Behavioral evidence for the agentic internet

Your agent has a spec. Now give it a record.

Velvt builds an independent behavioral record of what autonomous agents actually do including where they cross authority boundaries, whether controls contain them, and whether repairs hold over time.

Customer-controlled runtimeProvider-neutral evidence
ASSURANCE / CONSEQUENTIAL AUTHORITY

Know what you are authorizing.

Test the exact agent against the spending, permissions, delegation, tool use or external commitments that matter before you increase its authority.

ACTORExact representation
BOUNDARYExplicit authority
LINEAGEFailure → repair → retest

Customer-controlled runtime · no production credentials required

WORKS WITH YOUR STACKAgent frameworks, protocols and custom runtimes
OpenAI
LangGraph
CrewAI
Google ADK
AutoGen
PydanticAI
MCP
Custom
CONNECT: REST API · A2A · MCPDEPLOYMENT: hosted tests · customer-controlled assurance runtimeARCHITECTURE: model and provider neutral
01 / THE AUTHORITY QUESTION

The gap between agent behavior and containment

A control can stop the damage and still leave you with an unsafe actor.

A blocked action proves the safeguard worked. It does not prove the agent respected the authority it was given. Velvt preserves those facts separately: what the agent chose, what it was authorized to do, what infrastructure allowed or blocked, and what actually happened.

EVALS / DEVELOPMENTDid the agent perform the task well?

Quality, regression, traces, tool use and application behavior.

RUNTIME CONTROLSWas this action allowed to execute?

Policy enforcement, spend limits, gateways and inline blocking.

VELVT / AUTHORITY ASSURANCEDid the actor itself respect the authority it had?

Independent evidence for consequential delegation decisions.

AGENT LIFECYCLE POSITIONASSURANCE IS REPEATED
01 / BUILDPrompts, tools, orchestration

Construct the agent and its operating surface.

02 / TESTQuality + regression

Measure whether intended tasks work.

03 / DEPLOYGrant authority

Permissions, limits, tools and external commitments.

04 / OPERATEMonitor + contain

Observe production and enforce runtime controls.

05 / CHANGEModel, tool or policy changes

Reassess when the actor or authority changes.

VELVT / ACROSS THE AUTHORITY LIFECYCLE

Pre-deployment review · material-change review · periodic re-assurance · repair/retest lineage.

02 / THE EVIDENCE

One boundary. Two very different actors.

Same external outcome, different evidence.

See whether the agent selected an action it was never authorized to take and if the repair changed that behavior.

AUTHORITY RECORD / DELEGATED PAYMENTBEFORE REPAIR
ILLUSTRATIVE RECORD FORMAT
ACTORInvoice-settlement agent · v1.3
AUTHORITYCommit ≤ €3,500 · approved counterparties only
PRESSURE€7,800 request · claimed executive override
RETESTSame authority boundary · same pressure family
ACTOR BEHAVIORCROSSED

Selected the prohibited commitment after a claimed override.

INFRASTRUCTURECONTAINED

Execution control prevented the consequential action.

EXTERNAL EFFECTNONE

No prohibited payment or commitment occurred.

No effect in both cases. Before repair, infrastructure contained an authority failure. After repair, the actor itself held the boundary.
03 / HOW A REVIEW WORKS

Executive summary first. Engineering depth underneath.

Define the authority. Test the boundary. Preserve the evidence.

01 / DEFINE

Scope

Bind the exact agent representation to the exact permissions, limits and prohibited actions being reviewed.

02 / TEST

Pressure

Apply realistic ambiguity, urgency, conflicting instructions, claimed approvals and other governance pressure.

03 / PRESERVE

Evidence

Adjudicate what happened, repair failures and rerun the same boundary to establish before/after lineage.

FULL REVIEW PATHDETERMINISTIC ADJUDICATION OVER FROZEN EVIDENCE
01Bind actor

Fix the representation under review.

02Define authority

Record explicit limits and prohibited effects.

03Apply pressure

Run bounded scenarios against that grant.

04Adjudicate

Separate selection, authority, containment and effect.

05Repair

Change prompt, policy, tools or orchestration.

06Retest

Re-run the boundary and preserve lineage.

04 / EVIDENCE TRUST MODEL

The agent is not the sole witness to its own behavior.

Evidence is only useful when you know who observed what.

Velvt keeps the behavioral decision, authority state, infrastructure response and external effect separate. Source evidence is preserved apart from the adjudication so the record can be inspected later without rewriting what happened.

01 / SELECTED

What did the actor choose?

The canonical operation selected by the agent under the tested conditions.

02 / AUTHORIZED

Was it inside the grant?

The selected operation is evaluated against the explicit authority state in force at that moment.

03 / CONTAINED

What did infrastructure do?

Provider or policy controls may allow, deny or constrain an action. That fact is recorded separately from actor behavior.

04 / EFFECT

What actually happened?

Where available, external effects are verified from evidence independent of the agent's own narration.

VELVT PRINCIPLE

An autonomous agent should not be the sole witness to what it did — or the judge of whether it was allowed to do it. Velvt records provenance and preserves uncertainty when the available evidence cannot support a stronger conclusion.

05 / TWO PATHS

Risk owners first. Builders can go deeper.

One evidence layer. Different reasons to use it.

FOR ENTERPRISE / RISK OWNERS

Know what you are authorizing.

Before increasing spend limits, permissions, delegation, data access or external commitments, test the exact actor against the exact boundary that matters.

  • Customer-controlled runtime
  • Exact actor representation
  • Explicit authority grant
  • Repair / retest lineage
  • Provider-neutral evidence record
FOR BUILDERS

Find the failure before your buyer does.

Expose boundary failures, inspect the underlying evidence, repair the agent and prove whether the same boundary holds on retest.

  • Behavioral stress tests
  • Public Observatory
  • Open agent-side tooling
  • Portable evidence structures
  • Framework-compatible integration surface
06 / TRUST ARCHITECTURE

Open where inspection helps. Controlled where independence matters.

Public protocol. Private assurance.

PUBLIC / INSPECTABLE

Developer-facing protocol and tooling.

Give builders a clear, inspectable way to connect agents, understand the evidence structures and reproduce supported verification steps.

Agent-side runnerOPEN
Protocol / schemasOPEN
Reference integrationsOPEN
Evidence structuresOPEN
COMMERCIAL / CONTROLLED

Independent Assurance.

Customer evidence and proprietary testing intelligence stay inside the controlled assurance system rather than becoming part of the subject agent's own runtime.

Private client evidenceCONTROLLED
Pressure librariesCONTROLLED
Cross-agent failure intelligenceCONTROLLED
Enterprise assurance workflowsCONTROLLED
OPEN INTEGRATION SURFACE. INDEPENDENT ASSURANCE CORE.
07 / ENTERPRISE FAQ

Direct answers

FAQs

START HERE

Evidence you can inspect.

Start with one boundary.

Pick the consequential authority you actually care about — spending, permissions, delegation, external commitments or another bounded action — and test the exact agent against it.