Warpthread
THE PROVENANCE LAYER FOR AI-ASSISTED WORK

Keep AI work
from tangling.

Warpthread gates a change against your recorded intent only where it matters, and joins who acted on which route — with what verdict and cost — into one portable receipt. It verifies that what an agent claims matches what it did. Your content never leaves your hands.

PROMISE_VIOLATEDSURFACE_MISMATCHPROVENANCE_BLURROUTE_OKCONTENT_STAYS_YOURS

Metadata-only by default — Warpthread holds the receipt, never your prompts or documents. Bring your own keys and your own trace store.

SAMPLE · SCOPE GATE RECEIPT
illustrative mockup — one change that broke a commitment; most flow through
SCOPE GATEENG-1041auth/session.ts14:22:08BLOCKED
PROPOSED CHANGE · CLAUDE-OPUS-4
Refactor session token rotation to use sliding expiry window
3 files+47 linescloud lane
BACKLOG CONTEXT · CODEX REVIEW
ENG-1041 Session tokens expire too aggressively for mobile clients. Codex flagged: overlaps with ENG-982 (token refresh race condition, unresolved)
RECORDED INTENT · YOUR CONSTITUTION
Token lifetime must not exceed 24h per compliance review. Any sliding window implementation requires explicit security sign-off.
Recorded 2025-06-18 · lives in your store
ACTIVE SIGNALS
CRITICAL
PROMISE_VIOLATED
P-022 requires security review before any auth change
WARNING
SURFACE_MISMATCH
auth/session.ts not in declared scope for ENG-1041
WARNING
PROVENANCE_BLUR
Codex review context references unresolved ENG-982
INFO
VERIFY_OK
claimed change matches the artifact produced
TOUCHED PROMISES
P-014Session tokens expire within compliance windowat-risk
P-022No auth changes land without security reviewviolated
P-031Token refresh is atomic across mobile/webunknown
MODEL ROUTE / LANE
claude-opus-4codexgpt-oss-120b
cloud · local available · BYO keys
AGENT PROVENANCE
14:20:11claude-opus-4readauth/session.ts
14:20:44claude-opus-4readauth/token.ts
14:21:03claude-opus-4readconfig/execution
14:22:08claude-opus-4proposeauth/session.ts
THE RECEIPT · METADATA ONLYBLOCKED
verdict blocked
touched P-022 (binding) · P-014 (at-risk)
route claude-opus-4 · cloud lane
decided_by policy — model narrated the why
cost / latency $0.004 · 1.3s
trace → your own store (we hold the pointer)
CASE RECORD OUTPUT
case_id CR-2024-0892
status blocked — awaiting security review
resume after security-review.md recorded
▸ portable receipt · your content never left your store
100%
of gates leave a portable receipt
metadata-only
your content stays in your store
BYO
your keys, your observability
no embeddings
structured records, portable, fast
WHAT IT DOES

The receipt for every AI change — without the content.

GATE
Gates a change against recorded intent

Before a change lands, Warpthread checks it against your locked decisions and touched promises. The verdict is policy over your records — not a model's opinion. Good work flows through; it stops only what breaks a commitment.

RECEIPT
Every change leaves a portable receipt

Who acted · the route it ran · the verdict · the promises it touched · the trace · the cost — joined into one record you own. The receipt is the product, and it travels across agents, sessions, and models.

VERIFY
Checks the claim matches the work

Agents over-claim. Warpthread checks that what an agent says it did matches the artifact it actually produced — a second opinion that reads the work, not the summary.

PRIVATE
Your content never leaves your hands

Warpthread holds the receipt — the structure and provenance — never your prompts, docs, or quotes. Point it at your own trace store: we keep the metadata, you keep the content.

DRIFT
Surfaces surface-mismatch and provenance blur

When a model touches a file outside the declared scope, or review context references unresolved work, Warpthread surfaces it before the change merges.

RESUME
Closes work into resumable case records

Blocked, deferred, or cleared — each gate closes into a case record with a resume pointer. Pick the exact thread back up in any session, on any model.

HOW A GATE WORKS

The verdict is policy. The model only narrates.

From proposal to receipt, Warpthread keeps the thread intact across agents, sessions, and models — and decides with reproducible policy, not a model's judgment. Nothing lands without a gate; nothing is lost without a record; nothing of yours leaves your store.

  1. 01
    An agent proposes a change

    Claude, Codex, or any connected model proposes a change. Warpthread intercepts and opens a gate.

  2. 02
    The gate checks recorded intent — as code

    The contradiction and verbatim-quote checks run deterministically over your locked decisions. The verdict is reproducible policy, not a model's judgment call.

    PROMISE_VIOLATED · P-022 requires security review
  3. 03
    The model narrates the why

    Once the verdict is decided, a model writes the plain-language summary and recommendation. It explains the call; it doesn't make it.

    BLOCKED · token lifetime exceeds the recorded 24h limit
  4. 04
    Verify — does the artifact match the claim?

    Warpthread checks the produced work against what was claimed and flags any mismatch — the second opinion that can't be talked past.

    SURFACE_MISMATCH · auth/session.ts not in ENG-1041 scope
  5. 05
    The case record closes — content stays yours

    The gate closes into a portable receipt with a resume pointer. The trace lives in your store; Warpthread keeps only the metadata.

    CR-2024-0892 · resume after security-review.md
Stop watching AI work tangle.
Warpthread is available for early-access teams running concurrent model activity across sessions — metadata-only, bring your own keys and trace store.