Open source · Slack · Jira · Confluence · GitHub

The AI teammate that shows its receipts.

Every answer comes with its sources. Every change comes with a named person's sign-off. Everything lands on a record nobody can quietly edit. scriptorium does real work across your tools, and it can show you proof of all of it.

▶ The full 96-second demo · cited answers, gaps that become tickets, approvals shown in full, docs that learn with permission

Why receipts

The AI failures people remember come in three kinds. In each one, something the AI said or did was never checked. scriptorium checks it, in code, every time.

It made something up

A support bot told customers about a login policy that didn't exist, and they cancelled over it. An airline's chatbot promised a refund the airline didn't offer, and it was held to it.

Receipt: a source. Every claim must cite a record a tool actually fetched. A citation it invented is removed; with nothing to cite, it says so and opens a docs ticket.

It did something nobody approved

An AI agent deleted a production database during an explicit code freeze. No one had signed off on the command.

Receipt: a signature. Every write waits on a card for a listed person, bound by hash to the exact change they saw. The one who asked can't be the one who approves.

It misreported what happened

The same agent then produced fabricated data and said a rollback was impossible, until it turned out the rollback worked.

Receipt: the record. Every step is written to a hash-chained audit log. Edit one line and verification fails. Nothing it did depends on its own account of it.

What it does

One engine and one policy layer run every agent. The Teammate is the general one: it reads widely inside its allow-lists, and each write it proposes waits on a card for a listed approver.

All capabilities

How it stays safe

A rule that only lives in a prompt holds as well as the model obeys it. Here each rule is enforced in code, and sabotaged on purpose by a mutation test that must fail when the rule is removed.

Proven, not promised

A test that still passes with its guardrail deleted proves nothing. So every rule is sabotaged on purpose: pnpm mutate removes it, and its eval must fail. Independent reviews then try to break what's left. Here is some of what they caught before it shipped.

Built in the open: reviewed pull requests, each with a test that fails without it. See them on GitHub →

Architecture

Files and git are the system of record. No database. An agent is configuration on the same engine: its envelope, its skills and its triggers.

Slack mention · DM · command Jira comments · new issues GitHub pull request opened Timers digest · reminders TRIGGERS Gate + lanes drops with a reason one lane per thread Agent turn model + skills held to the thread Policy allow · approve · deny per tool Admin controls pause · read-only switch a tool off Connectors Jira · Confluence · Slack GitHub · docs vault Grounding claim ⇔ fetched record Cited reply or “not in the docs” → gap ticket Approval card exact arguments hash-bound Named approver signed · single-use never the requester Write, once op-keyed · probed retry-safe Audit log — hash-chained: every decision, approval, write and run event calls narrows allow: read cited approve: write approved deny: never offered
A read goes out to the connectors, and the answer may cite only records they returned. A write takes the lower path: an approval card, a named person who is not the requester, then one exactly-once write. Admin controls can only narrow the policy, and every step is recorded in the audit log.

Run it yourself

One container and a folder of files; git is the system of record, so there is no database to run. Bring the Anthropic API, Claude on Vertex, or Gemini.

git clone https://github.com/sloweyyy/scriptorium.git && cd scriptorium
cp .env.example .env          # a model key, a Slack app, who may approve
docker build -t scriptorium . && docker run --env-file .env -p 8080:8080 scriptorium
pnpm doctor                   # names anything missing, and how to fix it