Orcher · Component 04 of 07
Immutable Audit Ledger
Hashes the verified action permanently. Evidence, not logs.
Layer 1 — sequential, gating

The ledger records the directive, the role that authorized it, the verification that cleared it, the model that executed it, and the outcome — hashed and append-only. Logs can be rotated, redacted, and disputed. A hashed ledger record is the artifact a regulator, an auditor, or a court will accept.
- Writes one immutable record per Verified Execution Cycle.
- Chains each record to the directive, role, verification, and cost trace.
- Supports non-repudiation: the authorizing human cannot be reconstructed away.
- Produces exportable evidence packages per regime, per period.
Without it, you have telemetry
Telemetry answers what happened to the system. Evidence answers who authorized this and on what basis — the only question that matters when consequences arrive.
What it emits
OUT.A — the verified action, and its permanent hashed record.
Evidence
What the record shows
Figures drawn from the Enterprise Superintelligence Report, Vol. I, August 2026.
17,000+
attacker actions in the July 2026 registry-proxy incident
five-day detection gap — Vol. I, p.5
5%
of CISOs are confident they could contain unauthorized agent behavior
47% have already seen it — Vol. I, p.8
Mechanism
How it works
Four stages, in order. Layer 1 components gate execution; Layer 2 components run continuously and never block.
01
Assemble the cycle
On a verified action, Orcher assembles the full Verified Execution Cycle: the directive, the human and role, the verification evidence, the models invoked, the data-control verdict, and the cost trace.
02
Hash and chain
The cycle is hashed and appended. Each record chains to the directive that produced it, so the sequence cannot be reordered or silently amended.
03
Commit the action
The write to the system of record and the ledger entry are bound together. There is no committed action without a record, and no record without a committed action.
04
Export as evidence
Records are exported as evidence packages scoped by regime, period, role, or system — without a reconstruction project and without correlating half a dozen log stores.
Operational contract
- Input
- Cleared verification result and the committed action
- Output
- OUT.A — the verified action and its permanent hashed record
- Mode
- Layer 1 — sequential, gating
- Semantics
- Append-only; no update, no delete, no rotation
- Non-repudiation
- Authorizing human and role are part of the hashed payload
- Export
- Per-regime evidence packages with chain verification
What it is not
It is not application logging
Logs are rotated, sampled, redacted, and disputed. They answer what the system did. The ledger answers who authorized this, and on what basis.
It is not a blockchain product
There is no token, no consensus network, and no external dependency. Hashing and append-only semantics are the properties that matter; the rest is overhead.
Failure behaviour
If the ledger cannot write, the action does not commit. Availability of the record is a precondition of execution, not a downstream concern.
Questions
What enterprises ask first
- How long are records retained?
- For the retention period the governing regime requires, configured per record class. Records are never rotated away while an obligation is live.
- Can an administrator delete a record?
- No. The ledger is append-only, and a correction is recorded as a new entry that references the original. An administrator with full infrastructure access still cannot make history disagree with itself.
- What does an auditor actually receive?
- A scoped evidence package: for each action, the directive text, the named human and role, the verification that cleared it, the models used, and the hash chain that proves the sequence is intact.
- Does this replace our GRC platform?
- No. It supplies the artifact your GRC platform has never been able to get from an agent stack — per-action evidence of authorization rather than an attestation that a policy exists.
Where it shows up
Solutions and industries that depend on this
Surfaced automatically from the components each solution engages and each industry relies on.
Solution
Governance & audit evidence
Turn agent activity into evidence a regulator will accept.
Use case
Healthcare
Clinical authority cannot be delegated to a process.
Use case
Insurance
Every adjudication is a decision someone must own.
Use case
Banking & Financial Services
Supervised institutions need evidence, not dashboards.
The other six
Orcher is one control plane
Layer 1
Directive Interface
Plain language becomes the permanent record of what was asked.
Layer 1
Role Identity Fabric
Binds the directive to a human and a role, cryptographically and revocably.
Layer 1
Logic Scrubber
Verifies the proposed action against systems of record before commit.
Layer 2
Data Control Gateway
Training exclusion and residency verified before routing.
Layer 2
Cost Governance
Routes by stakes and halts runaway loops.
Layer 2
Observability
Real-time cross-provider trace: which model, which role, what cost, what outcome.
Verified execution, or none at all.
Orcher is deployed with named enterprises under the Human-in-the-Role model. Request a technical briefing with the founding team.
