Kijestic Acceptance 0.2.1. In private validation.
Don't trust done. Check it.
Define what done means before the work starts. Kijestic Acceptance checks the available evidence and shows what passed, failed or remains unproven.
In private security and reliability validation. Not publicly available yet.
An MCP server and a command-line tool, designed to run on your own machine.
good -> ACCEPTED passed: revenue_reproduces, note_sections, note_figure_matches, no_guarantees clearly_written: MISSING; no evidence: add a probe, or (judgment checks only) a review claim supported: The revenue figure reproduces from the model inputs. claim withheld: The note is clearly written. bad -> REJECTED revenue_reproduces: FAIL; computed 3000 != claimed 3200 note_sections: FAIL; heading_missing:'Assumptions' no_guarantees: FAIL; forbidden_present:'guarantee'
The rule that matters
An agent saying its work passed is a claim, not evidence.
AI agents report that the tests pass, the page is live and the source says what they quoted. Sometimes that is true. For factual checks, Kijestic Acceptance does not take the report. It runs the checks itself and records what it could show.
If an agent hands in "tests: pass", the receipt records it as an asserted claim and the check stays unproven.
What a run does
Contract, evidence, verdict, receipt.
-
Contract
Before the work, write what done means as checks that could fail, each tied to a deliverable: a file, a folder, a URL or a piece of text.
-
Evidence
The evaluator runs each check itself: a command you allow, an HTTP request, or an inspection of the file. The work can be done anywhere, by an agent, a script or a person.
-
Verdict
Accepted, staged, rejected, waiting on owner, or contract invalid. Staged means the evidence is missing or inconclusive.
-
Receipt
A JSON record of every check, every piece of evidence and where it came from, and which claims are supported and which must be withheld. Anyone holding the receipt can check it again.
Reading a verdict
Accepted is not released.
Accepted means every blocking check in the contract passed, for this exact version of the deliverable, on evidence the evaluator could admit. It does not mean:
- The contract asked the right questions. A weak contract gives a weak acceptance.
- The work was released. Every receipt says release: UNRELEASED.
- The intended outcome happened. Every receipt says realized_outcome: UNMEASURED.
- Anyone is authorized to act on it. Every receipt says grants_authority: false.
- The receipt came from who it says. Receipts carry SHA-256 digests, not signatures.
{
"format": "kijestic.acceptance-receipt/2",
...,
"verdict": "REJECTED",
"states": {
"acceptance": "REJECTED",
"release": {
"status": "UNRELEASED",
...
},
"realized_outcome": {
"status": "UNMEASURED",
...
}
},
"grants_authority": false,
...
"integrity": {
"method": "sha256-canonical-json",
"signature": null
}
}
Where it stands
What has been tested, and what has not.
| Automated tests | The automated test suite passes on Windows with Python 3.12, including the MCP server over real stdio. Linux and macOS have not been run. |
|---|---|
| Platforms | An install from the repository was run on Windows with a fresh cache. |
| AI tools | The Claude Code and Codex install steps were checked against each tool's own validator or command help. Neither has been run end to end inside the tool yet. |
| Security review | Four rounds of adversarial security review by a fresh AI session from the same vendor (process and session independence, no vendor independence). Round 1 found four high-severity problems. Round 4 left none open at critical or high. It is our own review, not a third-party audit. |
| Users | None outside Kijestic yet. |
Why we built it
Agents told us work was done when it was not.
False "done" reports from AI agents are a recurring, documented problem in our own work. A result handed in by the thing being checked is a claim, not evidence.
So in Kijestic Acceptance the evaluator collects its own evidence for factual checks, and anything the caller supplies is labelled asserted.
Limits
What it does not do.
- It is in private validation. The method has not been calibrated on a large set of real deliverables, and no error rates are published.
- Receipts are not signed. The digests show a receipt is internally consistent, not who produced it.
- A contract can still be weak. The built-in profiles set a minimum, not a standard of quality.
- A command that a contract runs has your account's permissions. Command checks are off by default in the MCP server. Read a contract before you allow them.
- Not built yet: signed receipts, a hosted record store, team review, checks for email or payments, and a remote server for ChatGPT.
- No certification and no outside audit.
Want AI systems built and run for your business? That is Kijestic AI.
Questions: kelvin@doorstopper.io
Kijestic Acceptance is a product of Kijestic.