Execution Receipts vs Decision Receipts
Two different problems. Two different receipts. Here is how to tell which one you need.
Prove what happened, or what was allowed?
Execution receipt
Question answered: What did the agent run, receive, return, and when?
Use it to inspect tool calls, outputs, timing, provenance, and whether the recorded result can be verified.
If you are debugging agent behavior, start here.
Decision receipt
Question answered: What policy or authority allowed, denied, or limited the action?
Use it to inspect the policy evaluated, decision, justification, decision-maker, and decision time.
If you are auditing access policy, start here.
An allow decision does not prove that an action ran. A successful tool call does not prove that the action was authorized.
Record the work that was observed
An execution receipt describes a bounded execution event. A useful record identifies the tool, the time, the caller or execution context, the observed result, and the integrity data needed for independent verification. Sensitive inputs should be minimized, redacted, or represented by a commitment instead of copied into a public record.
What ran
Tool or capability identity, version, and caller scope.
What was observed
Recorded inputs or commitments, output, status, and event time.
What can be checked
Canonical bytes, output hash, provenance, and any real upstream evidence.
These records help with debugging, audit trails, reproducibility, and usage reconciliation. A receipt proves what its recorder observed and committed to. It does not prove that an unobserved outside outcome happened.
AER-1 is an open Internet-Draft, revision -02, authored by Brennan Zambo. It is a proposed format, not a formally adopted standard or an endorsement by the standards body. Review the AER-1 Internet-Draft revision -02 and the AER-1 conformance kit.
Record the policy outcome separately
A decision receipt captures the governance event before, during, or after an attempted action. It can identify the subject, requested action, protected resource, policy and policy version, outcome, justification, authority, and decision time. Its verifier should answer whether the decision record is intact and whether the required decision fields are present.
A decision receipt is not a substitute for an execution record. It says what the decision system recorded, not whether a later tool call completed or changed external state.
Connect the records without merging their jobs
- 01 / REQUESTAgent asks to actCapture the requested subject, action, and resource.
- 02 / DECISIONPolicy is evaluatedWrite a decision receipt for allow, deny, or limits.
- 03 / EXECUTIONApproved work runsWrite an execution receipt for the observed tool call.
- 04 / LINKKeep both verifiableUse an application-level reference when correlation is needed.
If your implementation links the records, use a documented correlation field or relationship. Do not assume AER-1 defines a decision-receipt identifier unless the versioned schema says so.
Three boundaries worth keeping clear
1. Execution is not authorization
A complete execution record cannot make an access decision lawful or policy-compliant.
2. Policy does not belong in every execution schema
Keep policy evidence in the decision layer and preserve the execution schema's focused purpose.
3. One receipt does not prove both
Use separate evidence for the decision and the action, then connect them only when needed.
Start with the layer you need to prove
For execution receipts, inspect the AER-1 schema, run the conformance vectors, and verify a real receipt. Build a separate decision record around the policy system that controls your actions.
Related guide: EU AI Act Article 12 and agent event logging. Verify records independently at the receipt verifier.
Frequently asked questions
Do I need an execution receipt or a decision receipt?
Use an execution receipt to prove what the system recorded as running. Use a decision receipt to prove what policy outcome was recorded. Use both when you need both kinds of evidence.
Does an execution receipt prove an action was allowed?
No. Authorization evidence belongs to the decision layer. Link the records when correlation is useful, but keep each claim verifiable on its own.
Is AER-1 a finalized standard?
AER-1 revision -02 is an individual Internet-Draft. It is an open proposal and is not yet a formally adopted standard.