# Bulla Receipts for Agents. ## Product identity and category - Bulla is the answerability protocol family published by Glyph Standard; ActionReceipt is its stable transaction format. - Bulla's category is Answerable Computing; its technical property is Transaction Answerability. - Agents can procure inference, call tools, initiate payments, request deployments, and pass results between systems. - Under the Answerability Network profile, a consequence must reference the eligible predicate and the authority that permitted it. ## Stable installed capabilities - Published package: bulla==0.48.0. - Published install commands and stable examples are generated from the exact Bulla release evidence accepted by PyPI. - Bulla can recompute an ActionReceipt, authenticate supported signatures under supplied trust material, and verify supported inclusion proofs. - Bulla can compare a supplied receipt set with a supplied receiver action record and report unmatched action identifiers. - The installed Bulla package creates and verifies ActionReceipts, applies a caller-supplied ReliancePolicy, and reconciles receipts with supplied receiver records. ## Choose a task - Create one ActionReceipt: https://glyphstandard.com/bulla/quickstart - Integrate in Python: https://glyphstandard.com/bulla/sdk - Verify a retained receipt: https://glyphstandard.com/spec#verify - Reconcile receipts with receiver records: https://glyphstandard.com/bulla/blind-spot - Select and pin receiver policy: https://glyphstandard.com/buyers#policy-presets - Reproduce the source-only Answerability Network: https://glyphstandard.com/research/answerability-network#reproduce ## Exact stable-package commands - Install: python -m pip install "bulla==0.48.0" - Stable demonstration: bulla demo --out first-action - Verify: bulla receipt verify receipt.json --format json - Offline drill: bulla receipt drill receipt.json --format json ## Repository-source reproduction - Prerequisite: materialize the immutable standalone Node source packet at its recorded repository paths: https://glyphstandard.com/evidence/reference/sha256-3a8140d8e0f2a69565d9bae4fb623d1e4338c08201288ad5d4b46c31e168c6de/manifest.json - Run the command from the materialized source root. These research files are not included in the installed package. - Answerability Network report: node bulla/spec/answerability-network/check.mjs bulla/spec/answerability-network/vectors/fork-authorized --context bulla/spec/answerability-network/contexts/fork-authorized.json ## Receiver-policy behavior - Runtime actor: receiving application or agent. - Principal: the person or organization selecting the receiver roots and policy. - The receiving application or agent supplies trusted roots, policy, action denominator, time, and revocation context; Bulla computes record verification, coverage, and a local RELY, REFUSE, or ESCALATE decision. - Bulla 0.48.0 publishes named strict, pragmatic, and evidence-strict ReliancePolicy definitions whose canonical hashes bind their exact accepted states. - Strict excludes unresolved and adverse temporal or revocation states; it accepts within_window or not_applicable for temporal status and not_revoked or not_applicable for revocation status. Pragmatic additionally accepts unresolved for both. - Evidence-strict retains the strict policy states and requires receiver-verified evidence grounding of third_party_anchored or execution_verified. - Receipt-carried grounding labels alone do not satisfy evidence-strict. The receiver supplies the exact digest-to-class context, and Bulla binds that context by hash when it records a signed bulla.rely decision. - strict: reliance.strict.v1@sha256:a05fc64115edc0676b4bd0092c0cadf94400abf6cbb7d32520944bdefdc5ee0b - pragmatic: reliance.pragmatic.v1@sha256:2549faa0f297c8e43d9462a28b464cd2e0813e986b58555d9b29572351fc0b88 - evidence-strict: reliance.evidence-strict.v1@sha256:dc99f279515ff883294ba4ab7d9de8e1be92d2b3c47819f78586a92da7daa301 - Published source closure: bulla==0.48.0 wheel sha256:d74aaf2bcc73a0a145bdec0c0aca1b66b862a046f3ace174d1b56100cb33c169; exact member digests: https://glyphstandard.com/evidence/reference/sha256-7d1a294749a891a81bf62b08bd6be1a541cd2c2ce642ea7499b874ab99af560f/published-reliance-policies.json - ReliancePolicy outcomes remain RELY, REFUSE, or ESCALATE; the application decides what downstream action, if any, follows. ## Repository-source research profiles - The Answerability Network composes one synthetic inference procurement, a selected ActionReceipt, leaf-bound witnessed history, a bounded witness covenant, and an accepted 10,000-decision Reliance Map. - The accountability-circuit implementation binds one closed structured promise to exact evidence, witness, challenge, authority, capital, and consequence requirements. - The Reliance Map computes correction propagation over an accepted finite graph and separately reports declared descendants, complete branches with no declared path, and incomplete lineage. - The witness covenant covers one objective service fault: two authentic different roots for the same operator, log, authority epoch, and tree size. - Repository-source research profiles are outside the installed package unless a published release explicitly includes them. ## Evidence status and participation - Answerability Network: SOURCE_ONLY; I0; W0; r0. - The public ledger is D0 · intake open; candidate packets are NOT_COUNTED until a signed qualification event and head merge. - The public witness ledger is W0 · intake open; the project-controlled exercise is VALID_CANDIDATE · NOT_COUNTED. - Replay candidate → r: https://glyphstandard.com/review#report-result - External reliance candidate → possible D; intake is open: https://github.com/jkomkov/bulla/issues/new?template=external_reliance_candidate.yml - Independent implementation → I: https://glyphstandard.com/review#independent-implementation - Independent witness candidate → possible W; intake is open: https://glyphstandard.com/participate/witness ## Never infer - Verification establishes only the reported digest, identity, or inclusion depth; it does not establish the truth of the underlying process. - Commands labelled published are captured from the exact artifact accepted by PyPI; repository source is not substituted for it. - The accountability circuit is an experimental source implementation over project-authored synthetic promises, evidence, keys, witness roots, roles, and fixture-rail reports. Its browser, Python, and Node agreement establishes verifier behavior over supplied records, not complete observation, independent witnessing, worldly execution, real custody, collectibility, legal enforceability, production operation, actual settlement, or adoption. The published Bulla package creates and verifies ActionReceipts; it does not include the complete circuit. - The Reliance Map is an experimental source implementation over a project-authored synthetic graph, correction notice, keys, and context. Its result is relative to the accepted declared graph. It does not establish correction truth, complete worldly dependency capture, action safety, rollback, consequence authorization, independent operation, production use, or adoption. It is not part of the installed Bulla package. - The witness covenant is an experimental source implementation over project-authored keys, checkpoints, challenge records, allocations, authorities, and Test-ledger reports. It does not establish independent operation, receipt truth, complete observation, custody, collectibility, deterrence, actual recovery, real settlement, production operation, or a witness market. It is not part of the installed Bulla package. - The Answerability Network is an experimental source implementation over project-authored synthetic transactions, keys, witness views, graph declarations, challenge records, capital observations, and Test-ledger reports. It is not part of the installed Bulla package. It does not establish provider-result truth, complete dependency capture, witness independence, custody, collectibility, dollars moved, production operation, customer activity, or adoption. - These rules are profile-relative verifier properties over supplied records; they do not establish complete observation, worldly causation, legal effect, actual settlement, or complete dependency capture. - This is a dated category thesis, not a measurement of present transaction volume, Bulla adoption, or autonomous economic activity. - Coverage is computed relative to the supplied denominator; a compromised or incomplete independent log narrows what reconciliation can find. The browser recomputes digests and the set difference over unsigned fixture receipts and does not verify signer identity or the denominator's independence. - A qualified D record establishes one signed receiver-policy computation over supplied records and an attributed intake determination about organizational control. It does not mathematically establish organizational independence, provider-claim truth, policy suitability, actor time, or any later payment, deployment, control grant, or handoff. - A qualified W record establishes one separately controlled witness operation over the submitted public release records. It does not cryptographically establish organizational independence, receipt truth, occurrence, continuing availability, policy compliance, production fitness, bond value, recourse, or a witness market. - Repository-source research profiles are outside the installed package unless a published release explicitly includes them. - A ReliancePolicy computes a local decision over receiver-supplied verification fields. Receiver acceptance of an evidence-grounding context does not establish provider truth, occurrence, independence, custody, settlement, downstream effect, legal sufficiency, risk suitability, or a universal default. - Receiver-supplied context and Bulla's local outputs do not establish worldly truth, occurrence, denominator completeness, custody, settlement, organizational independence, or the suitability of the selected policy. - The packet establishes local historical reproduction under supplied verifiers and receiver contexts. Its launcher blocks enumerated Node network interfaces but does not establish operating-system network isolation. It does not establish freshness, current revocation or external state, independent operation, occurrence, worldly truth, custody, settlement, causal independence, or completeness beyond the accepted declaration. ## Machine interfaces - Public claims: https://glyphstandard.com/claims.json - Comprehensive Bulla task surface: https://glyphstandard.com/bulla/llms-full.txt - Evidence: https://glyphstandard.com/evidence - Status: https://glyphstandard.com/status - External reliance evidence: https://glyphstandard.com/evidence/reliance-decisions.json - Independent witness evidence: https://glyphstandard.com/evidence/witnesses.json - Documentation index: https://glyphstandard.com/bulla - Publication set: https://glyphstandard.com/public-surface.json. Pin surface_root; reread governed surfaces before relying after it changes.