Live demo
babit
Proof of what an AI agent did, and who allowed it.
I designed and built it on my own, from the architecture to the live demo.
- Role
- Sole author
- Context
- Personal project, source-available
- Duration
- About a month
- When
- 2026
What I did
- Designed signed capability grants where each delegated grant can only narrow its parent, checked for expiry and revocation on every action.
- Built a notary that seals actions into an append-only ledger, with a Postgres trigger that rejects any update or delete.
- Built 10 gRPC services with a REST gateway and a React console, plus an end-to-end test that tampers with a receipt to prove verification fails.
Owned end to end
The whole system
- Architecture doc
- Schema and migrations
- gRPC services
- REST gateway
- React console
- End-to-end tests
- Deployed demo
Sole author, from the architecture document to the live demo.
Impact
Live demo and public source; receipts verify offline with the babit verify command against the notary's public key and the session's Merkle root.

When things go wrong
When someone asks who allowed an agent to do that,
every action carries the signed grant that permitted it, and its receipt verifies without my server.
When a receipt is shared outside the company,
identifiers are 64-bit random values, so one receipt can't be used to guess others.
Built with
Go, gRPC, PostgreSQL, React, TypeScript