Inspiration

Every agent framework enforces its human-approval step with a sentence in a prompt. "Always ask the user before signing." That is not a control. It is a suggestion, offered to a system we already know can be argued with.

Meanwhile the thing that step is meant to protect has quietly stopped working. "Email a link to sign" never authenticated a person, it authenticated an inbox. And the fallback, "take a selfie," is collapsing under industry threat reporting: injection attacks that feed synthetic video straight into a verification pipeline, bypassing the camera entirely, have grown roughly ninefold year on year. Deepfakes now account for around one in five biometric fraud attempts. Human reviewers miss high quality ones roughly three times out of four.

Then came the wildcard. Perfect Corp built a dermatological grade pore and micro texture analyser so that virtual lipstick looks convincing at close range. Pore level micro texture is precisely the signal that GAN and diffusion generated faces measurably fail to reproduce. A cosmetics API turned out to be a forensic sensor that nobody was pointing at fraud.

What it does

Your agent can do the work. Only a human can sign for it.

STRATUM is a human authorisation layer for agentic workflows. The agent drafts, compares, inspects and prepares, then reaches a gate it is structurally incapable of passing.

Not "declines to pass." Incapable. The tool  sign_document  is absent from the agent's toolset entirely. Ask for it anyway and the backend answers  403 AGENT_FORBIDDEN , naming the tool that should have been used instead:  request_human_signature . The boundary is a backend state machine, not a system prompt. You can verify this yourself in about ten seconds from the demo link on this page.

Behind the gate sit four checks. Presence asks whether someone is really here. Authenticity asks whether this is skin or a render. Binding asks whether this is the person on the identity document. Uniqueness asks whether they have already claimed. Every event, from capture through verdict through human ruling through signature, appends to a per gate hash chain.

One engine runs three modes.  authorise_action  covers a supplier bank change request that an agent must not approve alone.  verify_identity  covers KYC, binding a live face to the photo on an identity document.  one_human_one_claim  covers Sybil resistance, signed EIP-191 so that  ecrecover  verifies the claim on chain.

Each gate ends in a sealed PDF/A-3b certificate that outlives the server which produced it.

The behaviour we care about most is the refusal. A gate cannot pass a check that was never attempted. A clean uniqueness sweep that never established a live person is not an authorisation, and the gate says exactly that. Every check also states what it could not establish, in the same type size as what it did, and that caveat travels all the way onto the sealed PDF.

How we built it

A FastAPI verifier over SQLite with a single writer lock, five React and Vite consoles, deployed as a Vercel frontend against a Render backend.

The matcher runs in four stages. Perfect Corp skin analysis acts as the sensor. Each dimension is z score normalised against population statistics. A weighted distance then runs over the stable identity dimensions only, since the volatile ones shift after exercise, so we exclude them and show our working. Procrustes point set registration aligns the landmark normalised spot constellation. Finally, calibrated thresholds with an explicit review band between them.

Every sponsor integration does real work rather than making an appearance. Foxit enforces the agent boundary and document operations. Nutrient DWS renders and signs the certificate, and runs genuinely live rather than from a recording. Doctavian issues the attestation. SerpApi provides live world corroboration. name.com provides verifiable origin. Xano serves as the backend tier. Perfect Corp is the sensor the entire thesis rests on.

751 tests hold the system together, including a concurrency suite that forks the audit chain if a lock is removed, and a tamper suite proving the chain detects edits after the fact.

Challenges we ran into

The threshold that turns away honest people. A sibling scores 7.45. A badly registered capture of a complete stranger scores about the same. No threshold separates them, and auto refusing costs an honest person their allocation. So we stopped pretending a clean threshold existed and built an explicit review band. Below 3.0 is a duplicate, above 10.0 is unique, and in between a person decides. The fraction of genuine traffic we route to a human is a real product cost, so we report it rather than tuning it out of the demo.

Serverless broke correctness, not speed. We deployed to Vercel and four enrolments reported a roster of two. The console contradicted itself inside a single view, showing "2 enrolled" directly beside "compared against 1 of 1." A claim is five requests that must all agree about one gate and one roster, and each was landing on a different instance with its own database. Worse, our store guards writes with a threading lock, which is genuine mutual exclusion inside one process and none at all between them. Interleaved appends fork the hash chain, so the verifier would have reported tampering that never happened. We moved the backend to a single process. Statelessness turned out to be a correctness property, not a performance one.

A deployment that died before Python ran. The platform returned  FUNCTION_INVOCATION_FAILED , no traceback, and logs we could not reach. Three blind fix cycles produced nothing at all. So we made the deployment serve its own boot traceback, and the very next cycle handed us an exact diagnosis:  int('')  on an environment variable that had been declared but left empty. Ten minutes of guessing, beaten by one deliberate act of self diagnosis.

A document that cannot be replayed. We run vendor calls from recordings to conserve a metered grant. But a certificate embeds its issue time, so no two renders are ever the same bytes. There is no recording to return. Replay does not serve a stale document, it raises, every single time. That one integration had to go genuinely live, and now does.

Accomplishments that we're proud of

The agent boundary is real and independently checkable. Request  sign_document  against the running deployment and you get a 403, with the correct tool named in the response body. No prompt engineering involved, and no way to talk it round.

The certificate weighs 97,422 bytes and is both PDF/A-3b conformant and cryptographically signed, confirmed by markers inside the file rather than by trusting that it rendered without error.

Duplicate claims are refused by a unique database index on the campaign and nullifier pair, not by a lookup. Under load a lookup is a suggestion. The index is the guarantee.

751 tests hold a line that is easy to state and genuinely hard to keep: a gate that could not run a check does not pass it.

The accomplishment we are proudest of is the least flashy one. The system states what it does not know. Our faces are synthetic, so the distances measure the matcher rather than real skin, and that sentence travels onto the sealed PDF in the same type size as the verdict itself. Building something that argues against itself in writing was considerably harder than building something that simply reports PASS.

What we learned

A control that lives in a prompt is not a control. Move it into a state machine, or admit you do not have one.

Honest uncertainty is a feature rather than a hole in the demo. The review band is the most defensible thing we built, precisely because it declines to guess.

When you cannot read the logs, make the deployment diagnose itself.

And volunteering your limits buys credibility for everything else you claim.

What's next for STRATUM

The real skin benchmark is our honest gap and our next piece of work. Every number in this demo comes from a synthetic cohort whose identities differ by construction, which measures the matcher rather than whether real faces separate. Next is roughly thirty real participants across varied lighting, devices and times of day, tested against print attacks, screen replay, virtual camera injection, face swap, fully synthetic faces and impostors, reported in ISO/IEC 30107-3 vocabulary with APCER and BPCER figures plus ROC curves per check and fused. We know exactly what that path looks like. We simply will not claim it before running it.

After that, an iBeta or ISO 30107-3 Level 1 to 2 lab evaluation, because a hackathon benchmark is not a certification. A purpose trained texture model, since Perfect Corp's was tuned for cosmetics and a model built for forensics would very likely beat it. An on chain verifier contract consuming the EIP-191 claim directly. And a multi writer store, so the guarantee survives beyond a single process

Built With

Share this project:

Updates