ClisTa is not where model decisions happen. It is where they become defensible — threshold changes, overrides, validation findings, effective challenge recorded as accountable state: evidence, the challenges that survived, sign-off authority, tamper-evident provenance. Not minutes. A sealed, replayable record.
conversation → event log → projection → verification → accountable state
Twenty-eight events encode the full challenge — proposal, attack, concession, revision, seal. The recommendation arrives with its accountability structure fused on: anyone holding the sealed log can reconstruct it, including the model risk committee it goes to.
every datum witnessed before use, bound to its writer at event time — no reasoning from thin air.
the checker's attack forced the maker to withdraw its proposal — named in the revision, not implied.
an invented assumption withdrawn in writing; the arithmetic that killed it verified by its opponent.
break-even at 11.44% — every number shown, checked by the counterparty, cited by hash.
the final yes carries both forward — recorded, not resolved away. Confidence the deliberation didn't earn is never assigned.
12 claims, 12 citations, zero unwitnessed; the chain verifies on any machine, without trusting us.
This run is one act of a longer story: a live swarm served a pre-recession rationale into a recession, the recall path wrote no audit record, and the remediation caught its own documents doing the same thing. Every claim cites its artifact.
Read the case study Verify the sealed thread
Eighteen layers, each verifying one boundary. Green never means endorsement —
every verifier keeps trusted: false until something
outside the protocol grants trust.
integrity verifycontinuity verifyexecution verifyoutcome verifyprovenance tracerelease verifyThe cockpit drives the same ClisTa engine behind the CLI: ingest a session, watch it project into accountable state, and verify each boundary live. No install, no clone — the event log and every verdict are real.
trusted: false
clean-room replay PASSED
The cockpit is a browser front-end bolted directly onto the ClisTa engine — the same code path the CLI drives. It is not a dashboard that summarizes results after the fact. You hand it a conversation, and it runs the protocol in front of you: the raw deliberation becomes a canonical event log, the log projects into accountable state, and every boundary is verified live. Nothing is mocked — the verdicts you see are the engine's, and the event log behind them is byte-for-byte replayable on your own machine.
Paste or load a session. The cockpit records it as an append-only event log — the canonical history, not a transcript.
The log projects into structured state: evidence, surviving objections, authority, provenance — each bound to who and when.
Each spine layer runs and fails closed. Green never means endorsement — state stays trusted: false until something outside the protocol grants trust.
An agent claimed a milestone was complete.
The artifact disagreed.
The protocol paused action.
Verification restored alignment.
The April 2026 revised interagency MRM guidance — Fed SR 26-2 · OCC 2026-13 · FDIC, superseding SR 11-7 — asks, in its own words, for what a sealed ClisTa thread is.
"an audit trail demonstrating design decisions and their rationale" — the sealed, hash-chained event log, replayable by an examiner who does not trust the vendor.
"material modifications … recorded with supporting justification and approval" — a threshold change that arrives as evidence, challenge, concession, and a gated recommendation.
"explicit sign-off authority and document approval decisions" — authority bound to participants at event time, dissent preserved past the yes.
The boundaries, stated before the pitch: the guidance is non-enforceable, principles-based — a description of best practice, not a mandate. Generative and agentic AI are explicitly out of its scope (classical ML and algorithmic models are in). ClisTa is not compliance software, and no regulator requires it. The chain proves what was recorded and when — never that the decision was good. And every claim above stays bounded by the independent evidence that has actually accumulated — see the invitation below.
Decisions we didn't pick, agents we don't operate, results we can verify without trusting the operator — and that you can verify without trusting us. One prompt, pasted into your own agent with a real decision you own, produces a sealed thread that checks mechanically. If your checker changes nothing, or the run falls apart — send that too.