The AI Loss Ledger
See the record →

The Coherence Layer for Agentic AI

Deploying AI agents is easy.
Trusting them is the hard part.

The moment an AI agent can act — pull a credit file, price a product, submit an application — a log after the fact stops being enough. Sheaf can stop the action that shouldn't happen, and prove the reasoning that did.

Risk control for agentic AI — give your agents more autonomy without taking the risk blind.

Three ways to deploy Sheaf → Measure · Gate · Orchestrate

The gap

Autonomy you can't stop, and a record you can't defend

Every institution is racing to move agents from pilot to production — agents that don't just answer, they take actions with real consequences. And the day you grant that, two questions replace “was it a good answer?”

Today the honest answer to both is no. You get autonomy, and you get a transcript. The transcript can't halt anything, and it can't reveal that two agents drifted into an incoherent picture of the world — each locally sensible, the whole thing broken underneath. That gap is exactly where agentic AI stalls before production in a regulated business.

What Sheaf is

Not who the agent is. Whether its reasoning holds together.

Sheaf is a supervision layer that wraps a group of working agents and does two things nothing else does: it halts an action before it happens when a human's sign-off is required, and it measures whether the agents were reasoning about a mutually consistent set of facts — as a score you can put on a page.

Most of the market calls itself “the trust layer for AI,” and nearly all of it means the same thing: identity — is this agent who it claims to be, is it authorised, can we prove it acted. Useful, and not what Sheaf does. Sheaf is the only layer that checks the agents' coherence, not their credentials. That ground is empty — and it's the ground that decides whether you can trust the output.

How it works

Five roles around every acting agent

The stop is instant and mechanical, so it is always reliable. The judgment sits beside the work, so it never becomes the bottleneck. You get both without paying for either.

Ledger
Before anything runs, the deployment declares the shared facts the agents reason over — an applicant's income, the loan-to-value, the rate, the risk tier — and the actions that require human consent. This is the rulebook everything measures against.
Gate In the path
Sits directly on every action. Simple and instant: if an agent is about to take a consent-listed action, the Gate blocks it before it fires. No AI in the way, no latency, no judgment call to get wrong — an unbreakable stop.
Witness Alongside
One per agent, watching quietly. It reads what its agent is reasoning and doing, and extracts that agent's claims about the shared facts — what it believes to be true about the world it's acting on.
Warden Red phone
When the Gate blocks an action — or the agents drift into contradiction — the Warden pauses the operation and puts it in front of a human: approve, deny, or step in. Nothing consequential happens without that door.
Reporter Continuous
Collects every Witness's testimony and continuously checks that it fits together. If two agents have quietly diverged, it catches the contradiction while it's happening and rings the red phone — then issues a coherence certificate when the run ends.
The move that makes it practical: the halt is dumb and instant, so it never fails; the intelligence runs off to the side, so it never slows the agents down.

The certificate is the product

A number a risk officer can sign

When a run finishes, Sheaf issues a signed record built on two genuine measurements — not a confidence percentage a model invented about itself.

H⁰ · consistent

Every agent's claims glue into one coherent view of the world.

1.00coherence — a global section exists
H¹ · contradiction

Each pair agrees, yet no single account holds them all — an irreducible loop.

0.41coherence — contradiction located

It's the same consistency mathematics used in signal fusion and formal verification — applied, for the first time, to overseeing agents that act. That's what lets a risk officer sign it, a regulator accept it, and a board rely on it.

How you deploy it

Three ways to put Sheaf in front of your agents

You choose how much Sheaf does — from a read-only check to actually stopping the action. All three give you the coherence certificate; two of them give you the hard stop.

Measure You enforce
Post your agents' outputs to one endpoint. Sheaf returns the coherence certificate and flags when they contradict — your system decides what to do. One API call, no change to how your agents run. The honest limit: if your agent acts anyway, Sheaf recorded the warning; it didn't stop it.
Gate via MCP Hard stop
Route your agents' tool calls through Sheaf over MCP. A contradiction physically parks the action until a human releases it — the agent can't skip the check. It's standard MCP work, not bespoke Sheaf code; you run the gate in front of your agents.
Orchestrate Hard stop
Let Sheaf convene the minds and return one answer. Attach the action it feeds, and a contradiction parks it automatically — no integration on your side. The turnkey option: measurement, answer, and the hard stop in a single API call.
Measurement is common to all three. The hard stop comes with Gate and Orchestrate; Measure advises, you enforce.

See it work

Don't take our word for it — watch the minds (dis)agree.

Ask any question. Five leading models answer it independently, and Sheaf computes the live H¹ inconsistency index — showing you the consistent core, and the exact contradictions that pairwise agreement hides.

The live H¹ demo

A genuine coherence measurement over five frontier models, in about a minute — no sign-up.

Try the live demo → Public · 5 models · real cohomology

Prepared demos for regulated workflows — AI mortgage advice & agentic renewal panels, shown on request.

What Sheaf checks

Three checks on every answer

Sheaf asks three questions about every answer. Against your source of truth: point it at the facts you designate as authoritative, and it flags any agent whose claims contradict them — where you have truth, it checks against it. A sanity check: even with no source, it flags values that are obviously false or impossible — a £1,000-trillion cost, a 400-year-old applicant. And does it hold together: it measures whether the agents were reasoning about a mutually consistent set of facts, and returns a single coherence certificate — H⁰ where it glues, H¹ where it can't.

What it catches is the failure that causes the incident: agents that look fine one by one but have silently pulled apart underneath — correct in the parts, broken in the whole. It runs on every case, at machine speed, and writes down that it looked.

“We deployed agents” and “we can prove our agents are trustworthy” are two very different sentences.
Sheaf turns the first into the second.

Sheaf — the coherence layer for agentic AI.
Stop the action that shouldn't happen. Prove the reasoning that did.