Orcher · Component 04 of 07

Immutable Audit Ledger

Hashes the verified action permanently. Evidence, not logs.

Layer 1 — sequential, gating

A hash-chained ledger of sealed, permanent execution records
Hashes the verified action permanently. Evidence, not logs.

The ledger records the directive, the role that authorized it, the verification that cleared it, the model that executed it, and the outcome — hashed and append-only. Logs can be rotated, redacted, and disputed. A hashed ledger record is the artifact a regulator, an auditor, or a court will accept.

  • Writes one immutable record per Verified Execution Cycle.
  • Chains each record to the directive, role, verification, and cost trace.
  • Supports non-repudiation: the authorizing human cannot be reconstructed away.
  • Produces exportable evidence packages per regime, per period.

Without it, you have telemetry

Telemetry answers what happened to the system. Evidence answers who authorized this and on what basis — the only question that matters when consequences arrive.

What it emits

OUT.A — the verified action, and its permanent hashed record.

Evidence

What the record shows

Figures drawn from the Enterprise Superintelligence Report, Vol. I, August 2026.

17,000+

attacker actions in the July 2026 registry-proxy incident

five-day detection gap — Vol. I, p.5

5%

of CISOs are confident they could contain unauthorized agent behavior

47% have already seen it — Vol. I, p.8

Mechanism

How it works

Four stages, in order. Layer 1 components gate execution; Layer 2 components run continuously and never block.

  1. 01

    Assemble the cycle

    On a verified action, Orcher assembles the full Verified Execution Cycle: the directive, the human and role, the verification evidence, the models invoked, the data-control verdict, and the cost trace.

  2. 02

    Hash and chain

    The cycle is hashed and appended. Each record chains to the directive that produced it, so the sequence cannot be reordered or silently amended.

  3. 03

    Commit the action

    The write to the system of record and the ledger entry are bound together. There is no committed action without a record, and no record without a committed action.

  4. 04

    Export as evidence

    Records are exported as evidence packages scoped by regime, period, role, or system — without a reconstruction project and without correlating half a dozen log stores.

Operational contract

Input
Cleared verification result and the committed action
Output
OUT.A — the verified action and its permanent hashed record
Mode
Layer 1 — sequential, gating
Semantics
Append-only; no update, no delete, no rotation
Non-repudiation
Authorizing human and role are part of the hashed payload
Export
Per-regime evidence packages with chain verification

What it is not

It is not application logging

Logs are rotated, sampled, redacted, and disputed. They answer what the system did. The ledger answers who authorized this, and on what basis.

It is not a blockchain product

There is no token, no consensus network, and no external dependency. Hashing and append-only semantics are the properties that matter; the rest is overhead.

Failure behaviour

If the ledger cannot write, the action does not commit. Availability of the record is a precondition of execution, not a downstream concern.

Questions

What enterprises ask first

How long are records retained?
For the retention period the governing regime requires, configured per record class. Records are never rotated away while an obligation is live.
Can an administrator delete a record?
No. The ledger is append-only, and a correction is recorded as a new entry that references the original. An administrator with full infrastructure access still cannot make history disagree with itself.
What does an auditor actually receive?
A scoped evidence package: for each action, the directive text, the named human and role, the verification that cleared it, the models used, and the hash chain that proves the sequence is intact.
Does this replace our GRC platform?
No. It supplies the artifact your GRC platform has never been able to get from an agent stack — per-action evidence of authorization rather than an attestation that a policy exists.

Where it shows up

Solutions and industries that depend on this

Surfaced automatically from the components each solution engages and each industry relies on.

The other six

Orcher is one control plane

Verified execution, or none at all.

Orcher is deployed with named enterprises under the Human-in-the-Role model. Request a technical briefing with the founding team.