-source-knot.fe453a5f12":"HONEST","open-source-knot.288d01e6fa":"You do not have to understand how it works to enjoy what it does. Think of it like a numbered receipt book or a second person counting the till. You never see the work, but you can trust the result because it was made hard to fake. Here are four plain reasons it matters.","open-source-knot.3daed3e8e1":"behind a fair record","open-source-knot.b0b9c6048d":"A quiet helper","open-source-knot.dba1a2e1e0":"Why it is good for you","open-source-knot.0f7f1377f4":"Just the idea","open-source-knot.1a03bcb291":"No jargon","open-source-knot.6af74613cf":"Within the boundary the team chooses","open-source-knot.3f66052a10":"Data boundary","open-source-knot.35ca1675a9":"Every action and result stays in order","open-source-knot.64ae43e8fe":"Sequence","open-source-knot.3a21d9aab2":"Nothing to install or manage","open-source-knot.a90ea728b1":"Keeps a record nobody can quietly change","open-source-knot.b017742a89":"It does","open-source-knot.c43534cee1":"A careful, honest record keeper","open-source-knot.3dd5d5b49f":"It is","open-source-knot.c943a1db59":"If you only read one thing","open-source-knot.cc835fe349":"The short answer","open-source-knot.93844fe5e2":"FOR EVERYONE","open-source-knot.4a9768fab0":"ORDERED","open-source-knot.1c34a90a63":"SIMPLE","open-source-knot.2a528729b5":"You will never use this yourself. But it is a small, careful thing that helps keep an honest record of what computer helpers do in your name. Here is the whole idea, one simple step at a time, with an everyday example for each one.","open-source-knot.f572c73bb9":"and why it matters","open-source-knot.66e1586456":"What is this,","open-source-knot.704869f20f":"In plain words","open-source-knot.27c92bbf5d":"Not hosted","open-source-knot.7a4d28eef6":"Verifiable","open-source-knot.2747d467ee":"Offline, no vendor cooperation","open-source-knot.18c80af5a2":"Edit one event, the root breaks","open-source-knot.1c58a8e1f4":"Merkle","open-source-knot.48a0110478":"Every event, signed","open-source-knot.6e3665d85f":"Signed","open-source-knot.4b719e5c03":"Ledger on local disk, not a vendor db","open-source-knot.b62ff5ccd1":"Owned","open-source-knot.c4530812c6":"Why offline verifiability wins","open-source-knot.f094ebbcd0":"The differentiator","open-source-knot.05b8cb72cf":"PROXY","open-source-knot.bd1c5451b4":"EVAL SERVICE","open-source-knot.42c0c0c950":"TRACE VIEWER","open-source-knot.cc8c81b9fd":"A hosted trace viewer records what a run did. An evaluation service keeps results in the infrastructure that produced them. An observability proxy sits beside the traffic. A database audit log is a row in a table somebody can still update. None of them signs an event, produces a Merkle root, or supports offline verification. Knot is write-optimised for verifiability: the design centre is the signed event, not the dashboard.","open-source-knot.1f98d2516a":"are trace platforms, not databases","open-source-knot.6c06dbbc84":"The closest analogues","open-source-knot.798da8f672":"How the record travels","open-source-knot.9babbe6fed":"Signed agent audit trails","open-source-knot.6b5eb5323e":"Signed agent audit trails","open-source-knot.c66d8490f1":"LLM, tool, file, branch","open-source-knot.54398265bf":"Event variants","open-source-knot.980ba41982":"Materialized read views","open-source-knot.c7bdffcad9":"Projections","open-source-knot.524451e5db":"Single event, p99","open-source-knot.a3c6629c10":"Signed entry","open-source-knot.cfe50d0a2e":"~28 us","open-source-knot.dba7c22f93":"Parse, redact, sign, store","open-source-knot.f0025e2917":"p99 commit_event","open-source-knot.d7564f39d8":"~3.8 ms","open-source-knot.58c76110f0":"By the numbers","open-source-knot.669f62b85d":"JSON output","open-source-knot.7e55188068":"Spec-compliant","open-source-knot.3134af8920":"2 usage to 7 integrity","open-source-knot.47b9175f29":"Exit codes","open-source-knot.d599472e2e":"Bearer token, constant-time","open-source-knot.35d0f5fbca":"Auth","open-source-knot.5ff57e53cf":"init, commit, status, verify, mcp","open-source-knot.700b401ca5":"CLI","open-source-knot.5836d18ecd":"knot://run, branch, status","open-source-knot.87df60de33":"Resources","open-source-knot.be52b2507c":"commit_event, replay, subscribe","open-source-knot.4fa8cc860c":"Tools","open-source-knot.29d4acef90":"Tools, resources, and verbs","open-source-knot.c0144d7f01":"The surface","open-source-knot.3b8a081c7b":"TYPED EXIT CODES","open-source-knot.f20f09bee5":"BEARER AUTH","open-source-knot.c6c32c30de":"STDIO BRIDGE","open-source-knot.80a8fd462f":"STREAMABLE HTTP","open-source-knot.cda26e878f":"The knotd daemon exposes commit_event, replay, and subscribe tools, plus knot:// resources, over the spec-compliant MCP Streamable HTTP transport, with a stdio bridge for local editor attach. Bearer-token auth uses constant-time comparison. The knot CLI mirrors the same operations with typed exit codes for shell-friendly scripting.","open-source-knot.f9adab1e12":"MCP surface, and a CLI","open-source-knot.8072fddca4":"A spec-compliant","open-source-knot.5d1f472c84":"Endpoint and CLI","open-source-knot.af9526f96c":"Same bytes","open-source-knot.7511195002":"Same events","open-source-knot.86d0cf47ca":"No daemon trust to consume it","open-source-knot.1d10323c27":"Standalone","open-source-knot.b56a1a6a0b":"Prove the state at logical time T","open-source-knot.2f218ca374":"At time T","open-source-knot.842c6549ca":"Signed ReplayAttestation object","open-source-knot.941cc89dfa":"Attest","open-source-knot.30cd7ecc3f":"Any event range, deterministic","open-source-knot.c0f85d6679":"Replay","open-source-knot.e30f0e2ce2":"Verify state at a logical time","open-source-knot.fe7f65186c":"Replay attestation","open-source-knot.3c9e174d9c":"REPLAYABLE","open-source-knot.6757848af7":"DETERMINISTIC","open-source-knot.887331ca43":"HOT REFRESH","open-source-knot.e5b211961e":"MATERIALIZED","open-source-knot.f14f780ab1":"Projections are materialized read views of the log. The ProjectionSet hot-refreshes them on a one-second default interval, with cold refresh on read. Every projection is deterministic: replaying the same events through it must produce the same bytes, which is what makes a replay attestation meaningful.","open-source-knot.e7af710fed":"deterministic by contract","open-source-knot.3439acc89c":"Six read views,","open-source-knot.a6557e91f4":"Never on output","open-source-knot.8dbdec694f":"Masked at ingest","open-source-knot.0a1dd0c39d":"Per-tenant config files","open-source-knot.8421926222":"Override","open-source-knot.73eb98106b":"Unmasked data never written","open-source-knot.9e092dda4f":"Storage","open-source-knot.376670f19e":"Whole-word, no substring trap","open-source-knot.e5651c683f":"Keys","open-source-knot.bf70f90429":"6+ patterns, card uses Luhn","open-source-knot.716aef4dca":"PII","open-source-knot.561c101b8c":"18+ regexes, AWS to Anthropic","open-source-knot.dd097a2297":"Credentials","open-source-knot.d187ef5b78":"Detectors that run on every event","open-source-knot.f9d8d178ad":"What it catches","open-source-knot.39e0ae0995":"AT INGEST","open-source-knot.f224a4f911":"The redaction pipeline walks every event JSON shape before storage and replaces credentials and PII with hash-stable placeholders. Redaction is applied at ingest, never on output, so the daemon never holds the unmasked data in the first place. The key matcher is whole-word, so donation_token does not match token.","open-source-knot.64760f4ee1":"before they are ever stored","open-source-knot.0bc54e6e2f":"Secrets masked","open-source-knot.88d6b28437":"Redaction at ingest","open-source-knot.e01fa717ba":"Offline","open-source-knot.73cd00ca3b":"None required","open-source-knot.53ebc572b4":"Network","open-source-knot.5517c5f84a":"Re-derive and check offline","open-source-knot.d20a14cfa7":"Portable export directory","open-source-knot.23ed731baa":"Bundle","open-source-knot.e55742c72f":"Canonical encoding, language-portable","open-source-knot.8e5fdab92d":"Bytes","open-source-knot.d0cc50808f":"Canonicalize, hash, sign","open-source-knot.a058400e6f":"Produce","open-source-knot.7b3d41cb90":"Producer and verifier never share trust","open-source-knot.5a4933ff77":"The two sides","open-source-knot.393c13f728":"PUBLIC KEY ONLY","open-source-knot.280208592c":"PORTABLE","open-source-knot.521ceae7be":"CANONICAL ENCODING","open-source-knot.c468ab5769":"Every event is signed over its canonical encoding, so the signature is portable across languages and survives a different serialiser. Verification is offline and needs only the public key, which is why a downstream consumer never has to trust the process that produced the record.","open-source-knot.9995c44e5e":"Verify with nothing but a key","open-source-knot.0145af2c21":"Sign on one side","open-source-knot.7df643b07d":"Signing and verification","open-source-knot.f0c7eb3989":"Sign and verify","open-source-knot.33b4a9d6ab":"StateSnapshot, BranchEvent","open-source-knot.a725020675":"State","open-source-knot.597b81f653":"MessageProduced, FileEdited","open-source-knot.00040bab8a":"Work","open-source-knot.73f1e405b5":"ToolCallRequested, ToolCallResponded","open-source-knot.2d83bb73c6":"LlmCallRequested, LlmCallResponded","open-source-knot.370515d5b1":"LLM","open-source-knot.aef9918ec6":"RunStarted, RunCompleted","open-source-knot.033df3d297":"Lifecycle","open-source-knot.84a2d4f055":"What an event can be","open-source-knot.5bd17549f6":"Ten payload variants","open-source-knot.230bde49ee":"MERKLE ROOT","open-source-knot.b9ca304990":"IDEMPOTENT","open-source-knot.f7cf057cd1":"IMMUTABLE","open-source-knot.b2654c5392":"Every state change in the agent lifecycle is captured as an immutable Event, LLM calls, tool calls, messages, file edits, state snapshots, branch moves. Each carries a deterministic BLAKE3 content id, so re-ingesting the same event is a no-op. The leaf hashes feed a per-run Merkle tree, and its single root is what an attestation signs.","open-source-knot.45df9abb3a":"one signed Merkle root","open-source-knot.f639ced438":"Append-only events,","open-source-knot.5cde36958b":"The event model","open-source-knot.4ec6d609ab":"Signed agent audit trails","open-source-knot.4ced359fe6":"Credentials and PII at ingest","open-source-knot.5a9ae81a43":"Redaction","open-source-knot.fe3c7e4af0":"Six materialized read views","open-source-knot.b0a4cf3626":"Per-run tree, O(1) append","open-source-knot.2823beb6f0":"Ten payload variants, BLAKE3 ids","open-source-knot.572fd6bf3a":"Event log","open-source-knot.402f720e47":"Production form, signed and tested","open-source-knot.e8ad793f72":"What ships in v1.0","open-source-knot.127edee78d":"SIGNED","open-source-knot.ddf530cd9f":"Knot is a self-hostable, offline-verifiable event log for AI agent runs. Events pass through redaction into storage, become read views, and are exposed through one authenticated endpoint. Each step has one job, so the path from emitted event to provable bundle is easy to follow and audit.","open-source-knot.39df8d4da3":"one responsibility each","open-source-knot.4323c13936":"Six layers,","open-source-knot.7a34aeb61f":"What Knot is","open-source-knot.21ecb524ed":"The verifier is a separate binary. It trusts nothing it cannot recompute from the raw events.","open-source-knot.4fa5c3778f":"VERDICT: VERIFIED, ledger is authentic and unaltered","open-source-knot.64d65fc7fe":"trust-log hash chain: intact","open-source-knot.8f5a0af3f3":"signatures verified: 1284 / 1284","open-source-knot.1f039eb1ab":"merkle roots re-derived: 3 / 3 match","open-source-knot.a91b77addd":"events: 1284  runs: 3  branches: 2","open-source-knot.331af8e6af":"verify an exported run bundle against a public key","open-source-knot.66cfa22b7d":"knot: offline ledger verification","open-source-knot.7f6e5a6efa":"Verdict","open-source-knot.fcdb30b6b9":"No vendor","open-source-knot.611898d7a7":"None, fully offline","open-source-knot.a04ad2ab7f":"Emits a JSON VerificationReport","open-source-knot.ee45c30326":"Report","open-source-knot.796892572c":"Checks the hash-chain and manifest","open-source-knot.752d737b0e":"Trust log","open-source-knot.aae794d12a":"Verifies every signature","open-source-knot.e4cf039229":"Signatures","open-source-knot.06a2eb9a9e":"Re-derives every per-run root","open-source-knot.c0e9018353":"Bundle plus public key, nothing else","open-source-knot.2b55082dc4":"What the verifier checks","open-source-knot.32da296982":"NO DAEMON","open-source-knot.d4fa1d473e":"MERKLE","open-source-knot.c689932b7d":"OFFLINE","open-source-knot.2f6950eb8d":"The whole promise is offline verifiability. Export a run to a portable bundle, hand it and a public key to a third party, and they re-derive every Merkle root from the raw events, check every signature, and reach a verdict. No service, no network and no trust in the producer. This is the verifier output.","open-source-knot.187de5d05f":"They verify it on a laptop","open-source-knot.9b7d2dbb86":"Hand someone a bundle","open-source-knot.90c2e4c6d3":"The artifact","open-source-knot.d627cfd39c":"Offline, no service to trust","open-source-knot.03128bed90":"Verification","open-source-knot.e2ecd770a0":"Agent trace, data record, pipeline inventory","open-source-knot.68f0ae4911":"Controls","open-source-knot.76b4d9f30d":"On premise, EU region, your hardware","open-source-knot.f7dd5c66e9":"The short version","open-source-knot.26132206bd":"The controls short version","open-source-knot.97abebdb00":"Knot keeps a signed, time-ordered record of what your AI agents do. It shows the steps, data references and pipeline components present in a run, and a third party can verify the whole history offline without trusting a hosted service. Use the resulting record alongside the legal, policy and operational controls that apply to your organisation.","open-source-knot.1d3cdb40ba":"verify it offline","open-source-knot.9059c4100b":"rebuild the run and","open-source-knot.da02b57c20":"Record every agent step","open-source-knot.bf49e9e7f8":"Knot","open-source-knot.21a1667b08":"Where does it stay","open-source-knot.7a3ea32828":"Yes, from the sealed record","open-source-knot.85083f1a43":"Can someone check it","open-source-knot.0513f036c7":"My private details","open-source-knot.2183315ae3":"Do I manage it","open-source-knot.eb1b344997":"No, it works in the background","open-source-knot.f4e4e83e14":"Does it interrupt me","open-source-knot.0360ed1ef7":"Teams that run computer helpers","open-source-knot.54f8de57f6":"Who uses it","open-source-knot.23c092228e":"Keeps an honest record of what an AI did","open-source-knot.ca032b5844":"A record that stays honest","open-source-knot.7ccd8cfc31":"For everyone","open-source-knot.afae86e6ff":"See the simple story","open-source-knot.8869fce870":"When a computer helper does things for you, somebody should be able to look back later and see exactly what it did, in order, with nothing quietly changed. Knot writes down each step, locks the steps together, seals them, and lets a second person check the whole record without having to trust the first.","open-source-knot.ce08f27dc3":"on your behalf","open-source-knot.647a4df5fa":" an AI did","open-source-knot.9d73150c40":"A tamper-proof diary of what","open-source-knot.616bb02520":"Separate offline binary, public key only","open-source-knot.e0264861a9":"Verifier","open-source-knot.e0949bb31f":"Per-run Merkle root, BLAKE3 leaves","open-source-knot.479d39e8c9":"Signature over canonical encoding","open-source-knot.1ebd45fcbe":"Signing","open-source-knot.b71eec88ba":"Authenticated endpoint and CLI","open-source-knot.7b4db7ef1f":"Interface","open-source-knot.e9921e9ad2":"Rust (edition 2021)","open-source-knot.89b86ab0e6":"Language","open-source-knot.942587e61e":"Project sheet","open-source-knot.d4a74b503a":"Read the docs","open-source-knot.904c95f470":"Knot is a signed, content-addressed event log for AI agent runs. Every entry carries its own identity, every run keeps its own Merkle root, and a third party can verify the history on a laptop with the public key. The event log, redaction, read views, replay statement, offline checker and endpoint travel together as one record system.","open-source-knot.2587ba16fa":"you can prove offline","open-source-knot.6836a180e3":" for AI agent state","open-source-knot.5ba9e91c47":"A verifiable, replayable ledger","oss-knot-audience-boards.01f82a9f31":"Capture begins","oss-knot-audience-boards.02ea9d7106":"The event is written while the agent acts","oss-knot-audience-boards.03d53ae387":"Sensitive data masked","oss-knot-audience-boards.04a3de24ef":"Secrets are replaced before storage","oss-knot-audience-boards.059353106e":"Run sealed","oss-knot-audience-boards.064c3e2a41":"The Merkle root is signed","oss-knot-audience-boards.0730ae3a16":"Bundle delivered","oss-knot-audience-boards.08621631f4":"An auditor verifies it offline","oss-knot-audience-boards.09b664ab90":"Request accepted","oss-knot-audience-boards.10a8db124e":"Prompt and identity linked","oss-knot-audience-boards.1142aac094":"Tool invoked","oss-knot-audience-boards.12e22e702a":"Tool and result paired","oss-knot-audience-boards.13e0d1a025":"File changed","oss-knot-audience-boards.1493c33e9e":"Exact before and after preserved","oss-knot-audience-boards.15e5041b22":"The helper looks something up","oss-knot-audience-boards.16b71dfe29":"Request and result are noted","oss-knot-audience-boards.1701f7d790":"The helper writes a reply","oss-knot-audience-boards.1898d03d5e":"The words stay tied to the moment","oss-knot-audience-boards.1970ad8d1a":"The work is saved","oss-knot-audience-boards.20cb2048a7":"Destination and change are recorded","oss-knot-audience-boards.21209489df":"The receipt is sealed","oss-knot-audience-boards.22f5f0e9ec":"Later edits become visible","oss-knot-audience-boards.23d8992b82":"Evidence made during the work","oss-knot-audience-boards.24a57bd178":"Every hand-off keeps its provenance","oss-knot-audience-boards.25c69d49be":"One chain from action to auditor","oss-knot-audience-boards.26e96c0ca3":"Ready when scrutiny starts","oss-knot-audience-boards.2759f615ab":"The exact run","oss-knot-audience-boards.284302d348":"Verified timeline","oss-knot-audience-boards.29ed13bb04":"Evidence packet","oss-knot-audience-boards.30c1661398":"Run","oss-knot-audience-boards.316283f530":"Root","oss-knot-audience-boards.3268680531":"Signature","oss-knot-audience-boards.33e5c9b634":"Status","oss-knot-audience-boards.34bc0a1685":"Verified","oss-knot-audience-boards.35c3772614":"Timeline authentic and complete","oss-knot-audience-boards.36b4e59f13":"Answer from the original run","oss-knot-audience-boards.37d90433fc":"No reconstruction","oss-knot-audience-boards.38d0142615":"The helper's receipt","oss-knot-audience-boards.39b972f69f":"Sealed","oss-knot-audience-boards.40a14f964e":"Nothing quietly changed","oss-knot-audience-boards.416d62b9bf":"A second person can check every step","oss-knot-audience-boards.42c3bd936c":"Checked from the receipt","oss-knot-audience-boards.43f8a18475":"A simple record of what happened, in order","oss-knot-audience-boards.4438778819":"Something is questioned","oss-knot-audience-boards.457c165a96":"Open the record","oss-knot-audience-boards.46c971158b":"Memory","oss-knot-audience-boards.47f94f4e6e":"I think this is what happened","oss-knot-audience-boards.48a3dbb221":"People remember differently, and important details disappear","oss-knot-audience-boards.49bba58237":"Sealed record","oss-knot-audience-boards.50a23521dd":"Here is the exact sequence","oss-knot-audience-boards.51fbb5ea27":"Each action, result and change remains in order","oss-knot-audience-boards.525b9e52d9":"In order","oss-knot-audience-boards.53aaeb968c":"No missing steps","oss-knot-audience-boards.545646020f":"Private","oss-knot-audience-boards.55f8da6c23":"Sensitive details hidden","oss-knot-audience-boards.5665f23c20":"Checkable","oss-knot-audience-boards.57073947fd":"Another person can verify","oss-knot-audience-boards.586cb3d71e":"Less arguing, faster answers","oss-knot-audience-boards.59c9e5a63a":"The record speaks","oss-knot-audience-boards.signedEntry":"SIGNED ENTRY","oss-knot-bundle-index.eyebrow":"A directory you can open","oss-knot-bundle-index.lead":"The evidence is a folder","oss-knot-bundle-index.accent":"and anybody can read it","oss-knot-bundle-index.body":"A Knot export is not an opaque archive or a dashboard somebody has to keep online. The manifest, run index, event files, read trail and signature travel together, so a reviewer can inspect the shape before running the checker.","oss-knot-bundle-index.pillDirectory":"A DIRECTORY","oss-knot-bundle-index.pillManifest":"ONE MANIFEST","oss-knot-bundle-index.pillPortable":"PORTABLE","oss-knot-bundle-index.signedPerEntry":"SIGNED PER ENTRY","oss-knot-bundle-index.sideKicker":"The bundle","oss-knot-bundle-index.sideSub":"named files, one verdict","oss-knot-bundle-index.sideManifest":"Manifest","oss-knot-bundle-index.sideManifestValue":"declares the format","oss-knot-bundle-index.sideEvents":"Events","oss-knot-bundle-index.sideEventsValue":"one file per content hash","oss-knot-bundle-index.sideTrail":"Read trail","oss-knot-bundle-index.sideTrailValue":"line-by-line integrity","oss-knot-bundle-index.sideSignature":"Signature","oss-knot-bundle-index.sideSignatureValue":"covers the manifest","oss-knot-bundle-index.sideFootLeft":"open without a service","oss-knot-bundle-index.sideFootRight":"checker is separate","oss-knot-bundle-index.caption":"Evidence bundle","oss-knot-bundle-index.captionMeta":"example layout","oss-knot-bundle-index.folderName":"knot-export/","oss-knot-bundle-index.folderBadge":"READABLE","oss-knot-bundle-index.manifestCopy":"format, version and run roots","oss-knot-bundle-index.indexCopy":"one place to find each run","oss-knot-bundle-index.eventCopy":"the entry named by its own hash","oss-knot-bundle-index.trailCopy":"the ordered read history","oss-knot-bundle-index.signatureCopy":"the public check over the manifest","oss-knot-bundle-index.exportsLabel":"same history, four shapes","oss-knot-bundle-index.exportDirectory":"directory","oss-knot-bundle-index.exportArchive":"archive","oss-knot-bundle-index.exportJsonl":"ndjson","oss-knot-bundle-index.exportParquet":"parquet","oss-knot-bundle-index.footer":"The recipient gets the record, not access to your system.","oss-knot-business-glyph.21d8bb4173":"Verify offline. No service to trust.","oss-knot-business-glyph.18ecbd2658":"On premise or EU region. Your keys.","oss-knot-business-glyph.f62199313e":"Ready evidence","oss-knot-business-glyph.17a86caa5b":"Obligation","oss-knot-business-glyph.6b5eb5323e":"Signed agent audit trails","oss-knot-business-glyph.46cbb019ae":"Audit trail you own","oss-knot-business-glyph.327bdc843a":"Portable bundle and public key","oss-knot-business-glyph.bf5dde2d06":"Evidence package","oss-knot-business-glyph.a148b36c17":"Offline, no service required","oss-knot-business-glyph.fdb4974dbe":"Verification","oss-knot-business-glyph.3229609e15":"Signed agent audit trails","oss-knot-business-glyph.b53e5ed6d0":"A record you can stand behind","oss-knot-business-glyph.0db809cc66":"Assurance","oss-knot-business-glyph.35fd6b4860":"A bill of materials for the pipeline","oss-knot-business-glyph.0679ce9143":"AI SBOM","oss-knot-business-glyph.0534e1100c":"Evidence of data touched, PII masked","oss-knot-business-glyph.a5b7d57a85":"GDPR","oss-knot-business-glyph.f73e4db760":"Provable trace of automated decisions","oss-knot-business-glyph.d75a4de2ef":"EU AI Act","oss-knot-compliance-ledger.cbd23a9689":"One record, read by your auditor, your customer, and a regulator alike.","oss-knot-compliance-ledger.1cd1c104cf":"Knot provides","oss-knot-compliance-ledger.bc5af23f32":"You must show","oss-knot-compliance-ledger.e330e94c2b":"What you must show, and what Knot hands you.","oss-knot-compliance-ledger.db2f6f8aca":"From the rule to the evidence","oss-knot-compliance-ledger.691ffe3d66":"Every model call, tool call, and file edit is on the ledger.","oss-knot-compliance-ledger.8735fb6b86":"A bill of materials for what the AI actually did.","oss-knot-compliance-ledger.f2169e4af9":"AI pipeline SBOM","oss-knot-compliance-ledger.648b03a6d4":"A third party verifies the whole history offline on a laptop.","oss-knot-compliance-ledger.161f52fecd":"A record an outsider can check, not just trust.","oss-knot-compliance-ledger.62da56891e":"Audit and assurance","oss-knot-compliance-ledger.3c560b37a3":"Personal data is masked at ingest, the trail stays intact.","oss-knot-compliance-ledger.5585e4213e":"Evidence of what data was touched and when.","oss-knot-compliance-ledger.a5b7d57a85":"GDPR","oss-knot-compliance-ledger.539e794faa":"A signed, time-ordered record of every step the agent took.","oss-knot-compliance-ledger.845d0dbb0b":"Provable traceability of automated decisions.","oss-knot-compliance-ledger.d75a4de2ef":"EU AI Act","oss-knot-consumer-glyph.c0fdd1dbde":"Looked something up for you","oss-knot-consumer-glyph.c164d1683e":"Wrote a short reply","oss-knot-consumer-glyph.8ef9e05b40":"Saved it where it belongs","oss-knot-consumer-glyph.84b04fa1f2":"What the helper did","oss-knot-consumer-glyph.05316b1967":"Sealed, so nothing changes","oss-knot-consumer-glyph.e8f23454a0":"Checked, all fair","oss-knot-consumer-glyph.bf1698049b":"A second person can look, and trust it","oss-knot-event-diagram.6b745f8459":"Each event carries a deterministic BLAKE3 id, so re-ingesting the same event is a no-op. Edit one\n        event and its leaf changes, the root changes, and the offline verifier reports a broken chain.","oss-knot-event-diagram.f86b32154c":"O(1) append","oss-knot-event-diagram.cbb24e869d":"root b3:c10e, sig:5a9f","oss-knot-event-diagram.3b3d592e9b":"Signed root","oss-knot-event-diagram.849c9d59b7":"Four events, one signed root","oss-knot-event-diagram.49da1d58cf":"A signed event chain","oss-knot-event-diagram.f2ecd4bf6c":"File changed","oss-knot-event-diagram.a69e8c4e8d":"Result received","oss-knot-event-diagram.d603add925":"Action requested","oss-knot-event-diagram.a1ce2113d3":"Run begins","oss-knot-handbook.hero-technical.eyebrow":"An agent audit log you can hand to a stranger","oss-knot-handbook.hero-technical.titleLead":"Knot. An agent audit log","oss-knot-handbook.hero-technical.titleAccent":"you can hand to a stranger","oss-knot-handbook.hero-technical.lede":"Knot is source-available software for AI agent audit logs: a signed, content-addressed event log for agent runs. Every step is a typed entry, signed where it is written, and each run carries its own Merkle root. A separate checker verifies the resulting folder offline, without a service, network or database.","oss-knot-handbook.hero-technical.action":"What is actually written down","oss-knot-handbook.hero-technical.sourceAction":"Ask about the release","oss-knot-handbook.hero-technical.ledgerLabel":"Knot","oss-knot-handbook.hero-technical.ledgerPill":"EVIDENCE","oss-knot-handbook.hero-technical.row1Label":"Entries","oss-knot-handbook.hero-technical.row1Value":"typed and signed","oss-knot-handbook.hero-technical.row2Label":"Runs","oss-knot-handbook.hero-technical.row2Value":"their own roots","oss-knot-handbook.hero-technical.row3Label":"Secrets","oss-knot-handbook.hero-technical.row3Value":"removed before the write","oss-knot-handbook.hero-technical.row4Label":"Check","oss-knot-handbook.hero-technical.row4Value":"a folder and public key","oss-knot-handbook.hero-business.eyebrow":"An agent audit log you can hand to a stranger","oss-knot-handbook.hero-business.titleLead":"Knot. An audit trail","oss-knot-handbook.hero-business.titleAccent":"you can hand to a stranger","oss-knot-handbook.hero-business.lede":"Knot is source-available software for AI agent audit trails. When a counterparty, auditor or regulator asks what your automated software did, hand them a signed, tamper-evident record. They can verify it offline with a public key, without access to your systems or a live service. The repository and its documentation go public on 1 September 2026, in the first round of Dweve's foundation release programme.","oss-knot-handbook.hero-business.action":"Where the record lives today","oss-knot-handbook.hero-business.sourceAction":"Ask about the release","oss-knot-handbook.hero-business.ledgerLabel":"Knot","oss-knot-handbook.hero-business.ledgerPill":"OWNED","oss-knot-handbook.hero-business.row1Label":"Hardware","oss-knot-handbook.hero-business.row1Value":"the operator controls it","oss-knot-handbook.hero-business.row2Label":"Key","oss-knot-handbook.hero-business.row2Value":"the operator signs","oss-knot-handbook.hero-business.row3Label":"Record","oss-knot-handbook.hero-business.row3Value":"a folder leaves deliberately","oss-knot-handbook.hero-business.row4Label":"Verdict","oss-knot-handbook.hero-business.row4Value":"the recipient reaches it alone","oss-knot-handbook.hero-consumer.eyebrow":"In plain words","oss-knot-handbook.hero-consumer.titleLead":"Knot. A receipt for agent work","oss-knot-handbook.hero-consumer.titleAccent":"you can hand to a stranger","oss-knot-handbook.hero-consumer.lede":"Knot is source-available software that writes a signed, tamper-evident receipt of what an AI agent did while it worked. Anyone holding the record and a public key can check that its contents were not altered. From 1 September 2026 the checker is something you download and run, not something you ask for.","oss-knot-handbook.hero-consumer.action":"Something acted for you","oss-knot-handbook.hero-consumer.sourceAction":"Ask about the release","oss-knot-handbook.hero-consumer.ledgerLabel":"The receipt","oss-knot-handbook.hero-consumer.ledgerPill":"PLAIN","oss-knot-handbook.hero-consumer.row1Label":"What happened","oss-knot-handbook.hero-consumer.row1Value":"written while it happens","oss-knot-handbook.hero-consumer.row2Label":"Private details","oss-knot-handbook.hero-consumer.row2Value":"taken out first","oss-knot-handbook.hero-consumer.row3Label":"Changes","oss-knot-handbook.hero-consumer.row3Value":"show up","oss-knot-handbook.hero-consumer.row4Label":"Checking","oss-knot-handbook.hero-consumer.row4Value":"needs no connection","oss-knot-handbook.close.headline":"One folder a stranger can check","oss-knot-handbook.close.body":"Knot is source-available software for teams running agents that do consequential work: reconciling invoices, editing customer records, moving money, filing documents and answering on the organisation's behalf. Publication is planned for 1 September 2026, the first round of Dweve's foundation release programme, and the repository and its documentation go live together.","oss-knot-handbook.close.sourceAction":"Ask about the release","oss-knot-handbook.eng-kinds.eyebrow":"The closed set","oss-knot-handbook.eng-kinds.lead":"The agent did the work","oss-knot-handbook.eng-kinds.accent":"and left no record of it","oss-knot-handbook.eng-kinds.body":"What an agent run leaves behind is usually output: whatever the framework chose to print, at whatever level somebody set last quarter. You can read it. You cannot ask it which tool ran, in what order, against which model reply, because none of those was ever a separate thing.","oss-knot-handbook.eng-kinds.detailLabel":"The mechanism","oss-knot-handbook.eng-kinds.detail":"Knot records ten kinds of event, each carrying a stable name on the wire. A tool call requested is one kind and the answer to it is another.","oss-knot-handbook.eng-kinds.pills":"RUN, MODEL, TOOL|FILE, STATE|CLOSED SET","oss-knot-handbook.eng-kinds.footer":"Ten kinds, one shape for every run. What each entry is called comes next.","oss-knot-handbook.eng-identity.eyebrow":"Identity","oss-knot-handbook.eng-identity.lead":"Send the same thing twice","oss-knot-handbook.eng-identity.accent":"and it is one entry, not two","oss-knot-handbook.eng-identity.body":"Agent runs retry. A tool times out and the call goes again, a process restarts mid flush, a queue delivers twice because that is what queues do. Where the identifier is handed out on arrival, each of those becomes another entry.","oss-knot-handbook.eng-identity.detailLabel":"Why it matters","oss-knot-handbook.eng-identity.detail":"A Knot entry is named by the hash of its own content, so identity belongs to what was recorded rather than to when it turned up.","oss-knot-handbook.eng-identity.pills":"SAME BYTES|SAME NAME|RETRY SAFE","oss-knot-handbook.eng-identity.footer":"A name out of the content is one half. The signature over it is the other.","oss-knot-handbook.eng-signature.eyebrow":"What the signature covers","oss-knot-handbook.eng-signature.lead":"A signature over itself","oss-knot-handbook.eng-signature.accent":"checked with a key alone","oss-knot-handbook.eng-signature.body":"Transport security proves a message reached you unaltered from whoever held the other end of the connection. That is a statement about a conversation, and the conversation ended in March. An hour later it says nothing about the bytes on the disk.","oss-knot-handbook.eng-signature.detailLabel":"The guarantee","oss-knot-handbook.eng-signature.detail":"Knot signs every entry over the canonical encoding of the entry itself. Checking wants the public key and nothing else.","oss-knot-handbook.eng-signature.pills":"SIGNED PER ENTRY|PUBLIC KEY ONLY|NO SERVICE","oss-knot-handbook.eng-signature.footer":"One entry holds up on its own. What an auditor asks is whether the run is all there.","oss-knot-handbook.eng-root.eyebrow":"Completeness","oss-knot-handbook.eng-root.lead":"Each run keeps its own root","oss-knot-handbook.eng-root.accent":"so one run can be checked","oss-knot-handbook.eng-root.body":"A signature proves an entry is as it was written. It says nothing about an entry that was taken out, because a deleted line leaves no evidence of itself. A log with a hole in it verifies perfectly, entry by entry, and lies by omission.","oss-knot-handbook.eng-root.detailLabel":"Under the surface","oss-knot-handbook.eng-root.detail":"Each Knot run accumulates a Merkle root over its own entries. A single run travels on its own and is complete when it lands.","oss-knot-handbook.eng-root.pills":"ONE ROOT PER RUN|EXTENDED|NOT REBUILT","oss-knot-handbook.eng-root.footer":"Completeness is settled by arithmetic, and the verdict belongs to whoever received it.","oss-knot-handbook.eng-enquiry.eyebrow":"What a verdict needs","oss-knot-handbook.eng-enquiry.lead":"Asking is not checking.","oss-knot-handbook.eng-enquiry.accent":"So nobody is asked.","oss-knot-handbook.eng-enquiry.body":"Most audit tooling answers a question about an agent by asking the system that produced the records. The response still comes from the party being asked about, and the recipient has only read it. A longer report or better query does not fix that. A verdict becomes independent only when everything it needs travels inside the thing being handed over.","oss-knot-handbook.eng-enquiry.detailLabel":"The distinction","oss-knot-handbook.eng-enquiry.detail":"Writing needs the private half of a key and a machine the operator controls. Checking needs the folder and the published half, which cannot write a new entry or alter one. The recipient can reach a verdict the sender cannot influence, while neither side needs a service, a session or the cooperation of the other.","oss-knot-handbook.eng-enquiry.pills":"THE RECORD|THE PUBLIC KEY|A SEPARATE CHECKER","oss-knot-handbook.eng-enquiry.verdict":"a verdict you cannot influence, and one they cannot manufacture","oss-knot-handbook.eng-enquiry.footer":"and the same standard holds for the log of who has been reading it","oss-knot-handbook.eng-trail.eyebrow":"Who read what","oss-knot-handbook.eng-trail.lead":"A chain that reports where","oss-knot-handbook.eng-trail.accent":"it stopped being intact","oss-knot-handbook.eng-trail.body":"A record of what an agent did invites a second question almost at once, which is who has been reading it. That log is evidence only if editing it shows.","oss-knot-handbook.eng-trail.detailLabel":"How it holds","oss-knot-handbook.eng-trail.detail":"Each line is hashed together with its own position, its timestamp, its message and the hash of the line before it. The report names the first line where the chain stopped holding.","oss-knot-handbook.eng-trail.pills":"LINE BY LINE|NAMES THE BREAK|ORDERED","oss-knot-handbook.eng-trail.footer":"The record and the log of who read it leave together, and neither one is a database.","oss-knot-handbook.eng-bundle.eyebrow":"What gets handed over","oss-knot-handbook.eng-bundle.lead":"The evidence is a folder","oss-knot-handbook.eng-bundle.accent":"and anybody can open it","oss-knot-handbook.eng-bundle.body":"An audit format that only its own tooling can open leaves the recipient dependent on the sender twice, once for the data and once for the means to read it. A bundle avoids that by being an ordinary directory, listed and opened with the tools a recipient already has.","oss-knot-handbook.eng-bundle.detailLabel":"In practice","oss-knot-handbook.eng-bundle.detail":"What leaves Knot is a directory: a manifest, indexes, one file per entry, the read trail and a single signature over the whole thing.","oss-knot-handbook.eng-bundle.pills":"A DIRECTORY|ONE FILE EACH|ONE SIGNATURE","oss-knot-handbook.eng-bundle.footer":"Which means everything the agent was shown is in that folder, and some of it should not be.","oss-knot-handbook.eng-handoff.eyebrow":"The handover test","oss-knot-handbook.eng-handoff.lead":"The writer can stop.","oss-knot-handbook.eng-handoff.accent":"The check still runs.","oss-knot-handbook.eng-handoff.body":"A transferable record has to survive the service that produced it. Once the folder leaves the operator, the recipient should not need an account, a network route or a live database to decide whether the run is complete and unchanged.","oss-knot-handbook.eng-handoff.detailLabel":"Inside the folder","oss-knot-handbook.eng-handoff.detail":"The manifest fixes the run roots, the entry files carry their own signed content and the public key lets a separate checker test both. Those pieces travel together, so the verdict belongs to the recipient rather than to the system under review.","oss-knot-handbook.eng-handoff.pills":"MANIFEST AND ROOTS|SIGNED ENTRY FILES|PUBLIC KEY AND CHECKER","oss-knot-handbook.eng-handoff.verdict":"a complete handover that still checks after the service is gone","oss-knot-handbook.eng-handoff.footer":"The next risk is not whether the folder opens, but what sensitive material was allowed into it.","oss-knot-handbook.eng-redact.eyebrow":"Before the write","oss-knot-handbook.eng-redact.lead":"The secret never reaches","oss-knot-handbook.eng-redact.accent":"the file it would sit in","oss-knot-handbook.eng-redact.body":"A trace of an agent run concentrates whatever that agent saw. Filter it on the way out and the value is still on the disk, still in the overnight copy, and still in the bundle you hand somebody.","oss-knot-handbook.eng-redact.detailLabel":"The order it runs in","oss-knot-handbook.eng-redact.detail":"Knot redacts each value before the write, in a fixed order of five passes: named secret fields, credentials, personal data, the tenant's blocklist and the tenant's own rules.","oss-knot-handbook.eng-redact.pills":"BEFORE THE WRITE|MARKED|REPORTED","oss-knot-handbook.eng-redact.footer":"Credentials have shapes. A person's details mostly do not, which is the harder half.","oss-knot-handbook.eng-validate.eyebrow":"Personal data, decided rather than matched","oss-knot-handbook.eng-validate.lead":"A number that validates","oss-knot-handbook.eng-validate.accent":"is not always personal","oss-knot-handbook.eng-validate.body":"Over redact and you have quietly damaged the record you built to be trustworthy. Under redact and somebody's details are now in an audit trail designed to be handed to strangers. Both failures are silent.","oss-knot-handbook.eng-validate.detailLabel":"The hard case","oss-knot-handbook.eng-validate.detail":"Knot validates rather than matching alone: card numbers have to satisfy their checksum, and national identifiers fire only where the surrounding words support the reading.","oss-knot-handbook.eng-validate.pills":"VALIDATED|IN CONTEXT|WHOLE WORD","oss-knot-handbook.eng-validate.footer":"That is care on the way in. Now edit one word of what came out and see what happens.","oss-knot-handbook.eng-onebyte.eyebrow":"Tamper evidence, shown","oss-knot-handbook.eng-onebyte.lead":"Change one byte.","oss-knot-handbook.eng-onebyte.accent":"Then hand it to somebody.","oss-knot-handbook.eng-onebyte.body":"Change `approve` to `reject` in one recorded model reply and the folder still opens normally. The altered entry still parses, the directory still lists and a reader may not spot the one changed word. That is the useful case: a change small enough to look harmless in an otherwise ordinary record.","oss-knot-handbook.eng-onebyte.detailLabel":"The report","oss-knot-handbook.eng-onebyte.detail":"Three checks now disagree with that file: its signature no longer matches, its content no longer matches its filename and the recomputed run root differs from the manifest. The checker names the entry and run while the other entries still pass. It locates one altered fact instead of calling a two-year history wholly suspect.","oss-knot-handbook.eng-onebyte.pills":"SIGNATURE|RUN ROOT|READ TRAIL","oss-knot-handbook.eng-onebyte.verdict":"detected and located, to the entry and to the run it belongs to","oss-knot-handbook.eng-onebyte.footer":"and everything built on top of these entries is derived from them, never beside them","oss-knot-handbook.eng-views.eyebrow":"Reading it back","oss-knot-handbook.eng-views.lead":"Every read view is derived","oss-knot-handbook.eng-views.accent":"and can be derived again","oss-knot-handbook.eng-views.body":"The moment a log acquires a summary table beside it there are two sources of truth, and the interesting question becomes which of them is wrong. Dashboards drift from the events they were built on.","oss-knot-handbook.eng-views.detailLabel":"What that rules out","oss-knot-handbook.eng-views.detail":"A Knot view is a function of the log and nothing else. Any of them can be deleted and rebuilt from the entries.","oss-knot-handbook.eng-views.pills":"SAME EVENTS|SAME VIEW|REBUILT","oss-knot-handbook.eng-views.footer":"A view says what is true now. An auditor asks what was true at twenty past two.","oss-knot-handbook.eng-replay.eyebrow":"Replay and re-execution","oss-knot-handbook.eng-replay.lead":"Run it again and compare","oss-knot-handbook.eng-replay.accent":"four verdicts, not one","oss-knot-handbook.eng-replay.body":"Replaying an agent run and getting a different answer is ordinary, and useless as a signal, because at least four separate things produce it. One pass or fail collapses all four.","oss-knot-handbook.eng-replay.detailLabel":"What changes","oss-knot-handbook.eng-replay.detail":"A Knot replay returns a signed statement of the state at a chosen point, and re-execution classifies every comparison rather than totalling them.","oss-knot-handbook.eng-replay.pills":"IDENTICAL|DIVERGENT|SUBSET OR SKIPPED","oss-knot-handbook.eng-replay.comparisonIdentical":"IDENTICAL","oss-knot-handbook.eng-replay.comparisonDivergent":"DIVERGENT","oss-knot-handbook.eng-replay.comparisonSubset":"SUBSET","oss-knot-handbook.eng-replay.comparisonSkipped":"SKIPPED","oss-knot-handbook.eng-replay.footer":"Reading it back is one half. Reaching the record at all is a door with four keys.","oss-knot-handbook.eng-surface.eyebrow":"The surface","oss-knot-handbook.eng-surface.lead":"One door on the machine","oss-knot-handbook.eng-surface.accent":"and a reading beside it","oss-knot-handbook.eng-surface.body":"The Knot service is deliberately small. It listens on one endpoint, accepts appends over the Model Context Protocol that an agent framework already speaks, and publishes a status reading.","oss-knot-handbook.eng-surface.detailLabel":"For operators","oss-knot-handbook.eng-surface.detail":"Beside the door sit an unauthenticated liveness path, an authenticated health reading and metrics in the Prometheus text form.","oss-knot-handbook.eng-surface.pills":"ONE ENDPOINT|CREDENTIALED|DRAIN STATE","oss-knot-handbook.eng-surface.footer":"One door keeps one writer busy, and one writer is what gives the log its order.","oss-knot-handbook.eng-order.eyebrow":"Ordering","oss-knot-handbook.eng-order.lead":"One writer, one total order","oss-knot-handbook.eng-order.accent":"settled without coordination","oss-knot-handbook.eng-order.body":"Ordering is where audit logs get expensive. Admit several writers and the sequence has to be agreed: clocks compared, a leader elected, a round trip paid on every append and a tie broken by something arbitrary. A single writer per process removes that negotiation rather than making it faster.","oss-knot-handbook.eng-order.detailLabel":"The design","oss-knot-handbook.eng-order.detail":"Knot writes through one writer per process, so entries acquire a total order at the store without a round trip.","oss-knot-handbook.eng-order.pills":"ONE WRITER|TOTAL ORDER|NO ROUND TRIP","oss-knot-handbook.eng-order.footer":"What Knot leaves behind is one folder a stranger can check without asking you for anything.","oss-knot-handbook.biz-account.eyebrow":"Where the record lives today","oss-knot-handbook.biz-account.lead":"The record of your agents","oss-knot-handbook.biz-account.accent":"sits in a supplier account","oss-knot-handbook.biz-account.body":"When an agent does something consequential, the account of what happened comes from the platform that ran it: held in that platform's storage, exported in that platform's format and kept for as long as that platform's retention setting says.","oss-knot-handbook.biz-account.detailLabel":"Why it matters","oss-knot-handbook.biz-account.detail":"In a dispute you are asking the other side to accept a report you commissioned. Knot moves that question onto your own ground: your hardware, your key, your folder.","oss-knot-handbook.biz-account.pills":"THEIR LOGS|THEIR ACCOUNT|YOUR RISK","oss-knot-handbook.biz-account.footer":"The fix is not a better export. It is something the recipient can check without you.","oss-knot-handbook.biz-handover.eyebrow":"The test that matters","oss-knot-handbook.biz-handover.lead":"You can stop being believed","oss-knot-handbook.biz-handover.accent":"and start being checked","oss-knot-handbook.biz-handover.body":"Hand somebody a Knot record and a public key, and they reach their own verdict. No access to your systems, no request to your supplier, no call with your engineers and nothing that depends on your cooperation once the folder has left.","oss-knot-handbook.biz-handover.detailLabel":"In practice","oss-knot-handbook.biz-handover.detail":"A small program tells them whether each entry is as it was written, whether any entry is missing from a run and whether the log of who read the record has been edited.","oss-knot-handbook.biz-handover.pills":"HAND IT OVER|THEY CHECK IT|NO ACCESS","oss-knot-handbook.biz-handover.footer":"Handing over everything the agent saw raises an objection, and it is the right one.","oss-knot-handbook.biz-redaction.eyebrow":"The objection","oss-knot-handbook.biz-redaction.lead":"The audit trail is where","oss-knot-handbook.biz-redaction.accent":"the secrets end up next","oss-knot-handbook.biz-redaction.body":"A complete record of what your agents did is also a complete record of what they were shown. Built carelessly, the thing you made for assurance becomes the largest concentration of sensitive material you hold.","oss-knot-handbook.biz-redaction.detailLabel":"What falls out of scope","oss-knot-handbook.biz-redaction.detail":"Knot redacts each value before anything is written. The raw value never reaches disk, and each downstream copy carries a signed removal marker.","oss-knot-handbook.biz-redaction.pills":"MINIMISED FIRST|NOT ON EXPORT|EVIDENCED","oss-knot-handbook.biz-redaction.footer":"So it is one record you can safely hold. Most estates are not one estate.","oss-knot-handbook.biz-estate.eyebrow":"A mixed estate","oss-knot-handbook.biz-estate.lead":"Two teams, two toolkits","oss-knot-handbook.biz-estate.accent":"and one history to read","oss-knot-handbook.biz-estate.body":"Most organisations running agents are running more than one framework, because two teams chose separately and both choices were defensible. Each produces its own trace shape, kept for its own period and exported in its own format.","oss-knot-handbook.biz-estate.detailLabel":"What changes","oss-knot-handbook.biz-estate.detail":"Knot sits underneath whichever framework a team picked and records which one produced each entry, and at what version. The history is one thing with one shape, one retention decision and one export.","oss-knot-handbook.biz-estate.pills":"ONE RECORD|ANY FRAMEWORK|ANY MODEL","oss-knot-handbook.biz-estate.footer":"None of which is tested until the day two parties disagree about what happened.","oss-knot-handbook.biz-dispute.eyebrow":"When it is disputed","oss-knot-handbook.biz-dispute.lead":"Two accounts is the problem.","oss-knot-handbook.biz-dispute.accent":"One record is the answer.","oss-knot-handbook.biz-dispute.body":"A dispute about automated software rarely turns on facts that cannot be known. It turns on two accounts assembled after the event by interested parties from sources they control. Reconciling those accounts takes weeks and usually ends in a negotiated version that neither side would defend line by line.","oss-knot-handbook.biz-dispute.detailLabel":"The point","oss-knot-handbook.biz-dispute.detail":"A correction in Knot is added at the end. The original entry remains signed where it was written, so the record accumulates one sequence rather than two reconstructions. Where parties genuinely differ, they can point to an entry in a named run. The dispute becomes a reading of evidence, which is a conversation that can end.","oss-knot-handbook.biz-dispute.pills":"ONE SEQUENCE|ONE ROOT|ONE CHECK","oss-knot-handbook.biz-dispute.verdict":"one record, read rather than reconciled","oss-knot-handbook.biz-dispute.footer":"which leaves the question a reviewer actually asks, about what the system knew before it acted","oss-knot-handbook.biz-state.eyebrow":"The question an auditor asks","oss-knot-handbook.biz-state.lead":"What was true at 14:20","oss-knot-handbook.biz-state.accent":"is a question with an answer","oss-knot-handbook.biz-state.body":"Reviewers rarely ask for a log. They ask what the system believed at the moment it acted: what it had been told, what it had already decided and what it was working from.","oss-knot-handbook.biz-state.detailLabel":"The record","oss-knot-handbook.biz-state.detail":"With Knot the answer is produced rather than composed. A replay up to a chosen point returns a signed statement of the state at that point.","oss-knot-handbook.biz-state.pills":"STATE AT A TIME|SIGNED|HANDED OVER","oss-knot-handbook.biz-state.footer":"Producing that at any point in the history means deciding how much history you keep.","oss-knot-handbook.biz-retention.eyebrow":"Retention","oss-knot-handbook.biz-retention.lead":"Keeping everything forever","oss-knot-handbook.biz-retention.accent":"is a decision, not a default","oss-knot-handbook.biz-retention.body":"An agent estate produces a great deal of history. The usual outcome is either keeping all of it because nobody chose, or losing it at thirty days because somebody chose once and moved on.","oss-knot-handbook.biz-retention.detailLabel":"For operators","oss-knot-handbook.biz-retention.detail":"Retention in Knot is off until you set it, and then it triggers on whichever comes first: an age, a size on disk or a number of entries.","oss-knot-handbook.biz-retention.pills":"YOU SET THE AGE|DATED FILES|STILL CHECKS","oss-knot-handbook.biz-retention.footer":"A file somebody has to keep raises the next question, which is whose disk it is on.","oss-knot-handbook.biz-retention-proof.eyebrow":"A retention decision with evidence","oss-knot-handbook.biz-retention-proof.lead":"A policy names the limit.","oss-knot-handbook.biz-retention-proof.accent":"The archive names what happened.","oss-knot-handbook.biz-retention-proof.body":"A retention schedule is hard to defend when it exists only as a setting. Reviewers need to see which limit applied to a record, when it was reached and what remained available for verification after the live entries moved.","oss-knot-handbook.biz-retention-proof.detailLabel":"The review trail","oss-knot-handbook.biz-retention-proof.detail":"Knot records the configured age, size and entry-count limits. The first limit reached produces a dated archive while the run root remains readable, connecting the policy decision to a named record without keeping the live store indefinitely.","oss-knot-handbook.biz-retention-proof.pills":"LIMIT RECORDED|TRIGGER REACHED|DATED ARCHIVE","oss-knot-handbook.biz-retention-proof.verdict":"the reviewer can connect the rule, the trigger and the retained run","oss-knot-handbook.biz-retention-proof.footer":"Retention answers how long the record stays. Sovereignty answers who controls it during that time.","oss-knot-handbook.biz-sovereignty.eyebrow":"Where it runs","oss-knot-handbook.biz-sovereignty.lead":"Your record sits on disk","oss-knot-handbook.biz-sovereignty.accent":"on hardware you control","oss-knot-handbook.biz-sovereignty.body":"Where the evidence lives is a procurement question before it is a technical one. Knot runs on machines you control, inside your own boundary, and every record is written entirely on your side of it.","oss-knot-handbook.biz-sovereignty.detailLabel":"What it removes","oss-knot-handbook.biz-sovereignty.detail":"Keeping the evidence path inside your own boundary takes a supplier assessment, transfer mechanism, availability dependency and external release schedule out of the assessment entirely.","oss-knot-handbook.biz-sovereignty.pills":"YOUR HARDWARE|YOUR KEY|EU GROUND","oss-knot-handbook.biz-sovereignty.footer":"If the record never leaves, the question is who inside the boundary may read it.","oss-knot-handbook.biz-access.eyebrow":"The reviewer's question","oss-knot-handbook.biz-access.lead":"Who is allowed to open it","oss-knot-handbook.biz-access.accent":"and who has already read it","oss-knot-handbook.biz-access.body":"Take every secret out of the history and it stays sensitive, because the sequence itself shows a reader how your organisation works. A reviewer asks who may open this, and who has opened it.","oss-knot-handbook.biz-access.detailLabel":"What a reviewer can read","oss-knot-handbook.biz-access.detail":"The first answer is configuration. The second answer is in the record: every read appends a line, sealed together with its position, its time and the line before it.","oss-knot-handbook.biz-access.pills":"ACCESS IS SET|READS ARE LOGGED|SEALED","oss-knot-handbook.biz-access.footer":"Every part of that runs on software you will replace, some of it inside the year.","oss-knot-handbook.biz-outlives.eyebrow":"What survives a change","oss-knot-handbook.biz-outlives.lead":"Change the model.","oss-knot-handbook.biz-outlives.accent":"The history still reads.","oss-knot-handbook.biz-outlives.body":"Every part of an agent estate will be replaced. Models change, a framework chosen in spring is questioned in autumn and a platform contract is renegotiated. The duty to account for what the software did in March does not move with any of them, and it cannot wait for the system that produced it to remain available.","oss-knot-handbook.biz-outlives.detailLabel":"The record","oss-knot-handbook.biz-outlives.detail":"A Knot record does not depend on the model, framework, platform or database that made it. The signature covers the entry itself, so a check needs the entries and the published public key, nothing still running. What you keep is a folder checked by a program that was never the program that wrote it.","oss-knot-handbook.biz-outlives.pills":"ENTRIES|SIGNATURE|READ TRAIL","oss-knot-handbook.biz-outlives.verdict":"the tools get replaced, and nothing in the record depends on them","oss-knot-handbook.biz-outlives.footer":"which leaves one question, which is whether the thing writing it is still set up properly","oss-knot-handbook.biz-standup.eyebrow":"Standing it up","oss-knot-handbook.biz-standup.lead":"One command reports what","oss-knot-handbook.biz-standup.accent":"is missing or misconfigured","oss-knot-handbook.biz-standup.body":"Assurance tooling fails in practice for a dull reason. It was installed by somebody who has since moved on, in a configuration nobody wrote down, and eighteen months later nobody can say whether it is working.","oss-knot-handbook.biz-standup.detailLabel":"How it is checked","oss-knot-handbook.biz-standup.detail":"One Knot command inspects the installation and reports whether the signing key, credential file, schema, data directory and log directory are in order.","oss-knot-handbook.biz-standup.pills":"ONE COMMAND|A SEVERITY EACH|REPAIRABLE","oss-knot-handbook.biz-standup.footer":"A clean reading means the record is ready for whatever the estate grows into.","oss-knot-handbook.biz-scale.eyebrow":"Where the record lives","oss-knot-handbook.biz-scale.lead":"One file on one machine","oss-knot-handbook.biz-scale.accent":"or a database when you grow","oss-knot-handbook.biz-scale.body":"An audit trail that only suits the pilot gets replaced at exactly the moment the history becomes worth keeping, and the replacement is where a year of records goes missing.","oss-knot-handbook.biz-scale.detailLabel":"Where it sits as you grow","oss-knot-handbook.biz-scale.detail":"Knot stores the log in a local file database by default, with a server database backend and object storage for blobs available as build options.","oss-knot-handbook.biz-scale.pills":"LOCAL FILE|SERVER DATABASE|OBJECT STORE","oss-knot-handbook.biz-scale.footer":"What you are left with is one folder, on your disk, that a stranger can check without you.","oss-knot-handbook.con-acted.eyebrow":"In plain words","oss-knot-handbook.con-acted.lead":"Something acted for you","oss-knot-handbook.con-acted.accent":"and nobody wrote it down","oss-knot-handbook.con-acted.body":"Software used to show you things and wait. Now it does things: books the appointment, answers the message, moves money between two of your accounts, fills the form in and sends it.","oss-knot-handbook.con-acted.detailLabel":"Why it matters","oss-knot-handbook.con-acted.detail":"You want to know what it actually did, in what order and what it was working from. Knot is a receipt instead, written while the work happens.","oss-knot-handbook.con-acted.pills":"IT ACTED|NO RECEIPT|NO PERSON","oss-knot-handbook.con-acted.footer":"A receipt sounds simple. What has to be on it is the part worth being careful about.","oss-knot-handbook.con-receipt.eyebrow":"What is on it","oss-knot-handbook.con-receipt.lead":"A receipt for the work","oss-knot-handbook.con-receipt.accent":"that a machine did for you","oss-knot-handbook.con-receipt.body":"A shop receipt is not a summary of your visit. It is a list of what happened, in order, with enough detail to settle an argument at the counter. Knot is the same idea for software that acts for you.","oss-knot-handbook.con-receipt.detailLabel":"In practice","oss-knot-handbook.con-receipt.detail":"The order is part of the record rather than something worked out afterwards. Nothing is written over: when something is corrected, the correction is added at the end.","oss-knot-handbook.con-receipt.pills":"WHAT IT ASKED|WHAT CAME BACK|IN ORDER","oss-knot-handbook.con-receipt.footer":"Which raises the obvious question about a receipt written by the thing being asked about.","oss-knot-handbook.con-seal.eyebrow":"Why you can trust it","oss-knot-handbook.con-seal.lead":"Change a line afterwards","oss-knot-handbook.con-seal.accent":"and the change shows up","oss-knot-handbook.con-seal.body":"A receipt written by the software being asked about is worth something only if changing it later is obvious. Otherwise it is a note, and a note can be rewritten by anybody with a reason to rewrite it.","oss-knot-handbook.con-seal.detailLabel":"The mechanism","oss-knot-handbook.con-seal.detail":"Each line carries a seal of its own, and the receipt carries one total over all its lines in the order they were written.","oss-knot-handbook.con-seal.pills":"A SEAL|CHANGES SHOW|NO INTERNET","oss-knot-handbook.con-seal.footer":"Before any of that, there are things that should never be on the receipt at all.","oss-knot-handbook.con-details.eyebrow":"What is left off","oss-knot-handbook.con-details.lead":"Your own details come out","oss-knot-handbook.con-details.accent":"before anything is saved","oss-knot-handbook.con-details.body":"A record of what software did for you would naturally hold your details, because your details are what it was working with. A receipt full of those is a new problem wearing the clothes of a solution.","oss-knot-handbook.con-details.detailLabel":"The guarantee","oss-knot-handbook.con-details.detail":"Knot takes them out before the receipt is saved, rather than hiding them when somebody looks at it. Hidden means still there.","oss-knot-handbook.con-details.pills":"TAKEN OUT FIRST|NOT STORED|NOTED","oss-knot-handbook.con-details.footer":"None of which helps while the answer to a complaint is still \"our records show\".","oss-knot-handbook.con-notgood.eyebrow":"The difference","oss-knot-handbook.con-notgood.lead":"\"Our records show\"","oss-knot-handbook.con-notgood.accent":"is not enough.","oss-knot-handbook.con-notgood.body":"When automated software does something you did not expect, the reply is often a version of ‘our records show’. It may be honest, but it is still one party reading its own notes to you. Getting beyond that usually means a complaint that takes weeks and reaches someone who was not there when the work happened.","oss-knot-handbook.con-notgood.detailLabel":"A sealed receipt","oss-knot-handbook.con-notgood.detail":"A sealed receipt changes what the conversation is about. It was written while the work happened, and someone else can check for themselves that it has not changed since. The disagreement stops being about whose account to believe. It becomes a question about one particular line, which is a question that can be answered.","oss-knot-handbook.con-notgood.pills":"WHAT IT WAS ASKED|WHAT IT DID|WHAT CHANGED","oss-knot-handbook.con-notgood.verdict":"a record, not a reassurance, and checking it needs no connection","oss-knot-handbook.con-notgood.footer":"all of which starts working the moment the receipt is in somebody else's hands","oss-knot-handbook.con-give.eyebrow":"When you ask for it","oss-knot-handbook.con-give.lead":"Ask them for the record","oss-knot-handbook.con-give.accent":"then hand it to anyone","oss-knot-handbook.con-give.body":"Knot runs wherever the software that acted for you runs, so you will never install it yourself. What you can do is ask for the record, and the question worth asking is what arrives when you do.","oss-knot-handbook.con-give.detailLabel":"What it means for you","oss-knot-handbook.con-give.detail":"What arrives is a folder of ordinary files and the public half of a signing key. Whoever you hand it to can check it for themselves, with no connection to anything.","oss-knot-handbook.con-give.pills":"ASK FOR IT|HAND IT ON|THEY CHECK IT","oss-knot-handbook.con-give.recipientOmbudsman":"OMBUDSMAN","oss-knot-handbook.con-give.recipientSolicitor":"SOLICITOR","oss-knot-handbook.con-give.recipientFriend":"FRIEND","oss-knot-handbook.con-give.footer":"One record, one check, and it works the same whoever's software wrote it.","oss-knot-handbook.con-anyone.eyebrow":"Whoever built it","oss-knot-handbook.con-anyone.lead":"The same kind of receipt","oss-knot-handbook.con-anyone.accent":"whoever's software acted","oss-knot-handbook.con-anyone.body":"Your bank, your insurer and the shop you ordered from all use different software, built by different people, changed on different Tuesdays. Today that means three different answers to the same question, in three formats.","oss-knot-handbook.con-anyone.detailLabel":"What it means for you","oss-knot-handbook.con-anyone.detail":"Knot sits underneath whichever system a company chose, so the receipt has the same shape whoever acted for you. The check is the same one every time.","oss-knot-handbook.con-anyone.pills":"ANY SOFTWARE|ONE SHAPE|SAME CHECK","oss-knot-handbook.con-anyone.sourceBank":"BANK TRANSFER","oss-knot-handbook.con-anyone.sourceInsurance":"INSURANCE CLAIM","oss-knot-handbook.con-anyone.stepAsked":"ASKED","oss-knot-handbook.con-anyone.stepLookedUp":"LOOKED UP","oss-knot-handbook.con-anyone.stepChanged":"CHANGED","oss-knot-handbook.con-anyone.stepFinished":"FINISHED","oss-knot-handbook.con-anyone.footer":"A receipt for work you did not watch, which outlasts the argument about it.","oss-knot-handbook.eng-kinds.detailLeft":"Knot records ten event kinds with stable names on the wire. A tool request and its response are separate entries, as are a model call, a produced message, a file edit, a state snapshot and a branch change. The record therefore preserves actions as things a reader can inspect, rather than lines somebody has to interpret.","oss-knot-handbook.eng-kinds.detailRight":"The set is closed. Nothing can introduce a new kind below the team that reviews the schema, so the same question works across every run. An adapter for a new framework must express its trace in the established kinds. That is how one record stays comparable when frameworks, models and teams change.","oss-knot-handbook.eng-identity.detailLeft":"Every entry takes its name from its own content, printed as a blake3 identifier. A retry after a timeout, a duplicate queue delivery or a process restart can submit the same bytes again. Knot resolves those arrivals to the entry already present instead of writing a second and third account of the same action.","oss-knot-handbook.eng-identity.detailRight":"One character of difference produces a different entry and both are kept. That makes idempotency a property of the record, not a patch every writer has to get right. It also gives two parties a simple comparison: if the names match, they hold the same content. They need not compare clocks or infer intent from arrival order.","oss-knot-handbook.eng-signature.detailLeft":"Knot signs the canonical encoding of each entry itself. Canonical encoding means two systems that represent the same content differently still arrive at the same bytes for signing. The proof follows the entry after the TLS session closes, the host is replaced and the database is moved, because none of those things sits inside the signature's claim.","oss-knot-handbook.eng-signature.detailRight":"A verifier needs only the entry and the published public key. It does not call the writer, join a session or receive access to the store. The public half can check a signature but cannot create one, so the receiver can reach a verdict without the organisation that wrote the record being present or helpful. The same check returns the same verdict years later, on a machine that never met the writer.","oss-knot-handbook.eng-root.detailLeft":"A valid signature proves that an entry has not changed. It cannot prove that an entry was not quietly removed. Knot therefore accumulates a Merkle root for each run, with the leaf count and intermediate peaks stored beside it. Recomputing that root from a delivered run exposes an omission even where every remaining signature is valid.","oss-knot-handbook.eng-root.detailRight":"Keeping roots per run is deliberate. A supplier can receive only the invoice run and still check its completeness, while unrelated runs remain where they are. An append extends the relevant structure by a binary carry instead of rebuilding its history. Adding to one run leaves every other run's root exactly unchanged.","oss-knot-handbook.eng-trail.detailLeft":"The record of who read a bundle has the same integrity problem as the run itself. Each trail line is hashed with its position, timestamp, message and the previous line's hash. The first line uses a fixed zero sentinel, and the digest is domain separated so it cannot be borrowed from another hashing purpose.","oss-knot-handbook.eng-trail.detailRight":"Position matters as much as content. Editing a line breaks its link, removing one shifts the numbering, and swapping two gives each the wrong predecessor. The checker stops at the first mismatch and names that exact line. Appending at the end remains normal activity, rather than a loophole in the record.","oss-knot-handbook.eng-bundle.detailLeft":"A Knot bundle is a readable directory: a manifest, run and branch indexes, one event file per content hash, the read trail and one signature over the manifest. Snapshots and projections can travel too, but they are explicitly derived. Anybody can list the directory and understand its shape without first trusting a proprietary reader.","oss-knot-handbook.eng-bundle.detailRight":"A file name is part of the check. If `9f2c1a04.json` no longer hashes to its name, any recipient with a hash function can see it. The same history can also leave as a compressed archive, newline-delimited JSON or Parquet where that optional build is enabled. The directory remains the clearest handover form, because reading it needs nothing installed first.","oss-knot-handbook.eng-redact.detailLeft":"Redaction happens before storage, in the same order every time: named secret fields, credentials, personal data, the tenant blocklist and tenant rules. An allowlist can end that walk early. This order matters because a broad local rule must not overtake a credential rule, or swallow a value the tenant expressly declared safe.","oss-knot-handbook.eng-redact.detailRight":"A removed value becomes a marker such as `[REDACTED:aws_key:3f9c2a]`. The kind and short fingerprint remain, so the same leaked credential can be found across many entries without being recoverable from any of them. Existing markers are left alone, and every removal is recorded inside the signed entry rather than asserted in an export policy.","oss-knot-handbook.eng-validate.detailLeft":"Knot does not redact a value merely because it resembles one. Card numbers are checked with Luhn, addresses with legal octet ranges and national identifiers against the words around them. The same nine digits in a bare reference field and a labelled note can therefore receive different, explainable treatment.","oss-knot-handbook.eng-validate.detailRight":"The restraint keeps the record usable. A card-shaped number that fails its checksum survives, as does `donation_token`, because field names match as whole words and it is not the field called `token`. The visual argument is two removals and four rescues. Avoiding needless redaction is part of preserving evidence, not a cosmetic exception.","oss-knot-handbook.eng-views.detailLeft":"Knot keeps six read views, including run state, branches, thread history, the run index, token usage and tool outcomes. Each is a deterministic function of the entries. A view is refreshed on read and on a short background interval, so it answers common questions quickly without becoming a second source of truth beside the log.","oss-knot-handbook.eng-views.detailRight":"If a dashboard claims all tool calls succeeded while an event records a failure, the entries settle the disagreement. Delete the view and rebuild it from the log. The same entries produce the same result, so the defect belongs to the stale view. A reviewer can inspect the entry file behind any figure the view presents.","oss-knot-handbook.eng-replay.detailLeft":"A replay can produce a signed statement of the state at a chosen point. Re-execution then classifies each comparison instead of rolling it into one pass or fail. A tool result may be byte identical, divergent, a subset of a newer result, or skipped. Model calls may match, diverge or be skipped, and each verdict is recorded against the step it belongs to.","oss-knot-handbook.eng-replay.detailRight":"Subset is not a polite word for failure. It says the new output contains everything recorded and more, which differs from a contradiction. The signed state statement captures what the system had been told before it acted. That separates the historical question from the later experiment of running an unstable dependency again.","oss-knot-handbook.eng-surface.detailLeft":"The service exposes one JSON-RPC endpoint, loopback for a single machine and TLS for remote callers. It accepts appends through the Model Context Protocol. Beside that door is unauthenticated liveness for a probe, authenticated health for in-flight requests and drain state, and Prometheus text metrics behind the credentialed surface.","oss-knot-handbook.eng-surface.detailRight":"Access has four modes: an owner-only token file, a client certificate, either during migration, or a workload identity token. The latter checks issuer, audience and validity window against published issuer keys. A drain reading is shown rather than inferred, so a rolling restart can wait for live work instead of gambling with an append.","oss-knot-handbook.eng-order.detailLeft":"One writer per process gives entries a total order at the store. There is no leader election, clock comparison or append round trip to describe later. A retry resolves to the content-addressed entry already present, so duplicate delivery is a no-op rather than a race between writers competing for a position.","oss-knot-handbook.eng-order.detailRight":"Reads sit beside the writer and do not hold its lock, because every projection can be rebuilt from the entries. Redaction runs before the write, the content name is taken, the position is fixed and the affected run root extends. What reaches a reviewer is the order one process wrote, not a consensus story they must trust.","oss-knot-handbook.biz-account.detailLeft":"A platform-held trace may be accurate and still leave the organisation exposed. During a dispute, a counterparty is asked to accept a report you commissioned. During review, an auditor is asked to accept a system they cannot inspect. When the contract ends, years of conduct can sit behind an account that is being closed.","oss-knot-handbook.biz-account.detailRight":"Knot moves the evidence path onto your own ground. The hardware is yours, the signing key is yours and the folder is yours to retain or hand over. The recipient does not need access to the production system to test it. That turns the record from a supplier assurance into an artefact an outside party can check.","oss-knot-handbook.biz-handover.detailLeft":"The recipient opens a folder and runs the checker without a network connection. It tests every entry signature, recomputes each run root and validates the read trail. The public key cannot write a new entry, which makes the receiver's verdict independent of the organisation that produced the folder.","oss-knot-handbook.biz-handover.detailRight":"A fault is located rather than used to dismiss an entire history. The report identifies the entry and run where it sits, while unaffected entries continue to pass. That matters in a long-lived record: one altered file should lead to a focused question about that file, not force an auditor to discard two years of evidence.","oss-knot-handbook.biz-redaction.detailLeft":"A full agent history naturally holds keys, tokens and personal details. If those values are filtered only at export, they have already reached the store, overnight copies and any replica the estate keeps. Knot removes them before writing, so downstream copies contain a tag rather than a value that creates another exception to manage.","oss-knot-handbook.biz-redaction.detailRight":"That changes the assessment itself. There is no sensitive value on disk for an export filter to catch, and no separate argument for each backup. The signed entry records what was removed and where, which gives a reviewer evidence of minimisation. The tag keeps enough context to understand the run without restoring the secret.","oss-knot-handbook.biz-estate.detailLeft":"The Python kit adapts LangGraph, OpenAI Agents, Microsoft Agent Framework, Pydantic-AI and CrewAI. The TypeScript kit adapts LangGraph, OpenAI Agents and Vercel AI, with a generic route in both. Each adapter translates its framework's trace into the same ten event kinds rather than wrapping it in a generic surface.","oss-knot-handbook.biz-estate.detailRight":"Framework and version remain recorded on every entry, so one history does not blur two teams into an average. A cross-estate question becomes a query over one shape, one retention decision and one export. Replacing a model or framework later leaves the earlier record comparable, which is the continuity procurement normally has to rebuild by hand.","oss-knot-handbook.biz-state.detailLeft":"A reviewer often wants the state before a decision, not an end-of-run summary. Knot replays the run up to a chosen point and produces a signed statement of what the system had been told and decided by then. Everything later is visibly outside the cut, including the decision the review may be investigating.","oss-knot-handbook.biz-state.detailRight":"That is an artefact a reviewer can check rather than a conclusion someone has composed from log lines. It addresses the record-keeping and traceability question directly: what was true at that moment. Re-execution is separate and returns classified comparisons, so the original state is not confused with whatever a changed model or tool does now.","oss-knot-handbook.biz-retention.detailLeft":"Retention starts disabled. Once configured, Knot archives when the first of three limits is reached: an age, a store size or an entry count. The archive is a dated compressed file, suitable for cheaper storage or an existing records process. A zero age is refused because immediate archiving is a mistake, not a policy.","oss-knot-handbook.biz-retention.detailRight":"Archiving does not erase the live account of a run. Its root remains readable, so an archived run can still be identified and accounted for without unpacking every old entry. The retention decision becomes explicit and reviewable: the trigger that fired is known, the archive has a date and the run still has a stable identity.","oss-knot-handbook.biz-sovereignty.detailLeft":"Knot writes records entirely inside the operator's boundary. You hold the signing half of the key and publish only the half that checks. Nothing operated by Knot's authors sits in the evidence path. A bundle crosses that boundary only when you choose to give it to a counterparty, auditor or regulator. The disk, the machine and the jurisdiction it stands in are the ones you already chose for the rest of the estate.","oss-knot-handbook.biz-sovereignty.detailRight":"This is not a waiver from normal procurement work. It removes questions that have no external subject here: supplier assessment in the evidence path, transfer mechanism for a record that never left, outside availability during an incident and a release schedule changing behaviour under you. The deliberate handover of a bundle remains a decision for the organisation.","oss-knot-handbook.biz-access.detailLeft":"Access configuration answers who may open the record. It can be an owner-only token file, a client certificate, both during migration or a workload identity token validated against issuer, audience and time. A reviewer can inspect that configuration and see a bad credential refused, instead of accepting a statement that the control exists.","oss-knot-handbook.biz-access.detailRight":"The answer to who did open it is inside the record. Each read appends a trail line sealed with its position, time and predecessor. Removing a read from the middle changes the chain and the checker names the first broken line. Access policy and access history are separate artefacts, because they answer different questions.","oss-knot-handbook.biz-standup.detailLeft":"The `doctor` command inspects the signing key, credential permissions, schema version, data directory and log directory. Each result has a severity. It catches ordinary inherited-installation faults, such as a token file readable by a group or a schema behind the software, before a team discovers them during an incident.","oss-knot-handbook.biz-standup.detailRight":"Routine faults can be repaired in place. Knot can rotate the credential, reset the ordinary permission problem and apply a pending migration, then report the clean reading that follows. The point is not that setup is easy. It is that the person inheriting the service can establish whether it will sign, store and export today with one observable check.","oss-knot-handbook.biz-scale.detailLeft":"Knot starts with a local file database on the machine beside the first agent. A server database backend is available for a shared estate, and object storage can hold large blobs while the entries remain small. These are deployment choices, not a migration to a different kind of record or a new assurance process.","oss-knot-handbook.biz-scale.detailRight":"The bundle remains the same across those choices: manifest, event files, roots, signature and separate checker. Retention, event kinds and the published public key do not need rewriting because storage changed under them. A pilot can grow into a multi-team history without making a year of evidence unreadable on the way.","oss-knot-handbook.con-acted.detailLeft":"When software books an appointment, replies for you, moves money or submits a form, the important question is not whether it was automated. It is what happened when nobody watched. Usually the only answer comes weeks later from the company whose system acted, in a summary it prepared from records you cannot inspect.","oss-knot-handbook.con-acted.detailRight":"Knot writes a receipt while the work happens. It keeps the steps in order, stays with the software's owner and can be handed to you or to someone you choose. If a transfer goes to the wrong account, the question begins with the record of the actual choice, not with a request for the company to remember it.","oss-knot-handbook.con-receipt.detailLeft":"The receipt records what was asked, what the software looked up, what came back, when a step failed and which file changed. The order matters because it shows whether the system checked before it acted. It is not a polished account written from memory after somebody asks why the outcome was wrong.","oss-knot-handbook.con-receipt.detailRight":"Nothing is written over. If a correction is needed, it is added at the end and the earlier line remains where it was. That is what lets a reader see the choice that led to the result, including a failed step. A notification saying only that a transfer completed cannot make the same case, and neither can a letter written weeks afterwards.","oss-knot-handbook.con-seal.detailLeft":"Each receipt line has a seal made from its exact content. Change a word and the seal no longer fits the words on the line. The receipt also carries a total over all lines in their original order, so quietly removing or moving a line changes a separate check even where every remaining line still looks ordinary.","oss-knot-handbook.con-seal.detailRight":"Checking needs the receipt and the published half of the key, not a connection or an account with the company. The result names the altered line. It does not merely say that something feels wrong. A later edit turns the receipt into a visibly broken record, which is very different from asking a person to believe a screenshot.","oss-knot-handbook.con-details.detailLeft":"A useful receipt must not become a second store of your bank details, card number or identity number. Knot removes those values before it saves the line. Hiding them later would leave them in the file, its backups and any copy sent to a reviewer. The saved receipt has no clear-text value to expose.","oss-knot-handbook.con-details.detailRight":"A tag says what was removed and carries a short fingerprint so the same value can still be recognised where it appeared again. The rest of the line stays useful: the amount, the time, what was selected and what went wrong. Number checks also avoid treating every reference number as though it were somebody's account.","oss-knot-handbook.con-give.detailLeft":"You would not install Knot yourself. It runs where the software that acted for you runs. What you can ask for is a record that is more than a notification or letter: a folder of ordinary files and a public key. The public key is not secret, and the same one can be given to anyone who needs to check the folder. Nothing in the folder needs a password or a special program to open.","oss-knot-handbook.con-give.detailRight":"An ombudsman, solicitor, bank or technically minded friend can each make the same three checks for themselves. The line seals fit, the total matches the lines present and the order is intact. Nothing needs to travel back to the company for confirmation. You do not have to be believed, and neither does the organisation that wrote the receipt.","oss-knot-handbook.con-anyone.detailLeft":"Different organisations will keep changing their software, but a Knot receipt keeps the same basic shape. It says that work was requested, information was looked up, a tool succeeded or failed, a file changed and the run finished. Each line also identifies the system and version that wrote it, rather than hiding that detail in a later header.","oss-knot-handbook.con-anyone.detailRight":"That gives you one way to read a bank transfer and an insurance claim, even when entirely different systems handled them. The same small checker applies to both and produces the same kind of verdict. A future system change does not alter what last year's receipt says, because the record describes the work rather than a supplier's interface.","oss-knot-handbook.visual.record":"record","oss-knot-handbook.visual.check":"check","oss-knot-handbook.visual.handover":"handover","oss-knot-handbook.visual.folder":"folder","oss-knot-handbook.visual.failed":"failed","oss-knot-handbook.visual.oneEntry":"one entry","oss-knot-handbook.visual.oneCharacterChanged":"one character changed","oss-knot-handbook.visual.connection":"connection","oss-knot-handbook.visual.closed":"closed","oss-knot-handbook.visual.machine":"machine","oss-knot-handbook.visual.replaced":"replaced","oss-knot-handbook.visual.process":"process","oss-knot-handbook.visual.restarted":"restarted","oss-knot-handbook.visual.store":"store","oss-knot-handbook.visual.migrated":"migrated","oss-knot-handbook.visual.entry":"entry","oss-knot-handbook.visual.toolResponse":"tool response","oss-knot-handbook.visual.eventHash":"event hash","oss-knot-handbook.visual.signaturePublicKey":"signature + public key","oss-knot-handbook.visual.checksAlone":"checks alone","oss-knot-handbook.visual.completeRun":"complete run","oss-knot-handbook.visual.rootChanges":"root changes","oss-knot-handbook.visual.missingResponse":"missing response","oss-knot-handbook.visual.externalAuditor":"external auditor","oss-knot-handbook.visual.internalReview":"internal review","oss-knot-handbook.visual.readBundle":"read bundle","oss-knot-handbook.visual.firstBrokenLine":"first broken line","oss-knot-handbook.visual.agentSaw":"agent saw","oss-knot-handbook.visual.stored":"stored","oss-knot-handbook.visual.sameShape":"same shape","oss-knot-handbook.visual.contextAbsent":"context absent","oss-knot-handbook.visual.kept":"kept","oss-knot-handbook.visual.identityLabel":"identity label","oss-knot-handbook.visual.removed":"removed","oss-knot-handbook.visual.checksum":"checksum","oss-knot-handbook.visual.range":"range","oss-knot-handbook.visual.wholeWord":"whole word","oss-knot-handbook.visual.patternOnly":"pattern only","oss-knot-handbook.visual.recordDamaged":"record damaged","oss-knot-handbook.visual.oldView":"old view","oss-knot-handbook.visual.successful":"successful","oss-knot-handbook.visual.failures":"failures","oss-knot-handbook.visual.events":"events","oss-knot-handbook.visual.rebuild":"rebuild","oss-knot-handbook.visual.rebuiltView":"rebuilt view","oss-knot-handbook.visual.stateAt":"state at","oss-knot-handbook.visual.signedStatement":"signed statement","oss-knot-handbook.visual.recordedResponse":"recorded response","oss-knot-handbook.visual.retryNote":"retry note","oss-knot-handbook.visual.identical":"identical","oss-knot-handbook.visual.divergent":"divergent","oss-knot-handbook.visual.subset":"subset","oss-knot-handbook.visual.skipped":"skipped","oss-knot-handbook.visual.endpoint":"endpoint","oss-knot-handbook.visual.tokenFile":"token file","oss-knot-handbook.visual.clientCertificate":"client certificate","oss-knot-handbook.visual.migration":"migration","oss-knot-handbook.visual.workloadIdentity":"workload identity","oss-knot-handbook.visual.health":"health","oss-knot-handbook.visual.inFlight":"in flight","oss-knot-handbook.visual.draining":"draining","oss-knot-handbook.visual.retry":"retry","oss-knot-handbook.visual.oneWriter":"one writer","oss-knot-handbook.visual.runList":"run list","oss-knot-handbook.visual.toolOutcomes":"tool outcomes","oss-knot-handbook.visual.browser":"browser","oss-knot-handbook.visual.operations":"operations","oss-knot-handbook.visual.wrongPayment":"wrong payment","oss-knot-handbook.visual.platformTrace":"platform trace","oss-knot-handbook.visual.theirAccount":"their account","oss-knot-handbook.visual.export":"export","oss-knot-handbook.visual.acceptedReturned":"accepted / returned","oss-knot-handbook.visual.yourDesk":"your desk","oss-knot-handbook.visual.publicKey":"public key","oss-knot-handbook.visual.noAccessRequest":"no access request","oss-knot-handbook.visual.onlyTheseCross":"only these cross","oss-knot-handbook.visual.reviewer":"reviewer","oss-knot-handbook.visual.entriesConfirmed":"entries confirmed","oss-knot-handbook.visual.rootMatches":"root matches","oss-knot-handbook.visual.faultNamed":"fault named","oss-knot-handbook.visual.redaction":"redaction","oss-knot-handbook.visual.overnightCopy":"overnight copy","oss-knot-handbook.visual.archive":"archive","oss-knot-handbook.visual.bundle":"bundle","oss-knot-handbook.visual.finance":"finance","oss-knot-handbook.visual.nestedTrace":"nested trace","oss-knot-handbook.visual.support":"support","oss-knot-handbook.visual.flatStream":"flat stream","oss-knot-handbook.visual.oneHistory":"one history","oss-knot-handbook.visual.framework":"framework","oss-knot-handbook.visual.version":"version","oss-knot-handbook.visual.event":"event","oss-knot-handbook.visual.asked":"asked","oss-knot-handbook.visual.lookedUp":"looked up","oss-knot-handbook.visual.selected":"selected","oss-knot-handbook.visual.approved":"approved","oss-knot-handbook.visual.fileChanged":"file changed","oss-knot-handbook.visual.signed":"signed","oss-knot-handbook.visual.live":"live","oss-knot-handbook.visual.age":"age","oss-knot-handbook.visual.size":"size","oss-knot-handbook.visual.count":"count","oss-knot-handbook.visual.agents":"agents","oss-knot-handbook.visual.yourBoundary":"your boundary","oss-knot-handbook.visual.supplierReview":"supplier review","oss-knot-handbook.visual.transferMechanism":"transfer mechanism","oss-knot-handbook.visual.externalUptime":"external uptime","oss-knot-handbook.visual.releaseSchedule":"release schedule","oss-knot-handbook.visual.issuer":"issuer","oss-knot-handbook.visual.audience":"audience","oss-knot-handbook.visual.window":"window","oss-knot-handbook.visual.permissions":"permissions","oss-knot-handbook.visual.ownerOnly":"owner only","oss-knot-handbook.visual.readTrail":"read trail","oss-knot-handbook.visual.auditor":"auditor","oss-knot-handbook.visual.counsel":"counsel","oss-knot-handbook.visual.doctorInherited":"doctor, inherited","oss-knot-handbook.visual.keyPresent":"key present","oss-knot-handbook.visual.credential":"credential","oss-knot-handbook.visual.findings":"findings","oss-knot-handbook.visual.schemaBehind":"schema behind","oss-knot-handbook.visual.dataDirectory":"data directory","oss-knot-handbook.visual.logDirectory":"log directory","oss-knot-handbook.visual.fix":"fix","oss-knot-handbook.visual.pass":"pass","oss-knot-handbook.visual.doctorRepaired":"doctor, repaired","oss-knot-handbook.visual.schemaCurrent":"schema current","oss-knot-handbook.visual.pilot":"pilot","oss-knot-handbook.visual.agent":"agent","oss-knot-handbook.visual.localFile":"local file","oss-knot-handbook.visual.estate":"estate","oss-knot-handbook.visual.fourServices":"four services","oss-knot-handbook.visual.serverDatabase":"server database","oss-knot-handbook.visual.payloads":"payloads","oss-knot-handbook.visual.sharedRecord":"shared record","oss-knot-handbook.visual.objectStorage":"object storage","oss-knot-handbook.visual.sameFolder":"same folder","oss-knot-handbook.visual.sameCheck":"same check","oss-knot-handbook.visual.appointment":"appointment","oss-knot-handbook.visual.reply":"reply","oss-knot-handbook.visual.transfer":"transfer","oss-knot-handbook.visual.form":"form","oss-knot-handbook.visual.wrongAccount":"wrong account","oss-knot-handbook.visual.noReceipt":"no receipt","oss-knot-handbook.visual.askedToMove":"asked to move EUR 400","oss-knot-handbook.visual.lookedUpAccounts":"looked up accounts","oss-knot-handbook.visual.twoNamesReturned":"two names returned","oss-knot-handbook.visual.choseSecond":"chose the second","oss-knot-handbook.visual.moved":"moved","oss-knot-handbook.visual.confirmed":"confirmed","oss-knot-handbook.visual.finished":"finished","oss-knot-handbook.visual.today":"today","oss-knot-handbook.visual.transferCompleted":"transfer completed","oss-knot-handbook.visual.original":"original","oss-knot-handbook.visual.choseThe":"chose the","oss-knot-handbook.visual.second":"second","oss-knot-handbook.visual.line":"line","oss-knot-handbook.visual.altered":"altered","oss-knot-handbook.visual.first":"first","oss-knot-handbook.visual.from":"from","oss-knot-handbook.visual.toAccountLineFour":"to the account chosen at line four, at","oss-knot-handbook.visual.afterReading":"after reading a document with","oss-knot-handbook.visual.amountKept":"amount kept","oss-knot-handbook.visual.timeKept":"time kept","oss-knot-handbook.visual.orderKept":"order kept","oss-knot-handbook.visual.detailsAbsent":"details absent","oss-knot-handbook.visual.yourRequest":"your request","oss-knot-handbook.visual.ombudsman":"ombudsman","oss-knot-handbook.visual.solicitor":"solicitor","oss-knot-handbook.visual.friend":"friend","oss-knot-handbook.visual.checks":"checks","oss-knot-handbook.visual.bankTransfer":"bank transfer","oss-knot-handbook.visual.insuranceClaim":"insurance claim","oss-knot-handbook.visual.changedFile":"changed a file","oss-knot-handbook.visual.lookupFailed":"lookup failed","oss-knot-handbook.visual.seal":"seal","oss-knot-handbook.visual.sameChecker":"same checker","oss-knot-handbook.visual.verifiedReading":"verified reading","oss-knot-handbook.visual.approve":"approve","oss-knot-handbook.visual.reject":"reject","oss-knot-handbook.visual.signature":"signature","oss-knot-handbook.visual.fileName":"file name","oss-knot-handbook.visual.runRoot":"run root","oss-knot-handbook.visual.fault":"fault","oss-knot-handbook.visual.yourReconstruction":"your reconstruction","oss-knot-handbook.visual.theirReconstruction":"their reconstruction","oss-knot-handbook.visual.oneSignedSequence":"one signed sequence","oss-knot-handbook.visual.model":"model","oss-knot-handbook.visual.platform":"platform","oss-knot-handbook.visual.changed":"changed","oss-knot-handbook.visual.renegotiated":"renegotiated","oss-knot-handbook.visual.entries":"entries","oss-knot-handbook.visual.signatures":"signatures","oss-knot-handbook.visual.roots":"roots","oss-knot-handbook.visual.trail":"trail","oss-knot-handbook.visual.ourRecordsShow":"our records show","oss-knot-handbook.visual.whatItDid":"what it did","oss-knot-handbook.visual.inOrder":"in order","oss-knot-handbook.visual.sealed":"sealed","oss-knot-handbook.visual.write":"write","oss-knot-handbook.visual.privateKey":"private key","oss-knot-handbook.visual.yourMachine":"your machine","oss-knot-handbook.visual.eventSequence":"event sequence","oss-knot-handbook.visual.oneRun":"one run","oss-knot-handbook.visual.appendOrder":"append order","oss-knot-handbook.visual.sameBytes":"same bytes","oss-knot-handbook.visual.writtenOnce":"written once","oss-knot-handbook.visual.contentName":"content name","oss-knot-handbook.visual.notClockOrder":"not clock order","oss-knot-handbook.visual.replayCut":"replay cut","oss-knot-handbook.visual.laterEventsExcluded":"later events excluded","oss-knot-handbook.visual.evidenceBeforeCut":"evidence before the cut","oss-knot-handbook.visual.signedStateStatement":"signed state statement","oss-knot-handbook.visual.whatWasKnown":"what was known and decided","oss-knot-handbook.visual.outsideTheCut":"outside the cut","oss-knot-handbook.visual.theCutIsSigned":"the cut is signed","oss-knot-handbook.visual.replayDoesNotRewrite":"replay does not rewrite history","oss-knot-handbook.visual.choseFirst":"chose the first","oss-knot-handbook.visual.receiptRoot":"receipt root","oss-knot-handbook.visual.receiptComparison":"receipt comparison","oss-knot-handbook.visual.sameRunDifferentBytes":"same run, different bytes","oss-knot-handbook.visual.sealBreaks":"seal breaks","oss-knot-handbook.visual.checkerNamesTheLine":"checker names the altered line","oss-knot-handbook.visual.runSi":"run: SI-2291","oss-knot-handbook.visual.modelReview":"model: review","oss-knot-handbook.visual.tokens418":"tokens: 418","oss-knot-handbook.visual.transferTool":"tool: transfer","oss-knot-handbook.visual.resultAccepted":"result: accepted","oss-knot-handbook.visual.customerThread":"thread: customer","oss-knot-handbook.visual.receiptFile":"file: receipt.pdf","oss-knot-handbook.visual.statusComplete":"status: complete","oss-knot-handbook.visual.requestMove":"request: move EUR 400","oss-knot-handbook.visual.accountsReturned":"accounts: 2 returned","oss-knot-handbook.visual.choiceAccount":"choice: account 02","oss-knot-handbook.visual.transferSubmitted":"transfer: submitted","oss-knot-handbook.visual.receiptWritten":"receipt.pdf written","oss-knot-handbook.visual.arrival":"arrival","oss-knot-handbook.visual.accepted":"accepted","oss-knot-handbook.visual.bundleInspector":"Bundle inspector","oss-knot-handbook.visual.bundleInspectorSubtitle":"Read the manifest, event file and signature from the portable evidence folder.","oss-knot-handbook.visual.endpointConsole":"MCP endpoint","oss-knot-handbook.visual.endpointConsoleSubtitle":"Inspect the authenticated append surface and its live health reading.","oss-knot-handbook.visual.doctorConsole":"Knot doctor","oss-knot-handbook.visual.doctorConsoleSubtitle":"Read the inherited installation, repair ordinary faults, then check it again.","oss-knot-handbook.visual.ready":"Ready","oss-knot-handbook.visual.healthy":"Healthy","oss-knot-handbook.visual.canonicalBytes":"canonical bytes","oss-knot-handbook.visual.metrics":"metrics","oss-knot-handbook.visual.textResponse":"text","oss-knot-handbook.visual.rootCarry":"root + one carry","oss-knot-handbook.visual.changeWord":"change a word","oss-knot-handbook.visual.sealFails":"seal fails","oss-knot-handbook.visual.removeLine":"remove a line","oss-knot-handbook.visual.rootFails":"root fails","oss-knot-handbook.visual.moveLine":"move a line","oss-knot-handbook.visual.orderFails":"order fails","oss-knot-handbook.visual.appendAtEnd":"add at the end","oss-knot-handbook.visual.cardNumber":"card number","oss-knot-handbook.visual.identityNumber":"identity number","oss-knot-handbook.visual.peak":"peak","oss-knot-handbook.visual.differentShape":"different shape","oss-knot-handbook.visual.contained":"contained","oss-knot-handbook.visual.notRunAgain":"not run again","oss-knot-handbook.visual.searchTool":"tool: ledger.search","oss-knot-handbook.visual.searchResult":"result: two accounts","oss-knot-handbook.visual.invoiceTool":"tool: invoice.fetch","oss-knot-handbook.visual.invoiceFailed":"result: failed","oss-knot-handbook.visual.messageProduced":"message: customer","oss-knot-handbook.visual.claim":"claim","oss-knot-handbook.visual.noPerson":"no person","oss-knot-handbook.visual.oneRecordOneCheck":"one record, one check","oss-knot-handbook.visual.receipt":"receipt","oss-knot-handbook.visual.returned":"returned","oss-knot-handbook.visual.sameKindOfReceipt":"the same receipt shape","oss-knot-handbook.visual.somethingActed":"something acted for you","oss-knot-handbook.visual.whoHasAlreadyRead":"who has already read it","oss-knot-handbook.visual.mainTitle.eng-kinds":"Event type sequence","oss-knot-handbook.visual.mainTitle.eng-identity":"Retry identity resolution","oss-knot-handbook.visual.mainTitle.eng-signature":"Signed entry scope","oss-knot-handbook.visual.mainTitle.eng-root":"Run completeness proof","oss-knot-handbook.visual.mainTitle.eng-trail":"Read-trail break inspection","oss-knot-handbook.visual.mainTitle.eng-bundle":"Portable bundle anatomy","oss-knot-handbook.visual.mainTitle.eng-redact":"Pre-write redaction path","oss-knot-handbook.visual.mainTitle.eng-validate":"Contextual identity decision","oss-knot-handbook.visual.mainTitle.eng-views":"Rebuildable derived view","oss-knot-handbook.visual.mainTitle.eng-replay":"Signed replay comparison","oss-knot-handbook.visual.mainTitle.eng-surface":"Authenticated append surface","oss-knot-handbook.visual.mainTitle.eng-order":"Single-writer ordering","oss-knot-handbook.visual.mainTitle.biz-account":"Shared supplier evidence","oss-knot-handbook.visual.mainTitle.biz-handover":"Independent evidence handover","oss-knot-handbook.visual.mainTitle.biz-redaction":"Redaction before replication","oss-knot-handbook.visual.mainTitle.biz-estate":"One history across frameworks","oss-knot-handbook.visual.mainTitle.biz-state":"Signed state at 14:20","oss-knot-handbook.visual.mainTitle.biz-retention":"Retention threshold control","oss-knot-handbook.visual.mainTitle.biz-sovereignty":"Operator-owned record boundary","oss-knot-handbook.visual.mainTitle.biz-access":"Access gate and read trail","oss-knot-handbook.visual.mainTitle.biz-standup":"Repairable estate diagnosis","oss-knot-handbook.visual.mainTitle.biz-scale":"One evidence contract at every scale","oss-knot-handbook.visual.mainTitle.con-acted":"Reconstructing an automated action","oss-knot-handbook.visual.mainTitle.con-receipt":"Machine-work receipt","oss-knot-handbook.visual.mainTitle.con-seal":"Sealed receipt comparison","oss-knot-handbook.visual.mainTitle.con-details":"Details removed before storage","oss-knot-handbook.visual.mainTitle.con-give":"Portable evidence handover","oss-knot-handbook.visual.mainTitle.con-anyone":"One checker for every source","oss-knot-handbook.visual.instrument.eng-kinds":"Event kind registry","oss-knot-handbook.visual.instrument.eng-identity":"Retry identity resolver","oss-knot-handbook.visual.instrument.eng-signature":"Signature coverage","oss-knot-handbook.visual.instrument.eng-root":"Run completeness meter","oss-knot-handbook.visual.instrument.eng-trail":"Read-trail break finder","oss-knot-handbook.visual.instrument.eng-bundle":"Portable bundle index","oss-knot-handbook.visual.instrument.eng-redact":"Pre-write redaction rotor","oss-knot-handbook.visual.instrument.eng-validate":"Context validation bench","oss-knot-handbook.visual.instrument.eng-views":"Derived-view projector","oss-knot-handbook.visual.instrument.eng-replay":"Replay verdict dial","oss-knot-handbook.visual.instrument.eng-surface":"Local append surface","oss-knot-handbook.visual.instrument.eng-order":"Single-writer sequencer","oss-knot-handbook.visual.instrument.biz-account":"Supplier evidence gap","oss-knot-handbook.visual.instrument.biz-handover":"Independent handover case","oss-knot-handbook.visual.instrument.biz-redaction":"Safe-copy boundary","oss-knot-handbook.visual.instrument.biz-estate":"Framework convergence","oss-knot-handbook.visual.instrument.biz-state":"Signed state cut","oss-knot-handbook.visual.instrument.biz-retention":"Retention threshold desk","oss-knot-handbook.visual.instrument.biz-sovereignty":"Operator boundary","oss-knot-handbook.visual.instrument.biz-access":"Access and read receipt","oss-knot-handbook.visual.instrument.biz-standup":"Estate health check","oss-knot-handbook.visual.instrument.biz-scale":"Storage growth path","oss-knot-handbook.visual.instrument.con-acted":"Unrecorded action clock","oss-knot-handbook.visual.instrument.con-receipt":"Work receipt","oss-knot-handbook.visual.instrument.con-seal":"Tamper-seal comparison","oss-knot-handbook.visual.instrument.con-details":"Privacy filter","oss-knot-handbook.visual.instrument.con-give":"Portable handover","oss-knot-handbook.visual.instrument.con-anyone":"Universal checker","oss-knot-handbook.visual.illustrative":"illustrative","oss-knot-handbook.visual.amountTimeOrder":"amount / time / order","oss-knot-handbook.visual.appScreenshot":"app screenshot","oss-knot-handbook.visual.applyMigration":"apply migration","oss-knot-handbook.visual.asFarAsEstablished":"as far as we can establish","oss-knot-handbook.visual.beforeWrite":"before write","oss-knot-handbook.visual.clockComparison":"clock comparison","oss-knot-handbook.visual.whatMultiWriterNeeds":"what multiple writers need","oss-knot-handbook.visual.leaderElection":"leader election","oss-knot-handbook.visual.datedFiles":"dated files","oss-knot-handbook.visual.days":"days","oss-knot-handbook.visual.daysLogsRotated":"days / logs rotated","oss-knot-handbook.visual.engineeringCall":"engineering call","oss-knot-handbook.visual.expired":"expired","oss-knot-handbook.visual.failedCallsOneQuery":"failed supplier portal calls / one query","oss-knot-handbook.visual.fourExports":"four exports","oss-knot-handbook.visual.intactThrough":"intact through line","oss-knot-handbook.visual.kindBeforeSaveFingerprint":"kind / before save / fingerprint","oss-knot-handbook.visual.leader":"leader","oss-knot-handbook.visual.leavesDeliberately":"leaves deliberately","oss-knot-handbook.visual.monthDecember":"December","oss-knot-handbook.visual.monthMarch":"March","oss-knot-handbook.visual.monthNovember":"November","oss-knot-handbook.visual.neverStored":"never stored","oss-knot-handbook.visual.newResponse":"new response","oss-knot-handbook.visual.noLock":"no lock","oss-knot-handbook.visual.noRawValue":"no raw value","oss-knot-handbook.visual.notApplicable":"not applicable","oss-knot-handbook.visual.oneMachine":"one machine","oss-knot-handbook.visual.oneRunTravels":"one run travels alone","oss-knot-handbook.visual.pdfLetter":"PDF letter","oss-knot-handbook.visual.peopleOneMovedTeams":"people / one moved teams","oss-knot-handbook.visual.recomputed":"recomputed","oss-knot-handbook.visual.removalReport":"removal report","oss-knot-handbook.visual.retrievedNote":"retrieved note","oss-knot-handbook.visual.rollingRestart":"rolling restart","oss-knot-handbook.visual.rootRemainsLive":"root remains live","oss-knot-handbook.visual.rotateCredential":"rotate credential","oss-knot-handbook.visual.roundTrip":"round trip","oss-knot-handbook.visual.runHere":"run here","oss-knot-handbook.visual.runs":"runs","oss-knot-handbook.visual.samePublicKey":"same public key","oss-knot-handbook.visual.sameRetention":"same retention","oss-knot-handbook.visual.sameSecretFourEntries":"same secret, four entries","oss-knot-handbook.visual.sealTotalOrder":"seal / total / order","oss-knot-handbook.visual.sendMyRecord":"send my record","oss-knot-handbook.visual.sessionProof":"session proof","oss-knot-handbook.visual.spreadsheet":"spreadsheet","oss-knot-handbook.visual.streamExport":"stream export","oss-knot-handbook.visual.supplierTicket":"supplier ticket","oss-knot-handbook.visual.tenKinds":"ten kinds","oss-knot-handbook.visual.tieBreak":"tie break","oss-knot-handbook.visual.treeExport":"tree export","oss-knot-handbook.visual.accessRequest":"access request","oss-knot-handbook.visual.account":"account","oss-knot-handbook.close.headlineAccent":"without asking you for anything","oss-knot-handbook.close.panelTitle":"What a stranger receives","oss-knot-handbook.close.panelTag":"BUNDLE","oss-knot-handbook.close.panelRow0Label":"What a bundle holds","oss-knot-handbook.close.panelRow0Value":"A manifest, run and branch indexes, one file per event, the read trail","oss-knot-handbook.close.panelRow1Label":"What checks it","oss-knot-handbook.close.panelRow1Value":"The entry and a published public key, nothing else","oss-knot-handbook.close.panelRow2Label":"Where it is written","oss-knot-handbook.close.panelRow2Value":"Machines inside your own boundary, one writer per process","oss-knot-handbook.close.panelRow3Label":"Replay verdicts","oss-knot-handbook.close.panelRow3Value":"Identical, divergent, subset or skipped","oss-knot-handbook.close.panelFoot":"A file whose name no longer matches its hash is visible to anyone holding a hash function.","oss-knot-hero-glyph.brandLabel":"Knot","oss-knot-hero-glyph.35d3461275":"knot export ./run-7f3a.bundle","oss-knot-hero-glyph.3f10a58594":"VERIFIED, authentic and unaltered, offline","oss-knot-hero-glyph.1b2da13597":"trust-log hash chain intact","oss-knot-hero-glyph.0a28ce80b2":"signatures 1284 / 1284","oss-knot-hero-glyph.4e43b1a78e":"merkle roots re-derived 3 / 3","oss-knot-hero-glyph.68bf2360cd":"events 1284  runs 3  branches 2","oss-knot-hero-glyph.91bea9e4b6":"verifier ./run-7f3a.bundle knot-deploy.pub","oss-knot-hero-glyph.809c461a9c":"evt_run_7f3a9c_...0504 (tool_call_responded)","oss-knot-hero-glyph.fbb7ebd7f8":"Last event:","oss-knot-hero-glyph.5e6f895a9d":"Merkle root (main):","oss-knot-hero-glyph.bf4f013e1d":"Knot daemon:","oss-knot-hero-glyph.904c7221d8":"knot status","oss-knot-hero-glyph.d41e7eec1b":"Signed at:","oss-knot-hero-glyph.1f369862cb":"Sequence:","oss-knot-hero-glyph.5bccbefc97":"b7af3c1e d4902f6b 88ae5170 c3fe21da","oss-knot-hero-glyph.fdc76b6c99":"Merkle root:","oss-knot-hero-glyph.b5b2d8d88b":"committed evt_run_7f3a9c_0000000000000504","oss-knot-hero-glyph.3b314a0a9f":"redact: 2 secrets masked at ingest","oss-knot-hero-glyph.7a1420ada5":"-m \"fs.read README\"","oss-knot-hero-glyph.fb68a15c14":"knot commit","oss-knot-hero-glyph.5a8d5adb24":"Config:","oss-knot-hero-glyph.fe5404dbd5":"Signing pubkey:","oss-knot-hero-glyph.eb005a07e7":"initialized knot at ~/.knot","oss-knot-hero-glyph.4aa90737c5":"knot init","oss-knot-mcp-surface.f1ccc2ebe4":"Bearer-token auth, constant-time comparison","oss-knot-mcp-surface.f6c5142982":"typed exit codes","oss-knot-mcp-surface.83d5fa1cbb":"Command line","oss-knot-mcp-surface.87df60de33":"Records","oss-knot-mcp-surface.4fa8cc860c":"Actions","oss-knot-mcp-surface.ff909511ab":"Streamable HTTP, stdio","oss-knot-mcp-surface.723acd7128":"Agent connection","oss-knot-mcp-surface.49b980782c":"stdio MCP bridge","oss-knot-mcp-surface.50918d9f5a":"knot mcp","oss-knot-mcp-surface.2ae8aa101e":"offline verdict","oss-knot-mcp-surface.84153f61a7":"knot verify ./bundle key.pub","oss-knot-mcp-surface.c607f33fe7":"current run state","oss-knot-mcp-surface.904c7221d8":"knot status","oss-knot-mcp-surface.e3af777c0b":"append an event","oss-knot-mcp-surface.dc3bc24fcf":"knot commit --json","oss-knot-mcp-surface.f79e678ea0":"create a data directory","oss-knot-mcp-surface.4aa90737c5":"knot init","oss-knot-mcp-surface.8871564f37":"Daemon health and counters","oss-knot-mcp-surface.2093789ce6":"A named branch head","oss-knot-mcp-surface.da574afa58":"Folded state of one run","oss-knot-mcp-surface.57935554aa":"Stream new events as they commit","oss-knot-mcp-surface.826c202807":"Replay a range into a signed attestation","oss-knot-mcp-surface.fc70700468":"Append a signed event to the log","oss-knot-notgood-banner.eyebrow":"What you should be able to get","oss-knot-notgood-banner.lead":"Our records show","oss-knot-notgood-banner.accent":"is not enough","oss-knot-notgood-banner.body":"A useful receipt says what happened, in order, and lets someone outside the company check it. That is the difference between a reassurance and a record.","oss-knot-notgood-banner.itemRecord":"a record, not a promise","oss-knot-notgood-banner.itemOrder":"the work in order","oss-knot-notgood-banner.itemChanges":"changes show up","oss-knot-notgood-banner.itemPrivate":"private details left out","oss-knot-notgood-banner.itemOffline":"checking needs no connection","oss-knot-notgood-banner.verdictLabel":"The fair answer","oss-knot-notgood-banner.verdict":"a receipt somebody else can check","oss-knot-onebyte-banner.eyebrow":"The altered entry","oss-knot-onebyte-banner.lead":"Change one byte.","oss-knot-onebyte-banner.accent":"Then hand it over.","oss-knot-onebyte-banner.body":"The checker does not stop at a vague failure. It names the entry, the run and the first broken link so the recipient knows exactly where the record stopped agreeing with itself.","oss-knot-onebyte-banner.signature":"entry signature fails","oss-knot-onebyte-banner.root":"run root no longer matches","oss-knot-onebyte-banner.trail":"read trail locates line 04","oss-knot-onebyte-banner.verdict":"detected and located without a connection","oss-knot-outlives-banner.eyebrow":"What a change does not touch","oss-knot-outlives-banner.lead":"Change the model.","oss-knot-outlives-banner.accent":"The history still reads.","oss-knot-outlives-banner.body":"Knot records the framework and model as facts about each entry, not as the shape of the history. A new toolkit changes the producer; it does not rewrite what the run already says.","oss-knot-outlives-banner.rowFramework":"framework name and version","oss-knot-outlives-banner.rowModel":"model call and answer","oss-knot-outlives-banner.rowStorage":"bundle layout and root","oss-knot-outlives-banner.rowFormat":"exports remain readable","oss-knot-outlives-banner.rowCheck":"the same checker verdict","oss-knot-outlives-banner.verdict":"the tools get replaced; the evidence does not","oss-knot-plain-explainer.55b17716ab":"It writes things down","oss-knot-plain-explainer.9ea4581067":"When a computer helper does something for you, it notes down each thing it did, in order.","oss-knot-plain-explainer.004c8b0e83":"Like a careful shop assistant who writes every item on the receipt as it is rung up.","oss-knot-plain-explainer.2cdd72dabf":"It locks the notes together","oss-knot-plain-explainer.5f6b1d0fb8":"Each note is locked to the one before it, so the list cannot be changed without it showing.","oss-knot-plain-explainer.2cdaa84360":"Like a numbered receipt book where a missing page is obvious at a glance.","oss-knot-plain-explainer.4635b66ff1":"It signs each note","oss-knot-plain-explainer.dcb177fd2e":"Every note gets a small seal that proves it is the real one and nobody swapped it.","oss-knot-plain-explainer.4daf6b39f8":"Like a wax seal on a letter that shows it has not been opened on the way.","oss-knot-plain-explainer.05876e68a2":"Anyone can check it","oss-knot-plain-explainer.623a2326b5":"Later, a different person can look at the whole list and confirm none of it was quietly changed.","oss-knot-plain-explainer.a53fc1a7b9":"Like a second person counting the till, who does not have to trust the first.","oss-knot-projection-grid.f4a18f6113":"The folded state of a run at logical time T.","oss-knot-projection-grid.a8daace2ab":"Run · status · step","oss-knot-projection-grid.3876a97ff2":"Every branch in the run and where it forked.","oss-knot-projection-grid.1de53bc029":"Branch · parent · head","oss-knot-projection-grid.5ffdc0b83a":"Messages in order, per conversation thread.","oss-knot-projection-grid.f84c6f9617":"Thread · turn · role","oss-knot-projection-grid.a846d60714":"An index of every run the daemon has seen.","oss-knot-projection-grid.a25985f130":"Run · started · status","oss-knot-projection-grid.df05c4b909":"Token spend rolled up per run and model.","oss-knot-projection-grid.0a39fc41ff":"Model · prompt · output","oss-knot-projection-grid.b95e9f1cb6":"Each tool call paired with its result.","oss-knot-projection-grid.808e30a4a8":"Tool · input · result","oss-knot-projection-grid.d307261cc6":"Hot refresh, 1 second default","oss-knot-projection-grid.0873163245":"Same events, same bytes","oss-knot-projection-grid.currentRun":"Current run","oss-knot-projection-grid.branches":"Branches","oss-knot-projection-grid.conversation":"Conversation","oss-knot-projection-grid.runHistory":"Run history","oss-knot-projection-grid.tokenUse":"Token use","oss-knot-projection-grid.toolResults":"Tool results","oss-knot-redaction-pipeline.9f362b0b1b":"\"[REDACTED:aws:9f2a14c0]\"","oss-knot-redaction-pipeline.8123e16f72":"\"[REDACTED:email:7de0bb31]\"","oss-knot-redaction-pipeline.08a04dd04a":"18+ regexes: cloud, source control, payment, messaging, JWT, PEM, model APIs","oss-knot-redaction-pipeline.eb0c867f05":"6+ patterns: email, phone, SSN, card with Luhn, IPv4, MAC, IBAN","oss-knot-redaction-pipeline.5333869ac3":"donation_token does not match token, no substring trap","oss-knot-redaction-pipeline.7b9caadddc":"Incoming event","oss-knot-redaction-pipeline.8f020796f0":"Redactor, at ingest","oss-knot-redaction-pipeline.dd38ec3d5e":"Stored event","oss-knot-sign-flow.f4eef6b70e":"The verifier trusts no daemon. It needs only the bundle and the public key to reach a verdict.","oss-knot-sign-flow.4270780d53":"Check it offline","oss-knot-sign-flow.5912b0adea":"portable bundle","oss-knot-sign-flow.fc8f5ea229":"Produce a signed record","oss-knot-sign-flow.13217925b0":"Verify every signature and the trust-log chain, emit a JSON report.","oss-knot-sign-flow.7f6e5a6efa":"Verdict","oss-knot-sign-flow.3bbbf570cf":"Recompute every Merkle root from the raw events.","oss-knot-sign-flow.550d4d4f84":"Re-derive","oss-knot-sign-flow.6fae2edc27":"Take a bundle directory and a public key. No daemon, no network.","oss-knot-sign-flow.5838eda58e":"Open bundle","oss-knot-sign-flow.4e7a08e767":"Sign the canonical entry with the private key.","oss-knot-sign-flow.8b3d8d665a":"Sign","oss-knot-sign-flow.e5f3bfbc51":"Derive the BLAKE3 event_id over those bytes.","oss-knot-sign-flow.16586c723b":"Content hash","oss-knot-sign-flow.3f9591fd36":"Serialize the event to canonical JSON bytes, portable across languages.","oss-knot-sign-flow.de6956c7ce":"Canonicalize","oss-knot-sovereignty.31025cf2ca":"Export a portable bundle and walk away.","oss-knot-sovereignty.4cf3439273":"Anyone verifies it offline, no vendor.","oss-knot-sovereignty.31a83345a7":"The ledger is on disk you control.","oss-knot-sovereignty.fecffc37bf":"Your record","oss-knot-sovereignty.c7195e6cbc":"Leaving means losing the trail.","oss-knot-sovereignty.05e99e3a98":"You verify only through their dashboard.","oss-knot-sovereignty.443c6923fb":"Your history sits in a vendor database.","oss-knot-sovereignty.8b7fb53083":"Their record","oss-knot-sovereignty.f8f560a718":"The signing key is yours. Verification needs only the public half.","oss-knot-sovereignty.d27c6d42b2":"You hold the keys","oss-knot-sovereignty.3a06604503":"Keep the ledger inside a border you choose. Sovereignty by default.","oss-knot-sovereignty.e4dc99696a":"European region","oss-knot-sovereignty.3fa4f3f53d":"Run the daemon on your own machines, behind your own controls.","oss-knot-sovereignty.499493296b":"On premise","page-breadcrumb.c766e66518":"Breadcrumb","page-toc.7e439c353e":"On this page","section_st_a1_display-split.7c9a7c0610":"Detail","section_st_f1_cta-dark.90e40d5043":"Get started","toc-rail.f5cbdf6bfb":"Contents"}
