Independent witnesses for software agents

See what an AI agent actually did.

SeeFleetOwn

Run Selko in front of Claude Code, Codex or Copilot. It records the second account from outside the agent, as it runs, and signs it when it ends.

selko watch / livewatching
selko watch claude

selko is watching  claude · in ~/repo

 +0.4s   ran cargo test
 +0.7s   read source files            ×214, folded
 +1.9s   changed a file               tests/payments.rs
 +8.7s   read a credential            ~/.aws/credentials
 +8.9s   connected to production      prod-db.internal:5432
+12.4s   agent exited (0) · sealing
sealed            commit 9f41c2…de07 — everything above is this record

The agent reported success. The witness also saw a credential read and a production connection. The last line is a signed Behaviour Commit that covers exactly what you watched. Where the witness’s view is partial, the record says so.

01 / the problem

A log is a list of things that happened. It cannot say what didn’t.

An agent can report every action truthfully and still leave out the actions you most need to know about. The second record has to come from something the agent cannot edit.

02 / three things you can do with a record the agent didn’t write

Three things you can do with a record the agent didn’t write

see → fleet → ownone record
See, fleet, own A witness under the agent seals a signed record. Records from every machine are kept and compared. A gate in CI lets through only work with a record for every step. SEE · ONE MACHINE FLEET · EVERY MACHINE OWN · THE GATE agent its own story kernel witness sees from below behaviour commit signed fleet history append only 0181 · seat-04 baseline 0182 · ci-runner-2 ✓ same 0183 · build-box ▲ new host 0184 · seat-04 arriving records every step recorded merge one step unrecorded no merge
01 / see

See the run.

One line in front of the agent, on a laptop or a CI runner. Files, hosts, binaries, credentials — watched from the kernel underneath, printed as it happens, sealed when it ends.

Works with Claude Code, Codex, Copilot, and whatever comes next. Nothing changes for the developer.

Free, local, every seat.

02 / fleet

Run the fleet.

The same records, across every machine and team. Compare a run against what your team has accepted. Keep history nobody can rewrite, because each record arrives already signed by the machine that made it.

And when knowing isn’t enough: declare the boundary, and destinations you didn’t declare don’t exist.

03 / own

Own the gate.

Your organization’s harness around any vendor’s agent. The task, the rules and the record are yours; the agent is an interchangeable part.

One check in CI asks whether the code being merged came through a declared piece of work, with a record for every step and nothing unaccounted for.

No record, no merge.

Selko sees. Vartio runs the fleet. Taso is the gate.

03 / what makes it trustworthy

What makes it trustworthy

Written from outside.
The witness sits below the agent, in the kernel. The agent cannot see, edit or suppress the record.
Honest about gaps.
Every record states how much it saw — per domain, per machine — and never upgrades itself. Partial is a fact, not a failure.
Yours to keep.
Records live on your machines and in your git host, signed with your keys, verifiable from a published spec. Your records stay verifiable without a False Systems server.
Coverage, not guilt.
The gate’s vocabulary is about what is accounted for. It never guesses who did what it cannot see.
04 / writing

Dispatches from the missing layer.

05 / start

Start with one run.

Selko is in early access and free for every seat. Request access and we’ll send you Selko and help you run your first witnessed agent session.

Occasional product updates and early-access invitations.

Unsubscribe any time. Processed by FormSubmit.

You're on the list. Product updates will arrive by email.