The Glass Ledger

Paul Blatherwick · Zenodo (CERN European Organization for Nuclear Research) · 2026

The Glass Ledger v2 is a tamper-evident decision journal for AI agents and any system whose audit trail must not be quietly rewritable — roughly 600 lines of Python, MIT-licensed, shipping with a demo that attacks its own ledger four ways and prints every verdict. The problem it addresses: any system that keeps its own log can rewrite its own log. Where that system is an AI agent acting autonomously, or a clinical tool whose audit trail is a legal record, a self-held log proves nothing. The Glass Ledger makes that class of lie detectable — not impossible, detectable — by anyone, from any machine, using only the ledger file and a 64-character public key. The mechanism: every entry carries the SHA-256 fingerprint of the entry before it and an Ed25519 signature over its own fingerprint, so the whole history hangs as one chain from a genesis entry that commits the public key into the record. Four defences harden the format: length-prefix framing, so no field boundary can be forged; canonical JSON, so the same body is the same bytes on every machine and an independent verifier recomputes the same hash; domain-separated signing, so a ledger signature cannot be replayed elsewhere and a v2 entry cannot masquerade as v1; and an append-only rule with no update and no delete — a correction is a new entry standing beside the mistake it fixes. The verifier reads only, never needs the private key, never trusts the machine that wrote the ledger, and never crashes on hostile input: malformed lines return verdicts, not tracebacks, with the intact prefix reported for forensics. Checkpoint pinning closes the blind spot every hash chain has — rollback by tail deletion, invisible from inside the file — and a torn-tail policy distinguishes power-loss accidents from attacks, so BROKEN keeps meaning broken. The threat model is published in full, including its honesty clause: defence against an attacker holding both the private key and the pins requires evidence that leaves the box — write-once object storage, an RFC 3161 timestamp authority, a copy on another machine. The trust boundary is stated as a deployment requirement: the witness never lives with the writer. Not a blockchain: one writer, one file, no consensus, no network. A blockchain is what you need when many mutually distrusting writers must agree; this is what you need when one writer must not be able to lie about its own past. Far more systems have the second problem. This record contains the source (chain.py, verify.py), the command-line verifier, the four-way attack demo, and the v1.0 paper. Built as the accountability spine of an always-on personal AI agent; the same pattern now underpins audit-trail claims in regulated health-tech safety cases. Deposited alongside the instrument whose log it keeps honest: After the Machine — the AI Interaction Outcome Profile (DOI 10.5281/zenodo.21515932). Screen → AIOP → Ledger: assess, measure, record. Paul Blatherwick, RMN. Code MIT-licensed; paper CC BY 4.0.

Read the paper · More papers on PaperTik