Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs

summary

Video file (mp4)

The gist

Agentic large language models (LLMs) move money through tools, yet their process record often follows the effect rather than preceding it, creating an audit gap.

In short

Janus is a system designed to fix an audit gap in agentic LLMs by ensuring evidence precedes action. It implements a signed, hash-chained log where proposals and verdicts are recorded durably before any effect is released. This creates verifiable provenance, preventing unauthorized actions by tying approvals directly to specific proposals.

Key concepts

Evidence before effect
This core rule mandates that any action or 'effect' cannot be released unless the decision that permits it—the evidence—is permanently recorded in a secure, chained log. This ensures you always know the justification for what happened, rather than just seeing the outcome.
Signed hash-chained log
This is a tamper-evident record system where every entry (a CBOR envelope) contains details about a step and its decision. Each new record is cryptographically linked to the previous one using BLAKE3 hashing, making it impossible to alter past entries without breaking the chain.
Saga engine as pure fold
The saga engine processes complex workflows by treating them like a 'pure fold.' This structure guarantees that if a coordinator fails mid-process, the system can reliably resume from the durable log and return to an identical state, ensuring deterministic behavior.
Outbox for effects
The outbox acts as a holding area for planned actions. Effects are only released once their corresponding evidence is durably stored in the log. This prevents effects from being executed prematurely or without proper justification.

Terminology used across episodes

This episode discusses

The paper

Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs · Read on arXiv

Mustafa Arslan

Agentic large language models (LLMs) now move money through tools, yet the record of what they did is usually a trace their own process emits beside the effect. Janus puts the record on the effect path. A step's proposal, the verdict on it and any answer from a validator or a person are durable in a signed, hash-chained log before the step may run or its effect be released; with keys declared, each answer is signed by whoever gave or relayed it. Gates are pure functions of that log, and an auditor re-derives every verdict offline from the log and one public key. At the MCP edge the effect is held until then; through the SDK, which our model experiment uses, a cooperating client runs it only afterwards. We evaluate Janus under crash injection (144 kills in-process, 81 through the daemon), by verifying a 100-million-event log offline (254.5 s), and with a real model behind a lending workflow, run governed and plain on the same recorded model outputs. With the lending mandate in the model's prompt, the comparison was 0 against 0. With it only in the policy and the amount's unit stated, the model approved six loans declared over the mandate, three with no injection (a run that also dropped the unit approved three); the plain agent paid all six and Janus none, each refused by a deterministic validator and re-derivable offline. An always-approve oracle over the recorded intakes gave 20 and 21 declared over the mandate against 0, though Janus paid four and three whose declared amount understated the request. Designing the experiment exposed, in a system that passed its own audit, an instance of post-approval substitution: an approval keyed to an attempt was counted for a different proposal, moving a person's approval from 100 to 1,000,000. We report it, a first fix and the five routes around it, and what Janus does not guarantee.

Transcript

Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.

Nadia: Today's paper: "Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs".

Elias: Agentic large language models (LLMs) move money through tools, yet their process record often follows the effect rather than preceding it, creating an audit gap.

Nadia: First, who's behind it and why it matters.

Title and authors: Nadia: So, looking at the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper, the core concept is establishing a strict ordering where evidence must precede the effect in a hash-chained log.

Elias: Precisely; this system creates a durable record of every step's proposal and verdict in that chain before any actual action is taken or released.

Priya: What I’m picking up is that their main innovation lies in making sure every single piece of data—the proposal, the verdict, and even external answers from validators—is secured in a signed log before it moves forward.

Nadia: That durability is what enables the auditability; they use a signed, hash-chained log where each record is linked using BLAKE3 to create an undeniable chain of custody for every decision.

Elias: And that chaining mechanism is what underpins the replay determinism; if you have that log, you can reconstruct the exact sequence of events perfectly without needing to re-run the original model processes.

Priya: That offline verifiability is what gets me on a privacy level; it means an auditor can re-derive every decision from that log using just one public key, which should give us absolute trust in the path taken.

Nadia: It sounds like they've solved the problem of trust by shifting the burden from trusting the runtime environment to trusting a cryptographic chain of custody.

Elias: They also tackle a specific issue where approvals get attached to an attempt rather than the actual proposal, which is something I've seen cause problems in other contexts.

Priya: And they showed how this architecture handles external inputs, like answers from outside, by recording them as immutable inputs to the log and re-deciding over them by the gate.

Nadia: That binding of human approvals to a specific transaction object and time window sounds like a solid mechanism for accountability in regulated environments.

Elias: They also detail how they test this system under crash injection, running it with one hundred forty-four kills in-process and eighty-one through the daemon to ensure resilience.

Priya: Seeing results verified on a log of one hundred million events offline for over a quarter of an hour gives us a good sense of the practical performance and durability here.

Nadia: It shows that even under significant operational stress, the system maintains its integrity because the evidence is held securely until the effect is released.

Elias: This entire structure allows for replay determinism where transitions are a pure function of the event sequence, which simplifies debugging immensely when something goes wrong.

Priya: If we look at potential implications, this could mean that agentic workflows in areas like finance become much more trustworthy because every single action has a provable history.

Nadia: It suggests that the standard for showing what was done and why is being improved by putting evidence durable before the effect in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.

Elias: Looking ahead, this framework provides a clear path toward building agentic systems where accountability isn't just a claim but an inherent property of the system design itself.

Priya: I think the real impact is in establishing a new baseline for how we measure privacy and security risks in personalized AI systems by forcing us to look at the whole system, not just individual model properties.

Nadia: So, to wrap up what we just heard, this paper demonstrates a way to make agentic LLM workflows significantly more auditable and resilient against failure through that strict evidence-before-effect ordering.

Elias: We've seen how they handle inputs and resilience under stress, but the real power here is the offline re-derivation capability for absolute verification of every single decision point.

Priya: I just want to say that while the paper notes limitations, like it being tested on one machine and not checking if a model’s declaration is faithful to its source, the core mechanism for binding approvals and logging evidence before effect is very compelling.

Nadia: That limitation about faithfulness to source is something we definitely need to watch closely in future work, but for now, Janus shows a concrete way to enforce provenance in these complex agentic systems.

The paper's summary: Nadia: So, we're talking now about how Janus suggests we can take this concept and actually make it even stronger by adding some specific enhancements to its architecture to deepen the security layers.

Elias: Exactly; the paper points out that while evidence before effect is a great start, there are ways to bake in deeper security and more robust verification into that log structure itself.

Priya: I'm interested in what they propose regarding making the system more resilient against failure, specifically how it handles those crashes we talked about earlier.

Nadia: They suggest engineering the system for extreme resilience by testing it under crash injection scenarios, which shows zero integrity violations even when the writing process gets killed between records.

Elias: That kind of deterministic recovery is a big deal because it means that state consistency is maintained upon any recovery, not just after a simple restart.

Priya: And beyond just surviving crashes, they propose adding an "evil auditor" suite to actively perform tampering attacks against the logs themselves to test how well the system actually holds up against malicious internal actors.

Nadia: That’s interesting; it means the system is designed not just to record data correctly, but also to defend that record from being corrupted or reordered by someone who gets access.

Elias: That moves us toward a more complete trust model where we can verify the integrity of the log against known tampering methods before we even consider trusting its contents.

Priya: Then there's this idea about improving governance, suggesting that gates should be purely functions of versioned policies admitted at the exact moment a saga starts, not just whatever is active when execution happens.

Nadia: That would really cement the semantic fidelity we discussed; it ensures that decisions are bound to the precise rules and facts that were active when they were proposed.

Elias: It’s about ensuring that a rule change never reinterprets a recorded history because the history itself is pinned under its original policy version.

Priya: Plus, they suggest improving how we handle external inputs by making sure those validator opinions are recorded as immutable inputs and then re-decided over by the gate in a very specific way.

Nadia: That reinforces the idea that an approval has to be tied precisely to the proposal it was asked about, preventing any kind of substitution down the line.

Elias: Those improvements collectively push toward a system where every aspect—from logging integrity to policy binding—is designed around that initial evidence-before-effect principle.

Priya: So, the implication here is moving from just tracking history to actively proving that the history itself is tamper-evident and contextually accurate.

Nadia: It really sounds like they’re building a system where trust isn't something you assume about the agent, but something that's cryptographically enforced by the log structure.

Elias: That’s right; it’s about making accountability an inherent property of the design rather than an afterthought we try to bolt on later.

Priya: And if we look at this system-level view, it suggests that for complex AI applications, privacy and security can be enforced as a core architectural requirement, not just something you patch in after the fact.

Nadia: That’s the kind of level of detail we need to see more often when designing agentic tools that interact with sensitive environments.

Elias: Moving forward, I think we should look closely at how these cryptographic primitives scale up when you move from a single node test environment to a distributed system where multiple agents are interacting across different machines.

The paper's improvements: Nadia: So, to wrap things up on this topic, Janus is presenting a way to ensure that agentic LLM workflows have verifiable provenance by making sure evidence precedes the effect in a hash-chained log.

Elias: It’s been fascinating looking at how they’ve structured this so we can actually audit what an AI system did, and I still wonder if there's any cheap way for someone to exploit that logging mechanism.

Priya: From a privacy standpoint, the fact that they verified this offline with such a large dataset gives us good data on what actual decision paths look like under stress, even if the test environment is limited.

Nadia: I agree with Priya; seeing those results on one hundred million events helps us understand the real-world density of these decision records.

Elias: The deterministic nature of the log is powerful because it means we can trust that any transition in the saga engine is a pure function of the event sequence, which simplifies trying to find where a security flaw might be hiding.

Priya: That replay determinism is definitely a strong feature for our work on privacy because it lets us run simulations and check for biases across different scenarios with high confidence.

Nadia: It makes the whole workflow much more predictable, which is exactly what we need when we're trying to understand how these complex AI agents behave under pressure.

Elias: I think that level of structural integrity they’ve built in is what makes this paper so compelling from a pure cryptography standpoint, even with those noted limitations.

Priya: It really shifts the conversation toward treating privacy and security as system properties rather than just things you check on an individual model component.

Nadia: So, to recap, Janus gives us a concrete mechanism for auditability in agentic systems by making evidence durable before the effect is released.

Elias: That’s right; it's about binding approvals and ensuring replay determinism through that strict logging structure.

Priya: It’s a huge step toward building more trustworthy AI systems where we can actually prove what was done and why in complex agentic workflows, as shown in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.

Nadia: We definitely need to keep an eye on those scaling issues Elias mentioned regarding the hardware setup, but for now, this framework is a really solid way to build better agentic tools.

Elias: Agreed; the potential impact on how we verify agent behavior is significant, and I look forward to seeing how others extend these cryptographic principles into larger systems.

Conclusion: Nadia: So we've talked through "Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs," which really shows how to fix that audit gap where AI agents move money without a clear record preceding the action.

Elias: It’s been fascinating looking at how they’ve structured this so we can actually audit what an AI system did, and I still wonder if there's any cheap way for someone to exploit that logging mechanism.

Priya: From my side, I'm seeing that their core innovation is making sure that every step an AI takes—the proposal and the final verdict—is durable in a signed log before the effect is released.

Nadia: That durability is key because it gives us something we can actually look at later, which ties directly into their contribution of having a signed hash-chained log where records are chained using BLAKE3.

Elias: And that chaining mechanism is what enables the replay determinism; if you have the log, you can reconstruct the exact sequence of events perfectly without ever needing to re-run the original model processes.

Priya: That offline verifiability is what really gets me on a privacy level; it means an auditor can re-derive every decision from that log using just one public key, which should give us absolute trust in the path taken.

Nadia: It sounds like they've solved the problem of trust by shifting the burden from trusting the runtime to trusting a cryptographic chain of custody.

Elias: They also tackle a specific issue where approvals get attached to an attempt rather than the actual proposal, which is something I've seen cause problems in other contexts.

Priya: And they showed how this architecture handles external inputs, like answers from outside, by recording them as immutable inputs to the log and re-deciding over them by the gate.

Nadia: That binding of human approvals to a specific transaction object and time window sounds like a solid mechanism for accountability in regulated environments.

Elias: They also detail how they test this system under crash injection, running it with one hundred forty-four kills in-process and eighty-one through the daemon to ensure resilience.

Priya: Seeing results verified on a log of one hundred million events offline for over a quarter of an hour gives us a good sense of the practical performance and durability here.

Nadia: It shows that even under significant operational stress, the system maintains its integrity because the evidence is held securely until the effect is released.

Elias: This entire structure allows for replay determinism where transitions are a pure function of the event sequence, which simplifies debugging immensely when something goes wrong.

Priya: If we look at potential implications, this could mean that agentic workflows in areas like finance become much more trustworthy because every single action has a provable history.

Nadia: It suggests that the standard for showing what was done and why is being improved by putting evidence durable before the effect in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.

Elias: Looking ahead, this framework provides a clear path toward building agentic systems where accountability isn't just a claim but an inherent property of the system design itself.

Priya: I think the real impact is in establishing a new baseline for how we measure privacy and security risks in personalized AI systems by forcing us to look at the whole system, not just individual model properties.

Nadia: So, to recap, this paper demonstrates a way to make agentic LLM workflows significantly more auditable and resilient against failure through that strict evidence-before-effect ordering.

Elias: That’s right; it's about binding approvals and ensuring replay determinism through that strict logging structure.

Priya: It’s a huge step toward building more trustworthy AI systems where we can actually prove what was done and why in complex agentic workflows, as shown in the Janus: Evidence-Before-Effect Sagas and Offline-Verifiable Provenance for Agentic LLMs paper.

Nadia: We definitely need to keep an eye on those scaling issues Elias mentioned regarding the hardware setup, but for now, this framework is a really solid way to build better agentic tools.

Elias: Agreed; the potential impact on how we verify agent behavior is significant, and I look forward to seeing how others extend these cryptographic principles into larger systems.

More episodes

← Home