CSOAI - the governance agent
Everyone shipped one agent. We designed a Council.
A single agent deciding compliance is a single point of failure. CSOAI is testing a multi-provider review design, but the current three-leg sample was fully correlated (n_eff 1.00). Human accountability remains in the loop.
A lone governance agent can be wrong, biased, or compromised - and nobody checks it.
A designed 33-seat review uses a supermajority threshold, but correlated seats can still be captured together. The latest point experiment measured n_eff 1.00 of 3 nominal legs; it is not live governance.
A card's trust path is an Ed25519 signature over a SHA-256 hash chain, verifiable offline against did:web:csoai.org — no blockchain and no timestamp authority sits in that path. The /xrpl-attest page is a reader of GET /root.json (signed root envelope; inclusion does not individually sign a leaf). GET /api/xrpl is a reader of that root (writes_board false, live locked 16, same merkle). Historical DEVNET Payment-memo / CredentialCreate hashes are not this feed. XLS-70 Credentials are live on XRPL mainnet as an allowlist primitive; we are not issuing GSPC grades on-ledger. Separately from the card trust path, The current canonical public root has a proof-derived CONFIRMED_BITCOIN OpenTimestamps witness at block 968130. That witness covers the exact public root.json bytes only, not the separate signed-card index. Queued and candidate atoms are not automatically admitted, published, or anchored; a pending calendar stamp, where one exists, does not by itself prove inclusion in a Bitcoin block. Outcomes are replayable — not a black-box recommendation.
MCP-native and cross-vendor - it governs agents wherever they run, not just inside one suite.
How it compares
Single 24/7 GRC agent inside the Vanta suite.
Governance agent as policy system-of-record.
Governance layer inside the ServiceNow walled garden.