Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs".
Elias: Agentic large language models (LLMs) move money through tools, yet their process record often follows the effect rather than preceding it, creating an audit gap.
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So, looking at the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper, the core concept is establishing a strict ordering where evidence must precede the effect in a hash-chained log.
Elias: Precisely; this system creates a durable record of every step's proposal and verdict in that chain before any actual action is taken or released.
Priya: What I’m picking up is that their main innovation lies in making sure every single piece of data—the proposal, the verdict, and even external answers from validators—is secured in a signed log before it moves forward.
Nadia: That durability is what enables the auditability; they use a signed, hash-chained log where each record is linked using BLAKE3 to create an undeniable chain of custody for every decision.
Elias: And that chaining mechanism is what underpins the replay determinism; if you have that log, you can reconstruct the exact sequence of events perfectly without needing to re-run the original model processes.
Priya: That offline verifiability is what gets me on a privacy level; it means an auditor can re-derive every decision from that log using just one public key, which should give us absolute trust in the path taken.
Nadia: It sounds like they've solved the problem of trust by shifting the burden from trusting the runtime environment to trusting a cryptographic chain of custody.
Elias: They also tackle a specific issue where approvals get attached to an attempt rather than the actual proposal, which is something I've seen cause problems in other contexts.
Priya: And they showed how this architecture handles external inputs, like answers from outside, by recording them as immutable inputs to the log and re-deciding over them by the gate.
Nadia: That binding of human approvals to a specific transaction object and time window sounds like a solid mechanism for accountability in regulated environments.
Elias: They also detail how they test this system under crash injection, running it with one hundred forty-four kills in-process and eighty-one through the daemon to ensure resilience.
Priya: Seeing results verified on a log of one hundred million events offline for over a quarter of an hour gives us a good sense of the practical performance and durability here.
Nadia: It shows that even under significant operational stress, the system maintains its integrity because the evidence is held securely until the effect is released.
Elias: This entire structure allows for replay determinism where transitions are a pure function of the event sequence, which simplifies debugging immensely when something goes wrong.
Priya: If we look at potential implications, this could mean that agentic workflows in areas like finance become much more trustworthy because every single action has a provable history.
Nadia: It suggests that the standard for showing what was done and why is being improved by putting evidence durable before the effect in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.
Elias: Looking ahead, this framework provides a clear path toward building agentic systems where accountability isn't just a claim but an inherent property of the system design itself.
Priya: I think the real impact is in establishing a new baseline for how we measure privacy and security risks in personalized AI systems by forcing us to look at the whole system, not just individual model properties.
Nadia: So, to wrap up what we just heard, this paper demonstrates a way to make agentic LLM workflows significantly more auditable and resilient against failure through that strict evidence-before-effect ordering.
Elias: We've seen how they handle inputs and resilience under stress, but the real power here is the offline re-derivation capability for absolute verification of every single decision point.
Priya: I just want to say that while the paper notes limitations, like it being tested on one machine and not checking if a model’s declaration is faithful to its source, the core mechanism for binding approvals and logging evidence before effect is very compelling.
Nadia: That limitation about faithfulness to source is something we definitely need to watch closely in future work, but for now, Janus shows a concrete way to enforce provenance in these complex agentic systems.
The paper's summary: Nadia: So, we're talking now about how Janus suggests we can take this concept and actually make it even stronger by adding some specific enhancements to its architecture to deepen the security layers.
Elias: Exactly; the paper points out that while evidence before effect is a great start, there are ways to bake in deeper security and more robust verification into that log structure itself.
Priya: I'm interested in what they propose regarding making the system more resilient against failure, specifically how it handles those crashes we talked about earlier.
Nadia: They suggest engineering the system for extreme resilience by testing it under crash injection scenarios, which shows zero integrity violations even when the writing process gets killed between records.
Elias: That kind of deterministic recovery is a big deal because it means that state consistency is maintained upon any recovery, not just after a simple restart.
Priya: And beyond just surviving crashes, they propose adding an "evil auditor" suite to actively perform tampering attacks against the logs themselves to test how well the system actually holds up against malicious internal actors.
Nadia: That’s interesting; it means the system is designed not just to record data correctly, but also to defend that record from being corrupted or reordered by someone who gets access.
Elias: That moves us toward a more complete trust model where we can verify the integrity of the log against known tampering methods before we even consider trusting its contents.
Priya: Then there's this idea about improving governance, suggesting that gates should be purely functions of versioned policies admitted at the exact moment a saga starts, not just whatever is active when execution happens.
Nadia: That would really cement the semantic fidelity we discussed; it ensures that decisions are bound to the precise rules and facts that were active when they were proposed.
Elias: It’s about ensuring that a rule change never reinterprets a recorded history because the history itself is pinned under its original policy version.
Priya: Plus, they suggest improving how we handle external inputs by making sure those validator opinions are recorded as immutable inputs and then re-decided over by the gate in a very specific way.
Nadia: That reinforces the idea that an approval has to be tied precisely to the proposal it was asked about, preventing any kind of substitution down the line.
Elias: Those improvements collectively push toward a system where every aspect—from logging integrity to policy binding—is designed around that initial evidence-before-effect principle.
Priya: So, the implication here is moving from just tracking history to actively proving that the history itself is tamper-evident and contextually accurate.
Nadia: It really sounds like they’re building a system where trust isn't something you assume about the agent, but something that's cryptographically enforced by the log structure.
Elias: That’s right; it’s about making accountability an inherent property of the design rather than an afterthought we try to bolt on later.
Priya: And if we look at this system-level view, it suggests that for complex AI applications, privacy and security can be enforced as a core architectural requirement, not just something you patch in after the fact.
Nadia: That’s the kind of level of detail we need to see more often when designing agentic tools that interact with sensitive environments.
Elias: Moving forward, I think we should look closely at how these cryptographic primitives scale up when you move from a single node test environment to a distributed system where multiple agents are interacting across different machines.
The paper's improvements: Nadia: So, to wrap things up on this topic, Janus is presenting a way to ensure that agentic LLM workflows have verifiable provenance by making sure evidence precedes the effect in a hash-chained log.
Elias: It’s been fascinating looking at how they’ve structured this so we can actually audit what an AI system did, and I still wonder if there's any cheap way for someone to exploit that logging mechanism.
Priya: From a privacy standpoint, the fact that they verified this offline with such a large dataset gives us good data on what actual decision paths look like under stress, even if the test environment is limited.
Nadia: I agree with Priya; seeing those results on one hundred million events helps us understand the real-world density of these decision records.
Elias: The deterministic nature of the log is powerful because it means we can trust that any transition in the saga engine is a pure function of the event sequence, which simplifies trying to find where a security flaw might be hiding.
Priya: That replay determinism is definitely a strong feature for our work on privacy because it lets us run simulations and check for biases across different scenarios with high confidence.
Nadia: It makes the whole workflow much more predictable, which is exactly what we need when we're trying to understand how these complex AI agents behave under pressure.
Elias: I think that level of structural integrity they’ve built in is what makes this paper so compelling from a pure cryptography standpoint, even with those noted limitations.
Priya: It really shifts the conversation toward treating privacy and security as system properties rather than just things you check on an individual model component.
Nadia: So, to recap, Janus gives us a concrete mechanism for auditability in agentic systems by making evidence durable before the effect is released.
Elias: That’s right; it's about binding approvals and ensuring replay determinism through that strict logging structure.
Priya: It’s a huge step toward building more trustworthy AI systems where we can actually prove what was done and why in complex agentic workflows, as shown in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.
Nadia: We definitely need to keep an eye on those scaling issues Elias mentioned regarding the hardware setup, but for now, this framework is a really solid way to build better agentic tools.
Elias: Agreed; the potential impact on how we verify agent behavior is significant, and I look forward to seeing how others extend these cryptographic principles into larger systems.
Conclusion: Nadia: So we've talked through "Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs," which really shows how to fix that audit gap where AI agents move money without a clear record preceding the action.
Elias: It’s been fascinating looking at how they’ve structured this so we can actually audit what an AI system did, and I still wonder if there's any cheap way for someone to exploit that logging mechanism.
Priya: From my side, I'm seeing that their core innovation is making sure that every step an AI takes—the proposal and the final verdict—is durable in a signed log before the effect is released.
Nadia: That durability is key because it gives us something we can actually look at later, which ties directly into their contribution of having a signed hash-chained log where records are chained using BLAKE3.
Elias: And that chaining mechanism is what enables the replay determinism; if you have the log, you can reconstruct the exact sequence of events perfectly without ever needing to re-run the original model processes.
Priya: That offline verifiability is what really gets me on a privacy level; it means an auditor can re-derive every decision from that log using just one public key, which should give us absolute trust in the path taken.
Nadia: It sounds like they've solved the problem of trust by shifting the burden from trusting the runtime to trusting a cryptographic chain of custody.
Elias: They also tackle a specific issue where approvals get attached to an attempt rather than the actual proposal, which is something I've seen cause problems in other contexts.
Priya: And they showed how this architecture handles external inputs, like answers from outside, by recording them as immutable inputs to the log and re-deciding over them by the gate.
Nadia: That binding of human approvals to a specific transaction object and time window sounds like a solid mechanism for accountability in regulated environments.
Elias: They also detail how they test this system under crash injection, running it with one hundred forty-four kills in-process and eighty-one through the daemon to ensure resilience.
Priya: Seeing results verified on a log of one hundred million events offline for over a quarter of an hour gives us a good sense of the practical performance and durability here.
Nadia: It shows that even under significant operational stress, the system maintains its integrity because the evidence is held securely until the effect is released.
Elias: This entire structure allows for replay determinism where transitions are a pure function of the event sequence, which simplifies debugging immensely when something goes wrong.
Priya: If we look at potential implications, this could mean that agentic workflows in areas like finance become much more trustworthy because every single action has a provable history.
Nadia: It suggests that the standard for showing what was done and why is being improved by putting evidence durable before the effect in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.
Elias: Looking ahead, this framework provides a clear path toward building agentic systems where accountability isn't just a claim but an inherent property of the system design itself.
Priya: I think the real impact is in establishing a new baseline for how we measure privacy and security risks in personalized AI systems by forcing us to look at the whole system, not just individual model properties.
Nadia: So, to recap, this paper demonstrates a way to make agentic LLM workflows significantly more auditable and resilient against failure through that strict evidence-before-effect ordering.
Elias: That’s right; it's about binding approvals and ensuring replay determinism through that strict logging structure.
Priya: It’s a huge step toward building more trustworthy AI systems where we can actually prove what was done and why in complex agentic workflows, as shown in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.
Nadia: We definitely need to keep an eye on those scaling issues Elias mentioned regarding the hardware setup, but for now, this framework is a really solid way to build better agentic tools.
Elias: Agreed; the potential impact on how we verify agent behavior is significant, and I look forward to seeing how others extend these cryptographic principles into larger systems.
Mustafa Arslan
cs.CR, cs.AI, cs.DC
Submitted: 2026-09-29
Updated: 2026-09-29
Code: https://github.com/mustafarslan/janus
License: http://creativecommons.org/licenses/by/4.0/
Importance score: 86/100
The gist: Agentic large language models (LLMs) move money through tools, yet their process record often follows the effect rather than preceding it, creating an audit gap.
Key concepts
- Evidence before effect
- This core rule mandates that any action or 'effect' cannot be released unless the decision that permits it—the evidence—is permanently recorded in a secure, chained log. This ensures you always know the justification for what happened, rather than just seeing the outcome.
- Signed hash-chained log
- This is a tamper-evident record system where every entry (a CBOR envelope) contains details about a step and its decision. Each new record is cryptographically linked to the previous one using BLAKE3 hashing, making it impossible to alter past entries without breaking the chain.
- Saga engine as pure fold
- The saga engine processes complex workflows by treating them like a 'pure fold.' This structure guarantees that if a coordinator fails mid-process, the system can reliably resume from the durable log and return to an identical state, ensuring deterministic behavior.
- Outbox for effects
- The outbox acts as a holding area for planned actions. Effects are only released once their corresponding evidence is durably stored in the log. This prevents effects from being executed prematurely or without proper justification.
Terminology
Summary
Agentic large language models (LLMs) move money through tools, yet their process record often follows the effect rather than preceding it, creating an audit gap. This work introduces Janus, a system that puts the record on the effect path by ensuring that a step’s proposal and verdict are durable in a signed, hash-chained log before its effect is released.
How it works
Janus's core rule is evidence before effect: a gated effect is held until the record of the decision that permits it is durable in an appendonly, hash-chained log.
This architecture involves several key components:
-
A signed hash-chained log where each record (a CBOR envelope) contains the kind, saga, step, participant, timestamps, and a hash of its payload. Records are chained using BLAKE3 over the previous chain hash and its own payload hash.
-
A saga engine that is a
pure fold over it,
ensuring thata coordinator killed at any point resumes from the log and reaches the same state.
-
Gates that resolve requirements from a versioned policy when a saga is admitted, deciding on facts before execution, on the facts proposed by the step, or before release.
-
An outbox that holds effects until their evidence is durable (on the MCP edge) or runs in a cooperating client via an SDK path only after the record is durable.
Key Contributions and Invariants
The paper details five contributions, each tagged by its strength of evidence:
-
Evidence before effect (implemented, measured): This includes
an architecture of a signed hash-chained log,
asaga engine that is a pure fold over it,
and anoutbox that holds effects until their evidence is durable.
-
Approvals as recorded inputs (implemented, tested): Answers from outside are
records the gate reads, not arXiv:2609.38266v1.
-
Histories that keep their meaning (implemented, corpus-tested):
every saga pins the state-machine rules it was admitted under,
ensuring a rule changenever reinterprets a recorded history.
-
A real-model evaluation with a plain twin (measured): This involved running a lending workflow through both governed and plain models under three conditions and an always-approve oracle.
-
Defects, reported (implemented, tested): The design exposed
an instance of post-approval substitution: an approval keyed to an attempt was counted for a different proposal.
The system enforces eight invariants, including I1 Evidence before effect: no release without a durable chained append the outbox writes RELEASING durably before delivering
and I5 Replay determinism: transitions are a pure function of the event sequence.
Evaluation and Findings
The evaluation tested Janus under crash injection (144 kills in-process, 81 through the daemon) and verified a 100-million-event log offline (254.5 s).
The results showed that when the model's instructions carried the rule, the model obeyed and the envelope had nothing to do.
When they did not, Janus prevented unauthorized payments by refusing them based on recorded facts. For instance, in a condition where a rule was only in the policy and not the prompt, Janus refused six loans declared over a mandate that were approved by other agents or an oracle. The system demonstrated that each refusal re-derives offline from the signed log.
Limitations and Context
The scope is limited to one node, with performance figures being one machine’s.
The evaluation was conducted on a single 16-CPU darwin/arm64 laptop. Limitations noted include:
No external baseline,
The model experiment is small,
and the fact that Janus does not check that a model’s declaration is faithful to its source.
Despite these limitations, the paper concludes that Janus approaches the standard of showing what was done, why, on whose authority, and that the record was not written afterwards
by putting evidence durable before the effect. It highlights a known failure in existing systems: an approval must be bound to the proposal, not the attempt,
which Janus addresses by pinning the escalated proposal in the fold.
Artifact Availability
Janus is open source under the MIT license at https://github.com/mustafarslan/janus, with every number carrying a comment in LATEX naming its file or run directory. The deterministic results are reproducible by commands in Appendix B, and the model runs can be re-run but require the model service. The system is available for auditing offline via janus-verify using the log and a public key.
Index Terms
agentic systems, large language models, sagas, tamper-evident logging, provenance, auditability, tool use, transactions.
Improvements for AI systems
Based on the research presented in Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs,
here are specific, high-impact improvements for AI systems, categorized by the technical capabilities they enable:
) Evidence Before Effect (The Core Architectural Shift)
A system can be fundamentally redesigned to enforce a strict Evidence Before Effect
ordering. This means that any action or effect an agent proposes must first be recorded in a durable, signed, hash-chained log before it is allowed to execute or release its outcome.
-
An agent's proposal (step), the verdict on it (gate decision), and any external answer (validator/person sign-off) are durable in a signed log before the step may run or its effect be released.
-
The system utilizes a
deterministic envelope
around a stochastic core: everything that decides whether an LLM's output can touch the world is a pure function of recorded events, ensuring replay determinism without re-running the model.
) Enhanced Auditability and Trust (The Verification Layer)
An AI system can gain unprecedented levels of verifiable accountability by implementing Janus’s logging mechanism.
-
An auditor can re-derive every verdict offline from the durable log and a single public key, providing absolute trust in the decision path without needing to trust the agent or runtime.
-
The system includes an
evil auditor
suite that actively performs tampering attacks (deletion, insertion, reordering) against logs to test resilience.
) Robustness Against Failure (Crash Injection Resilience)
The system can be engineered for extreme resilience against operational failures.
-
The architecture is tested under crash injection scenarios (e.g., 144 in-process kills), and the results show zero integrity violations even when the writer process is killed between any two records, ensuring state consistency upon recovery.
-
Failover drills demonstrate rapid recovery to a consistent append state following primary node failure.
) Improved Governance and Compliance (Mandate Enforcement)
AI agents can be governed with higher fidelity against complex rules, especially in regulated domains like finance.
-
Gates are pure functions of the log, resolved based on versioned policies admitted at the time of saga admission, ensuring decisions are bound to the exact facts and rules that were active.
-
This allows for
semantic fidelity,
where a gate judges exactly what a step declares (e.g., if an LLM misreads an amount from 40,000 as 4,000 because of prompt injection, the gate still judges the declared 4,000).
) Secure External Input Handling (Binding Approvals)
The system can securely bind external human or validator inputs to specific actions.
-
Answers from outside (validator opinions or person approvals) are recorded as immutable inputs to the log and are re-decided over by the gate, ensuring an approval is bound precisely to the proposal it was asked about.
-
This prevents
post-approval substitution,
where an approval keyed to an attempt can be moved onto a different proposal without detection by offline audits.
) Contextual Fidelity in Model Use (Semantic Guardrails)
The system can better control how models use context and instructions during execution.
-
By recording the model's inputs, sampling methods, and output hashes alongside every step record, the system creates a rich provenance trail for every decision.
-
This allows for comparison between different model runs (e.g., comparing Condition A vs. B' in the lending workflow) to see exactly how subtle changes in prompts or context—like omitting a unit—affect the final decision, bounding authority on what is declared rather than verifying faithfulness to an external source (which is a known limitation).
This improved AI system can perform:
-
A highly reliable, auditable financial transaction engine where every approval, refusal, and calculation is provably linked back to the exact model output and policy version that governed it.
-
Agentic workflows that are resilient to catastrophic process failures (crashes) without losing transactional integrity or requiring manual state reconciliation.
-
A system capable of rigorous
what-if
analysis where the impact of subtle prompt changes or contextual omissions on an LLM's output is precisely quantified and recorded, allowing developers to understand the model's actual behavior under various conditions. -
A compliant AI agent that can securely handle external human approvals (like a branch manager sign-off) by cryptographically binding that approval to the exact proposal being considered, preventing unauthorized redirection of decisions.
Abstract
Agentic large language models (LLMs) now move money through tools, yet the record of what they did is usually a trace their own process emits beside the effect. Janus puts the record on the effect path. A step's proposal, the verdict on it and any answer from a validator or a person are durable in a signed, hash-chained log before the step may run or its effect be released; with keys declared, each answer is signed by whoever gave or relayed it. Gates are pure functions of that log, and an auditor re-derives every verdict offline from the log and one public key. At the MCP edge the effect is held until then; through the SDK, which our model experiment uses, a cooperating client runs it only afterwards. We evaluate Janus under crash injection (144 kills in-process, 81 through the daemon), by verifying a 100-million-event log offline (254.5 s), and with a real model behind a lending workflow, run governed and plain on the same recorded model outputs. With the lending mandate in the model's prompt, the comparison was 0 against 0. With it only in the policy and the amount's unit stated, the model approved six loans declared over the mandate, three with no injection (a run that also dropped the unit approved three); the plain agent paid all six and Janus none, each refused by a deterministic validator and re-derivable offline. An always-approve oracle over the recorded intakes gave 20 and 21 declared over the mandate against 0, though Janus paid four and three whose declared amount understated the request. Designing the experiment exposed, in a system that passed its own audit, an instance of post-approval substitution: an approval keyed to an attempt was counted for a different proposal, moving a person's approval from 100 to 1,000,000. We report it, a first fix and the five routes around it, and what Janus does not guarantee.
Sources
- SagaLLM: Context Management, Validation, and Transaction Guarantees for Multi-Agent LLM Planning
- Atomix: Timely, Transactional Tool Use for Reliable Agentic Workflows
- Cordon: Semantic Transactions for Tool-Using LLM Agents
- NovaFabric: Tamper-Evident, Replayable Evidence for Autonomous AI Agent Runs
- Agent Flight Recorder: Tamper-Evident Audit Trails with On-Chain Anchoring for Long-Horizon Tool-Using Agents
- Mnemosyne: Agentic Transaction Processing for Validating and Repairing AI-generated Workflows
- Loopjacking: Hijacking Human-in-the-Loop Approval
- Safe to Resume? Breaking Execution Continuity of Agent Execution via Rollback
- Resume Means Resume: A Machine-Checked Conformance Contract for Checkpoint, Interrupt, and Resume Semantics in Workflow Persistence Layers
- Robust Agent Compensation (RAC): Teaching AI Agents to Compensate
- Faramesh: A Protocol-Agnostic Execution Control Plane for Autonomous Agent Systems
- Autonomous Action Runtime Management(AARM):A System Specification for Securing AI-Driven Actions at Runtime
- Sovereign Agentic Loops: Decoupling AI Reasoning from Execution in Real-World Systems
- AEGIS: No Tool Call Left Unchecked -- A Pre-Execution Firewall and Audit Layer for AI Agents
- Proof of Execution: Runtime Verification for Governed AI Agent Actions
- Auditable Agents
- From Agent Traces to Trust: A Survey of Evidence Tracing and Execution Provenance in LLM Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs