How it works
Your agents act. The record answers.
One support ticket, followed from the moment an agent decides to act to the moment someone six months later asks you to prove what happened. The record it produces builds alongside it, on the right.
01 · The ask
An agent decides to act.
A support agent finishes a ticket and moves to push the summary into the CRM. In most stacks that call simply executes. Here it passes through Glacis first — in the path, on your hardware, before anything lands.
02 · The policy
The rules run in the path.
This deployment has one rule that matters right now: customer identifiers stay inside the support boundary. The policy isn’t a PDF — it executes, on this call, before the CRM ever sees it.
03 · The decision
The call is blocked.
The identifiers are in scope, so the call does not go. Allow, flag, block — that is the whole vocabulary, and it is deliberately small. Glacis does not claim to judge whether the agent was right; it enforces the rule you set and records which of the three happened.
04 · The seal
What happened becomes a record.
Policy, decision, signer, and chain position are sealed into a signed receipt, hash‑chained to every receipt before it. Your prompts and data aren’t in it — hashes stand in for them.
05 · The second signature
Someone outside countersigns.
Hashes and signatures — nothing else — cross your boundary to an independent witness, which countersigns the record and enters it in an append‑only log. From this moment, you’re not the only one who can vouch for what happened.
06 · The answer
Six months later, someone asks.
An auditor, a customer, a court. You hand them the receipt. They check the math themselves — offline, with no Glacis account and no cooperation required from you. The record answers, so you do not have to.
Run it on something of your own.
Your first record takes minutes and costs nothing.