Two governed plans, one repository, nine nodes of AI-written code. Every completion claim checked outside the executor session under the evidence model then in force, every event on a hash-linked audit log. Along the way: a live operator pause, an executor process death, a recovery through the record's own channels, and a verified hand-off from the finished plan to its successor. This page walks that record, exactly as produced, with annotations for context. Open any entry to inspect the raw evidence.
AI now writes a large share of production software. When something breaks, or when an auditor, insurer, or customer asks how your software was built, most companies can only answer from memory: chat logs, terminal history, and whatever a developer recalls. That answer does not hold up, and the people asking know it.
Security questionnaires, insurance renewals, procurement reviews, and disputes increasingly ask a version of the same question: what controls governed your AI-assisted development, and can you show us? For a company working this way, the answer is a record like this one, produced automatically as a byproduct of the work. Without governed execution, that evidence is scattered across chat logs, terminal history, and commits, or does not exist at all.
This is a complete, real execution record from an AI-assisted software build. During the run:
This page is not a simulation. It presents the actual record generated by Atlas Orchestrator, unaltered, and every entry on it opens.
AI coding tools can generate software. What an engineering organization also has to be able to prove:
Without governed execution, that evidence is scattered across chat logs, terminal history, and commits, or does not exist at all. This record demonstrates all five, on a real run.
This kind of evidence matters wherever software must be explainable, auditable, or defensible: enterprise engineering, regulated industries, internal governance.
Every entry below is copied verbatim from the run's on-disk record: the hash-chained event log, the run manifests, the consumed operator-channel files, the repository's git history, and the machine-generated cross-run digest. Timestamps, hashes, and event text are unaltered. All 38 chained entries are here, and each one opens.
The fixture is a tiny zero-dependency date-formatting library, chosen precisely because it is trivial. The AI executor (Claude, headless) writes the code; Atlas Orchestrator holds the frozen plan, verifies every node's done-tests itself, and chains every event; Waypoint is the operator's cockpit. The plan was reviewed and frozen before the run: five nodes, each with machine-checkable completion tests, ending in a single governed commit.
master spec │ reviewed, then frozen: the plan gains a │ cryptographic identity ▼ frozen plan · the contract (51e028c2, then b20ae029) │ launched from Waypoint, the operator's cockpit ▼ AI executor (Claude) ◄────► Atlas Orchestrator writes the code holds the plan, gates every step, runs every verification itself (server_verified) │ ▼ hash-chained record → archives → cross-run digest ▲ operator channels: pause · approval · guidance
Each row is one line of the audit log, HMAC-linked to the one before it, so nothing can be inserted, removed, or rewritten without breaking the chain. Click any entry to see the verbatim record and its linkage. Green events are the orchestrator's own verifications; amber events are the human acting through designed channels.
lib-core done attempts=0 lib-tokens done attempts=0 tests done attempts=0 docs ready ← unblocked, never claimed: the exact point the executor vanished final-commit blocked
With plan v1 complete, its successor, a refactor plan frozen with a new identity, was launched against the same repository. At startup the orchestrator verified the prior run's entire chain, swept its artifacts into an archive, and opened a new chain whose first entry narrates the hand-off. It's the first entry in the ledger below. Open it.
archive\run-51e028c2-2026-07-08T22-00-21-223Z\ ├── atlas-run-state.json final state, 5/5 done ├── atlas-run-state.json.log the complete chain, 22 entries ├── atlas-diagnostics.log the engine's own log: nothing to confess ├── atlas-pause-inbox\consumed\ the operator's honored pause request └── atlas-guidance-inbox\consumed\the recovery note, as delivered
Act one's session deaths were traced to plan authoring: a supervised-cadence default meeting a headless executor. Act two's plan was authored for headless operation: continuous mode, plus one explicit instruction about commit discipline. One session, four nodes, zero interventions:
Governance quality lives in the plan. The engine behaved identically in both acts: every gate fired, every verification was the orchestrator's own. What changed was the authored contract, and the record measures the improvement precisely.
7a77e70 refactor(run): datefmt v2 governed run work ← act two: the one governed commit 32f2473 feat(run): datefmt v1 governed run work ← act one's conventioned run commit c0077d8 docs(datefmt): usage doc for formatDate tokens ┐ 431a0ec test(datefmt): self-contained run.js … │ act one's per-node commits: 2c55ed9 feat(datefmt): HH/mm/ss time tokens │ the finding the record preserved f40668d feat(datefmt): core formatDate with YYYY/MM/DD ┘ 973ea8d chore: fixture baseline — README only ← the only ungoverned commit this repo will ever have
atlas diagnose
is a read-only reporter that walks a run directory (current run and archives) and summarizes
what the records claim. It knows nothing about what was intended. This is its complete output
for the two-act run:
read-only report over records AS FOUND; nothing here is authenticated (verify_provenance is the authentication path). == RUNS (2) ==================================================== current: 4 node(s) — done 4 | COMPLETE | identity b20ae029d3fe | engine 1.3.0 archive/run-51e028c2-…: 5 node(s) — done 5 | COMPLETE | identity 51e028c2f683 | engine 1.3.0 == VERIFICATION FAILURES, reasons ranked ======================= none. == HALTS by node =============================================== none. == ENVIRONMENT (stops and precondition failures) =============== no environment stops. no precondition failures. == HEALING (state_reconciled) ================================== none — no state file ever disagreed with its chain. == WAIVERS (node_waived), with reasons ========================= none.
Every zero on that report is a claim: nine nodes of AI-written code, every done-test passed on first verification; through a pause, a process death, multiple relaunches, and a succession, the state never once disagreed with its chain. The escape hatches existed and were never needed.
Both chains verify against their keyed genesis: 22 of 22 and 16 of 16 entries. The succession itself was a verification event: act two's engine verified act one's entire chain before archiving it.
AI can write your software. The question an engineering organization has to answer is what it can prove about how that software came to exist. Atlas North builds and operates the governance layer that makes the answer: a checkable account of the authorized work, the observed checks, the recorded failures, and the governed recovery.