Chorix · Judgment Layer

A human ruling,
inside the system.

The Judgment Layer puts a person's ruling inside any graph, agent or orchestration system, and keeps a signed record of every one.

Your system poses a decision with its recommendation. A person rules on it with one of five verbs. Your system resumes on that ruling. Every pose, ruling and acknowledgment is kept in a record you can export and verify offline.

For the people who answer for the outcome: finance, legal, compliance, operations, and the engineers who build for them.

The principal's desk: five tallies across the top reading one coherence, and three decision cards on the deck. The first asks whether to delete 1,204 customer records, with three options, the agent's recommendation marked, and the verbs approve, reject, steer, stop and HOLD. The second shows a steer, the agent's account of what it did, and the five acknowledgment classes. Passkeys and agent connections are in a panel on the right.
Your system

poses the decision and pauses.

A person

rules. Nothing else can.

Your system

resumes on the ruling and accounts for the work.

The record

keeps all of it, signed.

Agents act quickly.
Someone still answers for the act.

A payment, a deletion, a deployment, a clause sent to the other side. Once software can do these, the question is who decided, on what, and whether that can be shown afterwards.

Authority

An approval that software can press is not an approval.

If the agent holds the same key as the person, the control is a formality.

Evidence

A yes in a chat thread is not a record.

It does not say what was asked, what was recommended, what was chosen, or what was then done.

Memory

The same question is asked again next month.

What the same person ruled last time, and why, is rarely in front of whoever rules next.

One layer, placed between
two you already have.

The Judgment Layer goes into a system that already works. It sits before the step that acts, holds that act until a person rules, and hands the ruling back.

  1. Above · yours

    Your graph, agent or workflow.

    It reaches an act it should not take alone, poses the decision, and pauses.

  2. The Judgment Layer

    The pose, the authority, the ruling, the record.

    It files the question, finds who may rule, checks that a person did, and returns the ruling.

  3. Beneath · yours

    The act itself.

    The payment, the deletion, the deployment. It runs only after the ruling, and its account goes back on the record.

The withheld content never passes through the Judgment Layer. Your system holds it and delivers it unmodified.

Pose, pause, rule, resume,
account, acknowledge.

  1. Pose
  2. Pause
  3. Rule
  4. Resume
  5. Account
  6. Acknowledge

The whole integration is a handful of tool calls, one pause in your system and one resume.

  1. Your system poses.

    A question, one to eight options, its own recommendation, and the scope of the act. The recommendation is committed before any verb exists.

  2. Your system pauses.

    Interrupt, checkpoint, park the job. Nothing executes while the act is withheld.

  3. A person rules.

    On the desk, with one verb. The options are shown in shuffled order, so the recommendation is never simply the first.

  4. Your system resumes.

    The ruling comes back once, in three shapes: generic, LangGraph, and the Judgment Layer's own.

  5. Your system accounts.

    When the work is done it files what was actually done, against the same row.

  6. The principal acknowledges.

    The person reads the account and classes the outcome. Only acknowledged rows are counted.

What a steer returned to the system · agent door, await_ruling
{
  "verb": "steer",
  "outcome": "deliver",
  "destination": "drafting",
  "instruction": "Take the cap at twenty-four months. Keep the
                  data-breach carve-out, and say why in the cover note.",
  "content": "unmodified",
  "generic": {
    "proceed": true,
    "next": "drafting",
    "stop": false,
    "waiting": false
  }
}
A decision card after a steer: the question about clause 9, the line The agent picked a, you steer a, your words, then The agent did with its account, and the question Which of the five was the actual resolution with the buttons coherence, override, divergence, arbitration, reconciled and conformance
The same decision on the desk, after the system filed its account: what the agent picked, what the person ruled and in what words, what was done, and the acknowledgment still owed.

The JSON is the product's own answer on the capture run, shortened to the fields shown; the instruction is wrapped here for width.

Five verbs and one control.
Nothing else exists.

A ruling is one verb on one decision. A condition attached to a yes is a steer, in the person's own words.

approvedeliver

The chosen option goes ahead, and the handoff is delivered unmodified.

steerdeliver, with words

It goes ahead with the person's instruction beside it. The content itself is never edited.

rejectrefuse

None of these. Your system takes its refusal path.

stopend

The run ends.

redirectstill withheld

The open decision passes to the next approver, or a named one. Your system stays paused.

HOLDstill withheld

A deliberate not yet. It rules nothing and the decision stays open.

An open decision card: Delete the 1,204 customer records the retention job flagged, three options with Delete the 1,187 with no open dispute marked agent recommends, the line saying which option the agent recommends and that the slot is randomised, and the verbs approve, reject, steer, stop and HOLD, with the line posed by records-retention workflow
An open decision on the desk. The question, the options with the recommendation marked, the verbs, and where the pose came from. Redirect appears once approvers are enrolled.

Routing is data on the options, never a new verb: an option can name where the handoff goes if it is the one approved.

One page,
where the ruling is made.

The desk is a page on the machine that runs the Judgment Layer. It asks for a sign-in, then shows what is waiting.

ON THE DECK

Every decision waiting, as a card.

Pick an option and press a verb. Steer and redirect ask for words first. A card stays until the work is accounted for.

THE FIVE TALLIES

Coherence, override, arbitration, divergence, conformance.

Counted from acknowledged rows only. Arbitration sends the work back for another pass.

THREADS

Each decision under the thread that posed it.

Named as your system names it: the framework, the thread or run, the node, with where each one stands.

BOOTH · PODIUM · LEDGER

Three more ways to see the same deck.

The Booth docks the Podium, one decision at a time on a ring of the verbs. The Ledger window carries the live tallies, the blind trial, the domains and the recent record.

Your system does not need the desk to be open. A pose waits on the record until someone rules, and the ruling waits there until your system reads it.

The Threads view: four threads, each named with its framework, workflow, agent connection and node, and under each its decision with a state: executing, to acknowledge, to rule, and coherence
Threads. Four systems, four decisions, each where it stands.
The Booth: the same deck of decision cards on the left and the Podium docked on the right in a handset frame, showing one decision above a ring of the verbs steer, stop, deny, hold, approve and redirect
The Booth, with the Podium docked beside the deck.
The Ledger window: five tallies with one coherence, a row of counts, the blind trial line, one steer awaiting check-off with its words quoted, the domains spend external and deploy website, and the recent record
The Ledger window: tallies, the blind trial, the domains, the recent record.

Every capture on this page is the product itself, run from the bundle on a spare port with a scratch record and four poses written for the purpose. Its title bar still reads Judgment Ledger. The says exactly how.

The agent cannot rule,
because the tool is not there.

The Judgment Layer speaks MCP, the Model Context Protocol, through two separate doors. They never share a key.

The agent door · 15 tools

What you give your graph, agent or workflow.

  • pose a decision and wait for the ruling
  • read precedent for a scope
  • file its account of the work
  • read the record and check it

It cannot rule, acknowledge or change who has authority. Those tools are absent from this door, not merely refused.

The authority door · 39 tools

For the people who rule.

  • the verbs and the acknowledgments
  • approvers, grants and escalation chains
  • principals, agent connections and passkeys
  • the licence, the corpus and the sealed export

Every tool that rules, acknowledges or changes authority needs a human credential, and the core checks it.

Agent connections

One credential per connected system.

Each graph, agent or workflow has its own, with its own permissions. Every pose is stamped with the connection that made it.

Scope

A closed register of acts and surfaces.

Ten acts, from read to spend, on ten surfaces. A pose outside it is refused. Your own words for acts are aliases onto it.

Precedent

Shown as information, never applied.

What the same person ruled before in that scope, in their words, is put beside the new decision. Nothing rules by precedent.

The desk on first sign-in: the tallies at zero, an empty deck, and a panel headed Enrol your passkey saying that every ruling and acknowledgment asks for the passkey, with a setting for who needs a passkey to rule
The desk on first sign-in. The passkey comes before anything else.

Every ruling carries
proof of a human hand.

A credential is a file, and a program running as you could read a file. A passkey, confirmed with a PIN or a fingerprint on the person's own device, is what a program cannot supply.

BY DEFAULT

The principal and every approver.

A new installation asks for a passkey on every ruling and every acknowledgment. Lowering that is the owner's act, takes the owner's passkey, and shows a plain warning first.

BOUND

The passkey signs the exact act.

The row, the verb, the option, the words. A submission that differs from what was signed is refused.

FIRST

No agent connection before the owner's passkey.

The product creates none at first run. The owner enrols a passkey on the desk, then creates each connection there.

The product says this itself: run agents under a separate operating-system account or in a container, not as yourself.

When the decision is not yours alone,
the chain finds who may rule.

An organization can name approvers and escalation chains. While your system is paused, the Judgment Layer locates authority along the chain by the clock. Approvers are never counted in the price.

Grants

Authority with a shape.

Which verbs, over what scope, in what position on the chain, up to what amount, until when. Single or dual decision.

Notices

By email, webhook, Slack or the console.

The person next in the chain gets a notice with a single-use code, on their own channel.

Attribution

Who held it, when, and what was tried.

Every ruling is recorded with who made it. A late, out-of-scope or unproven attempt is refused.

Off the network · off by default

The hosted relay.

An approver elsewhere can rule from a page on the Chorix Studio site. Your machine fetches the ruling and applies it itself. The site's half is to build.

Ruling from a phone on the same network is disabled in this release, pending a security review. The Podium and the Booth open on the machine that runs the Judgment Layer and nowhere else.

Signed on your machine.
Checked without us.

Every write is an event on a hash chain. An export of the record is sealed with a key made and kept on your own machine.

OFFLINE

One file checks it. No network, no account.

The verifier ships in the bundle. It confirms the seal, that every event follows the one before it, and that every row is the state its last event recorded.

A REWRITE SHOWS

Compare a newer export with an older one.

The older export's past must be the newer one's past. The verifier says plainly what it cannot prove alone, and that this comparison is what exposes it.

NEVER DELETED

A judgment is not retracted.

An open decision can be withdrawn. A ruled one can be reopened for another pass, linked to the first. Neither removes what happened.

BACKUP

One command, while it runs.

Records, registry and licence, with a manifest of hashes. Restore refuses a backup whose files do not match it.

The bundle's verifier on an export of the capture run
> node tools/verify/chorix-record-verify.mjs export.json
VALID -- chorix-record-export of workspace 91afccb8-…
  seal: verifies (key 5bsec/40b3UsKuA=)
  head: seq 15 3f7334b5998d354d...
  chain 91afccb8: 15 events, 7 rows matched, 0 pre-genesis
  chain *: 0 events, 0 rows matched, 0 pre-genesis

Printed by the verifier in the bundle, exit code 0, on the record the captures on this page came from. The workspace id is shortened here.

It runs on your machine.
What leaves it is printed, in full.

The copy on your machine is the original. It stays readable and exportable there with or without the service, paid or not.

On your machine

The core, the desk, the record.

  • one data folder holds everything it keeps
  • the signing key and the credentials never leave it
  • the withheld content never reaches the Judgment Layer at all
  • no model runs in it, and nothing is used for training
Leaves it · on by default

The hosted record: a signed copy on the Chorix Studio site.

  • every decision, ruling, account and acknowledgment, words included
  • kept so the record can be read and exported if the machine is lost
  • SPEKTX can read it; it is not encrypted against us
  • the owner turns it off with a passkey; the copy is then offered as a final export and deleted after 30 days

The product prints what it sends when it starts, and shows the same list on the desk. The site's side of the hosted record, where it is read and exported, is to build.

Your system keeps its own pause.
The gate is a few calls.

Any MCP client can call it over stdio or streamable HTTP. The bundle ships a gate for LangGraph in Python that needs only the standard library, a gate for Node, and the contract for everything else.

SystemIt pauses withIt resumes withIn the bundle
LangGraph · LangChain agentsan interrupt in the gate nodea Command; the node re-runs and reads the ruling by its decision keythe LangGraph gate
LangSmith Deploymentthe thread is interrupteda poller waits for the ruling, then starts a run on the threadthe same file
CrewAI · AutoGen · OpenAI Agentsa tool that blocks, or a task that parksthe tool returns the generic resumethe MCP tools, called directly
Temporal · Step Functions · a queuean activity that returns waitingthe activity reads the ruling and returns itthe Node gate or the Python class
n8n · Make · Zapieran HTTP node posting to the doora wait node, then a read of the rulingnone needed
Claude Code · Codex · any MCP clientthe tool call itself waitsthe tool resultthe stdio door
Idempotent

A node that re-runs never poses twice.

A stable decision key returns the existing row with its ruling.

Fail closed

A wake-up is not a ruling.

Whatever resumes your system, the gate reads the ruling from the record. A resume that arrives early pauses again.

Requirements

Node.js 24 or later.

Windows, macOS or Linux. Unzip, put the licence file beside START, run START.

SPEKTX is not affiliated with LangChain, Inc. or any other orchestration vendor, and none of them endorses this product. Each name belongs to its owner.

An honest look
at what exists.

Walked means it was done on the bundle itself for this page, with the result on file. In the bundle means it was read in the bundle's code and its own documentation and not walked here. To build is not there yet. Every row still owes the principal's own walk.

The productOn the machine
0.12.0the bundle
Pose, ruling, resume, account, acknowledgmentWalked
Two doors: 15 tools for agents, 39 for authorityWalked
Passkey on every ruling; agent connections after itWalked
Desk, Threads, Booth, Podium, Ledger windowWalked
The desk in black and purple, with the markWalked
Sealed export and the offline verifierWalked
Approvers, grants, escalation, noticesIn the bundle
LangGraph and Node gatesIn the bundle
Backup and restoreIn the bundle
Around itThe service
Draftthe agreement
Licence: paid, grace, lapse; records never lockedIn the bundle
Hosted record: the machine's sending sideIn the bundle
Hosted record: reading and export on the siteTo build
Hosted relay for approvers off the networkTo build
Checkout, account page, licence issue and renewalTo build
Ruling from a phone on the same networkDisabled
The subscription agreementDraft
The name in the product: Judgment LayerTo build

Per organization.
Never per person who approves.

A subscription, tiered by the number of principals and the number of connected systems, whichever is exceeded first. Approvers are never counted. There is no free tier. Annual is ten months' price.

Judgment$99 a month
  • up to 5 principals
  • up to 10 connected systems
  • approvers without limit

$990 a year

Team$199 a month
  • up to 15 principals
  • up to 30 connected systems
  • approvers without limit

$1,990 a year

Business$349 a month
  • up to 40 principals
  • up to 80 connected systems
  • approvers without limit

$3,490 a year

Enterprisefrom $999 a month
  • 41 principals or more
  • connected systems by order
  • approvers without limit

by order

If a payment is missed

Fourteen days of grace.

Work continues. After that, new poses are refused, and the calling system is told why.

No stranded run

Open decisions stay rulable for seven days.

A paused run is not left hanging by a payment event.

Always yours

The record is never locked.

Records, exports and the corpus on your machine stay readable whatever the licence says.

A principal is a person whose judgment the record captures. A connected system is one graph, agent or workflow with its own credential. Checkout is not open; these are the figures the product itself enforces.

Risk controls,
not guarantees.

Plainly

It withholds an act until a person rules.

It does not promise that a person will rule within any time, that your system will honour the ruling, or that your own pause and resume will work. A ruling is the act of the person who makes it.

Not for

The sole control where failure costs a life.

Life support, emergency response, medical treatment, aviation or vehicle safety, industrial safety interlocks, and uses like them.

Built inside Chorix, for Chorix.
Now offered alone.

Chorix is human-governed orchestration of several AI models, and its Ledger is where its principal rules. The Judgment Layer is that ledger, its judgment and its governance of approval, cut out to stand alone inside a system someone else built.

The short
answers.

No. The door an agent is given carries no tool that rules, acknowledges or changes authority. Those tools are on a second door that opens only on a human credential, and by default every ruling also needs that person's passkey.

One layer · between the system and the act

The system proposes.
A person rules. The record shows it.