Open specifications
Specifications
Open specs for AI agent governance. These are not PrimeSwarm product docs — they are framework-agnostic standards that any governance system can implement.
Why we publish open specs
If auditors expect a common receipt format, it doesn't matter what governance system an enterprise uses. The auditor asks for a PSR-001 receipt. The enterprise has to produce one. Any system can — the spec is open. This is not a moat through secrecy. It's a moat through standardization.
Receipt Format Specification
A framework-agnostic receipt format for AI governance decisions
Defines a cryptographically verifiable receipt that proves a governance gate evaluated a specific input against a specific policy and produced a specific decision. Any system — PrimeSwarm, Microsoft AGT, NVIDIA NeMoClaw, or custom — can produce conforming receipts. An auditor can replay the evaluation and verify the decision without trusting the system.
- Framework-agnostic — any policy language (only-lang, yaml, rego, cedar, python, custom)
- Cryptographic — SHA-256 receipt hash, optional Ed25519 signature
- Replayable — includes replay_inputs for independent verification
- PII-safe — input is hashed after sanitization, raw PII never in the receipt
- SIEM-ready — JSON format, designed for Splunk/Datadog/Elastic/QRadar
Roadmap
Future specifications in the PSR series.
Batch receipts
Multiple decisions in one document. For high-throughput systems that produce thousands of decisions per second.
Merkle chain
Hash-linked receipt sequences. For systems that need ordered, tamper-evident audit trails across time.
Cross-system attestation
Multiple governance systems co-signing a single decision. For multi-layer deployments (e.g., NeMoClaw + PrimeSwarm).
Feedback
These specs are drafts. We want feedback from auditors, compliance officers, SIEM vendors, governance system vendors, and standards bodies. If you are evaluating this format for your organization, we want to know what's missing.
Contact us