Human oversight for AI agents: block a tool call on a verified human, with on-chain proof.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
An AI agent stops mid-payment and pays a live, verified human for permission to continue.
An AI agent hits a policy threshold and is stopped by an HTTP 402. It pays $0.42 in USDC on Hedera to open a decision. A human witness who is not the operator proves liveness with World ID, bound to the hash of that exact decision, and approves or refuses inside 60 seconds. The default is refuse. An attestation binding the decision hash, the liveness proof, the witness nullifier and a consensus timestamp lands on a Hedera Consensus Service topic with no admin key.
The product is the evidence, not the approval.
Built for ETHOnline 2026. Partners: Hedera (AI & Agentic Payments, Improve the Harness), World (Selfie Check), Arc (Best Agentic Economy with Circle Agent Stack).
Every AI agent framework already ships a human-approval interrupt. LangGraph has interrupt, Temporal has signals, OpenAI has needsApproval. They are free, already integrated, and they all produce the same artefact:
That row is written by the system being audited. It is editable by the party being audited. And it contains no evidence that a human, rather than the agent's own service account, produced it.
Since 2 August 2026, the EU AI Act's obligations bind deployed high-risk systems. Article 12(3)(d) requires "the identification of the natural persons involved in the verification of the results", and Article 14(4) requires that such systems be "effectively overseen by natural persons" who can "interrupt the system". Both bind every high-risk deployer.
Article 14(5) goes further and requires "at least two natural persons" β but read its opening clause: "For high-risk AI systems referred to in point 1(a) of Annex III", which is remote biometric identification. A supplier-payment agent is not that, so 14(5) does not bind this example deployer. We build to it anyway, because it is the strictest oversight bar the Act names and the evidence is identical either way. The scope is set out in full here.
A self-written, self-editable log satisfies neither.
Proctor binds four things a self-hosted approve button cannot:
signal, not to "a human approved something at some point"Any third party verifies the whole record offline, against Hedera's mirror node and World's own verifier, without trusting Proctor.
No wallet, no API keys, no feature flags. This runs the entire oversight loop:
Unconfigured, this runs the full loop and produces a record that is deliberately
NOT independently verifiable β it is signed with a published demo key and never
reaches a topic. bun run demo says so in its own closing line, and bun run doctor
lists exactly what is missing. The difference between "it ran" and "it produced
evidence" is the entire product, so the tooling refuses to blur it.
And the outcome an auditor actually cares about:
Two checks, two different claims. The first proves nothing was altered. The second proves nothing was withheld β an operator who never submits a record breaks no hash.
Zero dependencies. node:crypto only. It contacts Hedera's public mirror node and nothing of ours.
Every row is a link to a file range or a public explorer. Nothing here asks you to take our word.
| Claim | Verify here |
|---|---|
| Evidence topic exists with no admin key | HashScan 0.0.10390147 |
| The running hash chain verifies offline, from genesis | bun verify/bin/verify.ts --topic 0.0.10390147 |
| β¦and the implementation is dependency-free | verify/package.json β empty dependencies |
| The Java-framing footgun is real, not folklore | verify/src/runningHash.ts:56-62 + the failing-naive test in verify/test/runningHash.test.ts |
| Tampering is detected, naming the sequence number | docs/hashscan-links.md |
| The gate settles through Blocky402 | extra.feePayer: 0.0.7162784 in the live 402, docs/hashscan-links.md |
| The boot preflight stops a dead facilitator taking Hedera down | backend/src/lib/x402/server.ts:63 |
| A proof for another decision is rejected | backend/src/lib/world/verify.ts:104 |
| The operator cannot approve their own agent | backend/src/lib/world/verify.ts:123 |
| Second 61 is a hard refuse, arbitrated by Postgres | backend/src/lib/decision/lifecycle.ts:114 |
| Canonicalisation is RFC 8785, recursive at every depth | backend/src/lib/attestation/canonical.ts:37 |
| Independence is derived, never asserted | backend/src/lib/attestation/build.ts:179 |
| A decision withheld before submission is detected offline | verify/src/completeness.ts + bun verify/bin/verify.ts --topic <id> |
| Issuance numbers cannot be burned by a failed create | backend/src/lib/decision/issue.ts β counter and create share one transaction |
| Test fixtures cannot reach the immutable evidence topic | Org.attestable defaults to false; orgs opt in |
| Every 402 carries an EIP-712 offer we cannot later reprice | decode the payment-required header |
| HCS-14 UAID matches a fixed test vector | backend/src/lib/attestation/uaid.ts:77 |
| The export cites the Act provisions it speaks to | backend/src/lib/evidence/export.ts:110 |
Per Hedera's documentation: "if no adminKey is specified the topic is immutable."
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/proctor)<a href="https://allmcps.com/mcp/proctor"><img src="https://allmcps.com/api/badge/proctor?style=directory" alt="Proctor on AllMCPs" /></a>