private architecture proposal · prepared for Ramp · not a customer, partner, pilot, or endorsement · not indexed
the proof layer under agentic spend

Ramp counts it.
Hive proves it.

Your agents now triage requests, review contracts, run compliance checks, and, with your card network partner, execute payments on their own. And your newest product counts the fastest-growing line in business spend. Both of those rest on records someone else wrote about themselves. Hive signs the decision and the delivery, so the numbers and the approvals verify without anyone's word.

20.7×growth in customer AI token spend since June 2025
Agents that paywith your card network partner, executing bill pay on their own
Token spend, one viewevery AI provider, counted from provider-reported figures
$100B+annualized spend running across the platform
the demonstration · flip the switch

Every number on an AI invoice
comes from the seller's own meter.

You built the product that finally shows AI spend in one place, connected through billing APIs, reading only cost and usage, never the prompts. But each figure inside it is still provider-reported, the vendor counting its own sales. It is the only major category in corporate spend with no independent record. Switch on receipts and see what the numbers do.

ai token invoice · one customer · one monthsource · provider-reported
provider · modelbilledindependently
accounted
total · illustrative$18,412·
independent receipts · OFF
every line is the seller's own count · nothing here can be checked by the buyer · the invoice is a claim
You already reconcile the invoice against logged usage.
The logged usage is still the seller's own number.
Ramp becomes the first spend record that verifies itself.
the second problem · watch it run

The task was approved once.
The agent decides how many steps.

Your own research says it plainly: an agent runs like a meter, and each step it chooses to take is another charge. Approval happens at the top. The spending happens after, out of anyone's sight. Set a ceiling and watch what a signed hold does that a dashboard alert cannot.

0steps the agent chose to take
$0.00run cost · decided after approval
RUNNINGstate · signed at every step
the agent is working · every step is being receipted as it happens
the approvals side · move the sliders

It sizes the proof a decision deserves.
It does not judge the purchase.

Hive forms no opinion about your customers' vendors, budgets, or risk appetite. It sizes how much proof a decision needs, records provenance, and signs it. Your customer sets the floor, and a floor can only get stricter, never looser.

ROUTINE
customer's policy floor:
The weighting is private. How Carnac™ sizes proof is trade secret and never leaves Hive. What ships to you is the route it chose and a receipt anyone can re-check offline. Two planes, kept apart on purpose. That separation is what makes the proof worth anything to an auditor.
where it rides · nothing you have to rebuild

One receipt layer, under what you already shipped

Agents that approve

Controllers, AP, and procurement agents decide, and their decisions become commitments. Each one gets a signed record: which model, which policy floor, cleared or held, sealed before the money moves.

Agents that pay

An autonomous payment is the one action nobody can walk back. A receipt above the authorization proves the rule ran first, and a held payment proves the limit worked.

Token spend, verified

Receipted usage turns provider-reported figures into counts the buyer can check, and gives you the one thing a dashboard alone cannot: numbers that survive a dispute.

Contract review

When an agent reads a contract and recommends, the recommendation is evidence in a later negotiation. Signed the moment it was made, not reconstructed after.

Your customers' auditors

Every controller you serve eventually answers "who approved this, and on what basis?" The exam becomes a query, one signed bundle, verifiable offline.

Europe, next

New markets mean new supervisors reading the same records. Evidence produced continuously beats evidence assembled after the request. It exists before anyone asks.

Your customers bought autonomy.
What they'll be asked for is proof it had limits.

The first step is small: point one agent decision at the protected route and see what comes back. No integration, no change to card rails or ledgers, no access to customer data. The proof verifies offline today, on a post-quantum standard, by anyone you hand it to.

layer · above the action, never competing standard · ML-DSA-65 · FIPS 204 verification · free · offline · forever
Private architecture proposal prepared for Ramp · noindex / nofollow / noarchive · this page does not state or imply that Ramp is a customer, partner, pilot, or endorser · the invoice, agent run, and routing shown are illustrations of how the flow works and are not Ramp or customer data · Hive proves what an AI decided and what was delivered; it does not replace card rails, ledgers, or the systems that secure them, and stating that a policy check ran and was signed is not a statement of legal or accounting compliance · we prove conditions, never outcomes; an unaccounted difference is reported as a gap, never as an accusation · we never read prompt content; every request is receipted by a one-way SHA-256 fingerprint, not the words · verification is always free and works offline against the Hive public key · Carnac™, CarnacPrompt™, and Carnac Gateway™ are Hive marks · all Hive primitives patent pending · company facts referenced are public and source-reported as of July 2026 (procurement agent fleet, April 2026; agent-executed corporate bill pay with its card network partner, March 2026; AI Token Spend Management, July 16, 2026; 20.7× growth in customer token spend since June 2025) and should be re-verified before external use · prepared by Steve Rotzin, Founder, Hive Civilization Inc. · Wyoming, USA
new in the canon · runnable on this page

Keep spend controls and the run record together

These receipts add a check of one corporate card action against its delegated control and a continuous record of the receipted run that led to it. They are deployed and open to verify, so the runs below are live checks, not mocks.

mandate.conformance · Deployed in production

Test one corporate card charge against its delegated control

This receipt gives your controls team a specific way to inspect one agent initiated card charge. It compares the charge amount, currency, timing, and scope with the constraints in one authority receipt signed before that charge was authorized. The service recomputes the finding from the comparison instead of relying on a result supplied by the caller. Finance, compliance, risk, and legal can see the stated control beside the charge under review. The record can support a review without becoming part of the card rail or ledger.

What it does not do. It does not establish that the cardholder granted the authority, that the agent is genuine, that any network authorized or settled the charge, that goods or services arrived, or that displayed terms were read. It is not payment authorization and holds no cardholder credential; no card network, issuer, or regulator currently recognises it as authentication data, compelling evidence, or a liability shift; it cannot deny, resolve, or affect a dispute, limit rights under Regulation E, Regulation Z, or an equivalent rule, measure cumulative or fast repeat spend, or show that the supplied authority had not been revoked at authorization.

POST /verify/mandate-conformance · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/mandate-conformance · case fail, a forged record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

causal.path · Deployed in production

Follow the receipted run behind one card charge

Use this receipt when a charge review needs the sequence of signed steps that led from a run's origin to its terminus. It checks that every declared input fingerprint equals the prior step's declared output fingerprint, with no unreceipted gap in the presented sequence. It also checks that recorded times do not run backward and recomputes the continuity finding rather than accepting it from the caller. That lets finance, risk, and legal inspect the run that was presented beside a charge. It is useful when an agent chose several steps after the original approval and the review needs an intact record of those steps.

What it does not do. It does not show that the first step caused the last step, that the last step caused a claimed effect, that any claimed effect occurred, or that anyone was harmed, and it never receives a description of that effect. It does not show that this was the only chain, rule out parallel or intervening causes, establish that the selected steps are those a court, regulator, or investigator would consider relevant, create legal liability, or provide an expert opinion on causation.

POST /verify/causal-path · case pass, a clean record

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/causal-path · case broken, the chain is broken

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.