Proof, by Torem Labs
AI GOVERNANCE

Agents write the code. Who signs off?

Proof turns what an agent did into a record you can review, question, and defend.

Autopilot flies the plane. The pilot is still responsible for the flight.

Coding agents are autopilot for software. Proof keeps you in the seat.

autoideationthe agentreview

A prompt can only give you so much

Does your chat look like this?

chats
Birthday RSVP
RSVP page
Untitled
rsvp help
Birthday RSVP (2)
New chat
Birthday RSVP
Help me build an RSVP page for my birthday.

Good idea. Here is what you will want:

  • 1.RSVP form
  • 2.Guest list
  • 3.A reminder email
  • 4.A date and location field
  • 5.A thank-you page

Want me to start on the form?

Can guests bring people?

Yes, add a plus-one field to the form.

a good idea
What if the place only holds so many? It should cap, then waitlist.

Good point. You could add a capacity check. Want me to?

Actually, can guests pick songs too?

Sure, add a song field and build a shared playlist.

Hmm, can you redo the form from the top?

Of course, here is the form again.

Wait, what did we decide about capacity?

Could you remind me what you wanted for capacity?

Reply, and keep the thread going…

Two sides of the same coin

Proof is active before the run and after it.

01Ideation

Before the run.

02Agent

Your agent writes the code.

03Review

After the run.

For teams

Proof gates a merge on how much of the diff was actually read, not on how many people clicked approve.

Approval counts stopped meaning much once agents started writing most of the diff. A reviewer can clear 60 files in a minute and the pull request looks exactly as approved as one somebody read.

  • Set the bar as coverage, not headcount

    Require a percentage of the review-required files to be read in depth. Two approvals on an unopened diff do not satisfy it.

  • The check runs on the pull request

    A status appears on the PR and states where the review stands. Nobody has to remember to look somewhere else.

  • Unread files are counted, not hidden

    A file approved without being opened is recorded as approved without being opened. The number is on the record and on the check.

  • A new commit does not inherit an old sign-off

    A record sealed against an earlier commit stops satisfying the policy, so pushing after approval reopens the gate instead of slipping through it.

  • Roles are sealed at signing time

    The signer’s role is written into the record when they sign. Promoting someone later cannot retroactively make an old sign-off count for more.

All of it is live today. What a record holds, and what it deliberately does not, is on the trust page.

Build faster, and still own what ships.

Free to start. No card needed.

Sign in

Write to us.

Questions, bug reports, ideas: they all land in the same inbox, and we reply.

By contacting us you accept that we use your name, email, and message to reply, and nothing else. Details in the privacy policy.