Memory decides what your agents can see. HiveBase governs what they do.
An action receipt records what acted, why, what changed — before and after — the sources it stood on, and how to undo it. Produced automatically, for every AI-initiated change across your tools.
This is the trust grammar behind every Squad, Task, and FYI brief: approval boundaries, receipts, verification verdicts, and autonomy that's earned — never assumed.
Every action category moves through the same three stages — but what needs a person scales with the action's blast radius. A password reset and an outbound payment don't share the same gate: reversible work can graduate to auto-apply; irreversible work never does.
Every new action category proposes before it acts. Nothing runs silently on day one.
As accuracy compounds, reversible categories graduate to auto-apply — always with a receipt.
Money, contracts, customer-facing sends, and anything irreversible always wait for you — permanently, not just at launch.
Every field below is filled in automatically, the moment the action runs — not reconstructed later from logs.
Linear priority Backlog → P0 · this cycle
Every mission ends in one honest state — never a bare “done” checkbox.
Passing checks or HiveBase-owned command output prove the reviewed head.
HiveBase reviewed the diff and risks, but executed proof is missing.
Evidence is too thin; the verdict names the exact gaps instead of over-claiming.
A new push invalidates the prior head until verification runs again.
One ladder per category. Accuracy compounds rung by rung — and slips send it back down.
97% accuracy over 60 days — handles silently
91% accuracy — auto-applies safe merges, notifies you
Still earning trust — always asks
Accuracy figures illustrative — trust threshold configurable per category
Every receipt stays — approved, corrected, or reversed, none of it disappears or gets overwritten.
Your receipts add up to an action ledger — append-only, durable, yours. Anyone can bolt an audit log onto an agent after the fact. What compounds is the record of judgment behind it: the calls your team actually made, in order, with the evidence they were made on.
Compliance-grade, if you need that word for it — but built for the founder who wants to see what happened, not a compliance team that has to be convinced nothing did.
That compounding record is what lets you stop watching — trustworthy autonomy isn't a promise, it's what a durable action ledger earns, receipt by receipt.
An action receipt is the record HiveBase attaches to every AI-initiated change: what acted, why, what changed (the before/after), the sources it stood on, and how to undo it. It's produced automatically for every action — not an audit log you have to go looking for.
Yes, for every reversible action. Each receipt carries a working undo — one click reverses the change and the receipt stays, marked reversed, so the record is never lost. Irreversible categories (money, contracts, customer-facing sends) require your approval before they run at all, precisely because they can't be undone.
Every category starts supervised — the agent proposes, you approve. Categories earn autonomy separately as accuracy compounds, and reversible ones can graduate to auto-apply-with-receipt. One-way doors (irreversible, high-stakes, or customer-facing) always wait for a human, no matter how long the system has been running.
Per category, not all at once. HiveBase tracks accuracy for each action type — deduplication, stale-task archiving, priority updates — and only lets a category graduate from asking to auto-applying once it's proven itself. If accuracy slips, the category is handed back to asking. Nothing is ever granted blanket autonomy up front.
Every action's receipt names the actor, the change, the sources, and the outcome — reviewable at any time, not reconstructed after the fact from logs. Receipts accumulate into an append-only action ledger: a durable record of everything approved, corrected, and reversed.
Trustworthy autonomy is autonomy you can actually stop watching — not because nothing could go wrong, but because what's allowed to run unsupervised is scaled to what's actually at stake. A password reset and an outbound payment don't share the same gate: the axis is reversibility and consequence, not one approval switch for everything. Reversible, low-stakes categories earn the right to run silently — receipted, undoable, reviewable any time. Anything that can't be undone always waits for you.
Permalinks for the trustworthy-autonomy spine — definition-first docs agents and operators can cite.
Full index: /docs/guides/glossary
Connect your first tool. Every Squad and Task runs inside these same boundaries, from the first action.