warrant sits between an agent and the systems it would otherwise reach. Type an action the way an agent would propose one. Nothing here is connected to a real system, and nothing is kept between requests.
Three decisions are sealed into a chain, then one of them is rewritten directly in the database and its own hash resealed to match, which is what someone covering a track would do. Verification runs before and after.
Thirteen rules, each citing a real authority. Raise only, so a Class 2 match beats a Class 1 match on the same action. Fail closed, so an action matching no rule is Class 2 rather than assumed safe. Source and the two-arm evaluation: github.com/mariaangelikabuilds/warrant