<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Thinking | Proofpane</title>
  <subtitle>Position pieces from Proofpane's founder on AI governance, evidence, authorization and making AI work auditable.</subtitle>
  <link href="https://proofpane.com/thinking/"/>
  <link rel="self" href="https://proofpane.com/thinking/feed.xml"/>
  <id>https://proofpane.com/thinking/</id>
  <updated>2026-08-14T00:00:00Z</updated>
  <author><name>Louie Lu</name></author>
  <entry>
    <title>Your agent&#x27;s memory is not your audit trail</title>
    <link href="https://proofpane.com/thinking/your-agents-memory-is-not-your-audit-trail/"/>
    <id>https://proofpane.com/thinking/your-agents-memory-is-not-your-audit-trail/</id>
    <published>2026-08-14T00:00:00Z</published>
    <updated>2026-08-14T00:00:00Z</updated>
    <summary>There is a genuinely good agent memory pattern making the rounds under the name LVP: an append-only event Ledger, a Policy layer, derived Views, bitemporal timestamps underneath. Then comes the inference — &quot;we already have a ledger and a policy layer, so governance is covered.&quot; Same words, opposite sides of a trust boundary. The test is one question — hand your ledger to someone who distrusts you: what can they verify? — and a five-question checklist this piece runs on our own product too, failing part of it in public.</summary>
  </entry>
  <entry>
    <title>Six gates in a day. Every one caught us first.</title>
    <link href="https://proofpane.com/thinking/every-control-caught-us-first/"/>
    <id>https://proofpane.com/thinking/every-control-caught-us-first/</id>
    <published>2026-08-08T00:00:00Z</published>
    <updated>2026-08-08T00:00:00Z</updated>
    <summary>We built six governance controls in one day, and within minutes of existing each one found a real defect — in us. A gate that read a plan as an accomplishment, so the stronger wording scored as a downgrade and passed silently. An evidence checker whose first act was to certify a page that does not exist. A safety gate that locked us out of repairing the outage it was guarding, because the fix required the service it had just refused. Not one was found wanting by review; every one was found wanting by being run.</summary>
  </entry>
  <entry>
    <title>Trust Without Acquaintance</title>
    <link href="https://proofpane.com/thinking/trust-without-acquaintance/"/>
    <id>https://proofpane.com/thinking/trust-without-acquaintance/</id>
    <published>2026-08-02T00:00:00Z</published>
    <updated>2026-08-02T00:00:00Z</updated>
    <summary>Humans allocate trust by familiarity, not ability, and that layer does not scale: a mid-size company now runs thousands of AI actions a day, and every one is a stranger. Institutions always answered this by manufacturing familiarity, but a SOC 2 report vouches for a company, roughly, once a year, and says nothing about the action at 4:51pm yesterday. On runtime receipts as familiarity manufactured at the resolution of one action, and the distinction that separates testimony from surveillance footage: the only receipts that carry weight are generated by enforcement.</summary>
  </entry>
  <entry>
    <title>Evidence cuts both ways</title>
    <link href="https://proofpane.com/thinking/evidence-cuts-both-ways/"/>
    <id>https://proofpane.com/thinking/evidence-cuts-both-ways/</id>
    <published>2026-08-01T00:00:00Z</published>
    <updated>2026-08-01T00:00:00Z</updated>
    <summary>Every AI guardrail treats the human approver as ground truth, and the human is the least verifiable component in the loop. My agent asked me to photograph a device because &quot;I tested it&quot; resolved to nothing. It refused a six-second code review and asked for the business-scenario run instead. Why holding the person to evidence makes the model hallucinate less — and why the harder question is whether a decision reaches production at all.</summary>
  </entry>
  <entry>
    <title>We send each other our chat logs now</title>
    <link href="https://proofpane.com/thinking/we-send-each-other-our-chat-logs/"/>
    <id>https://proofpane.com/thinking/we-send-each-other-our-chat-logs/</id>
    <published>2026-07-27T00:00:00Z</published>
    <updated>2026-07-27T00:00:00Z</updated>
    <summary>Humans stopped handing off to each other, and it was not because the tools made us antisocial. Human bandwidth stopped meeting the rate agents created, so the medium changed by itself: we exchange AI conversation logs, compressed by a step neither party sees. What breaks in there, the claim gate that already ships, the alignment gate nobody is building, and why execution governance leaves the most consequential step unrecorded.</summary>
  </entry>
  <entry>
    <title>It was true. It still wasn&#x27;t allowed.</title>
    <link href="https://proofpane.com/thinking/hardware-backed-says-who/"/>
    <id>https://proofpane.com/thinking/hardware-backed-says-who/</id>
    <published>2026-07-27T00:00:00Z</published>
    <updated>2026-07-27T00:00:00Z</updated>
    <summary>My product published a claim about itself that hadn&#x27;t happened yet. The claim turned out to be true, and that is not a defence. The gate had been firing the whole time; I clicked approve without reading it. What the logs showed, the two measured device rows, why the tier was split instead of loosened, and what a human click is actually worth.</summary>
  </entry>
  <entry>
    <title>Who approved that?</title>
    <link href="https://proofpane.com/thinking/who-approved-that/"/>
    <id>https://proofpane.com/thinking/who-approved-that/</id>
    <published>2026-07-25T00:00:00Z</published>
    <updated>2026-07-25T00:00:00Z</updated>
    <summary>Now that AI agents do real work beside humans, authorization and accountability have quietly become the audit question. Why logs can&#x27;t answer it, a frequency law for approvals (assurance ∝ blast radius ÷ frequency), the R0–R4 assurance ladder with its honest limits — and why the accountability chain has to end at a key your own organization holds.</summary>
  </entry>
</feed>
