Memory decides what your agents can see. HiveBase governs what they do.
An action receipt records what acted, why, what changed — before and after — the sources it stood on, and how to undo it. Produced automatically, for every AI-initiated change across your tools.
This is the trust grammar behind every Squad, Task, and FYI brief: approval boundaries, receipts, verification verdicts, and autonomy that's earned — never assumed.
Every action category moves through the same three stages — but what needs a person scales with the action's blast radius. A password reset and an outbound payment don't share the same gate: reversible work can graduate to auto-apply; outbound and high-blast-radius work stays held on the surfaces that own it.
Every new action category proposes before it acts. Nothing runs silently on day one.
As accuracy compounds, reversible categories graduate to auto-apply — always with a receipt.
Money, contracts, and customer-facing sends stay held on the surfaces that own them. You approve before they go out. Reversibility and blast radius set the gate — not a single switch that covers every write.
Every field below is filled in automatically, the moment the action runs — not reconstructed later from logs.
Linear priority Backlog → P0 · this cycle
Every mission ends in one honest state — never a bare “done” checkbox.
Passing checks or HiveBase-owned command output prove the reviewed head.
HiveBase reviewed the diff and risks, but executed proof is missing.
Evidence is too thin; the verdict names the exact gaps instead of over-claiming.
A new push invalidates the prior head until verification runs again.
One ladder per category. Accuracy compounds rung by rung — and slips send it back down.
Earned silent handling — archived with a receipt
Auto-applies safe merges, notifies you
Still earning trust — held on this surface
Trust threshold configurable per category
Every receipt stays — approved, corrected, or reversed, none of it disappears or gets overwritten.
Your receipts add up to an action ledger — append-only, durable, yours. Anyone can bolt an audit log onto an agent after the fact. What compounds is the record of judgment behind it: the calls your team actually made, in order, with the evidence they were made on.
Compliance-grade, if you need that word for it — but built for the founder who wants to see what happened, not a compliance team that has to be convinced nothing did.
That compounding record is what lets you stop watching — trustworthy autonomy isn't a promise, it's what a durable action ledger earns, receipt by receipt.
An action receipt is the record HiveBase attaches to every AI-initiated change: what acted, why, what changed (the before/after), the sources it stood on, and how to undo it. It's produced automatically for every action — not an audit log you have to go looking for.
Yes, for every reversible action. Each receipt carries a working undo — one click reverses the change and the receipt stays, marked reversed, so the record is never lost. Money, contracts, and customer-facing sends are held on the surfaces that own them, precisely because they can't be undone from a receipt.
Every category starts supervised — the agent proposes, you approve. Categories earn autonomy separately as accuracy compounds, and reversible ones can graduate to auto-apply-with-receipt. Outbound writes and high-blast-radius actions stay held on the surfaces that own them.
Per category, not all at once. HiveBase tracks accuracy for each action type — deduplication, stale-task archiving, priority updates — and only lets a category graduate from asking to auto-applying once it's proven itself. If accuracy slips, the category is handed back to asking. Nothing is ever granted blanket autonomy up front.
Every action's receipt names the actor, the change, the sources, and the outcome — reviewable at any time, not reconstructed after the fact from logs. Receipts accumulate into an append-only action ledger: a durable record of everything approved, corrected, and reversed.
Trustworthy autonomy is autonomy you can actually stop watching — not because nothing could go wrong, but because what's allowed to run unsupervised is scaled to what's actually at stake. A password reset and an outbound payment don't share the same gate: the axis is reversibility and consequence, not one approval switch for everything. Reversible, low-stakes categories earn the right to run silently — receipted, undoable, reviewable any time. Outbound and high-blast-radius categories stay held on the surfaces that own them.
Permalinks for the trustworthy-autonomy spine — definition-first docs agents and operators can cite.
Full index: /docs/guides/glossary
Connect your first tool. Every Squad and Task runs inside these same boundaries, from the first action.