Every decision waiting, as a card.
Pick an option and press a verb. Steer and redirect ask for words first. A card stays until the work is accounted for.
A human ruling,
inside the system.
Your system poses a decision with its recommendation. A person rules on it with one of five verbs. Your system resumes on that ruling. Every pose, ruling and acknowledgment is kept in a record you can export and verify offline.
For the people who answer for the outcome: finance, legal, compliance, operations, and the engineers who build for them.
poses the decision and pauses.
resumes on the ruling and accounts for the work.
keeps all of it, signed.
A payment, a deletion, a deployment, a clause sent to the other side. Once software can do these, the question is who decided, on what, and whether that can be shown afterwards.
If the agent holds the same key as the person, the control is a formality.
It does not say what was asked, what was recommended, what was chosen, or what was then done.
What the same person ruled last time, and why, is rarely in front of whoever rules next.
The Judgment Layer goes into a system that already works. It sits before the step that acts, holds that act until a person rules, and hands the ruling back.
It reaches an act it should not take alone, poses the decision, and pauses.
It files the question, finds who may rule, checks that a person did, and returns the ruling.
The payment, the deletion, the deployment. It runs only after the ruling, and its account goes back on the record.
The withheld content never passes through the Judgment Layer. Your system holds it and delivers it unmodified.
The whole integration is a handful of tool calls, one pause in your system and one resume.
A question, one to eight options, its own recommendation, and the scope of the act. The recommendation is committed before any verb exists.
Interrupt, checkpoint, park the job. Nothing executes while the act is withheld.
On the desk, with one verb. The options are shown in shuffled order, so the recommendation is never simply the first.
The ruling comes back once, in three shapes: generic, LangGraph, and the Judgment Layer's own.
When the work is done it files what was actually done, against the same row.
The person reads the account and classes the outcome. Only acknowledged rows are counted.
{
"verb": "steer",
"outcome": "deliver",
"destination": "drafting",
"instruction": "Take the cap at twenty-four months. Keep the
data-breach carve-out, and say why in the cover note.",
"content": "unmodified",
"generic": {
"proceed": true,
"next": "drafting",
"stop": false,
"waiting": false
}
}

The JSON is the product's own answer on the capture run, shortened to the fields shown; the instruction is wrapped here for width.
A ruling is one verb on one decision. A condition attached to a yes is a steer, in the person's own words.
The chosen option goes ahead, and the handoff is delivered unmodified.
It goes ahead with the person's instruction beside it. The content itself is never edited.
None of these. Your system takes its refusal path.
The run ends.
The open decision passes to the next approver, or a named one. Your system stays paused.
A deliberate not yet. It rules nothing and the decision stays open.

Routing is data on the options, never a new verb: an option can name where the handoff goes if it is the one approved.
The desk is a page on the machine that runs the Judgment Layer. It asks for a sign-in, then shows what is waiting.
Pick an option and press a verb. Steer and redirect ask for words first. A card stays until the work is accounted for.
Counted from acknowledged rows only. Arbitration sends the work back for another pass.
Named as your system names it: the framework, the thread or run, the node, with where each one stands.
The Booth docks the Podium, one decision at a time on a ring of the verbs. The Ledger window carries the live tallies, the blind trial, the domains and the recent record.
Your system does not need the desk to be open. A pose waits on the record until someone rules, and the ruling waits there until your system reads it.



Every capture on this page is the product itself, run from the bundle on a spare port with a scratch record and four poses written for the purpose. Its title bar still reads Judgment Ledger. The says exactly how.
The Judgment Layer speaks MCP, the Model Context Protocol, through two separate doors. They never share a key.
It cannot rule, acknowledge or change who has authority. Those tools are absent from this door, not merely refused.
Every tool that rules, acknowledges or changes authority needs a human credential, and the core checks it.
Each graph, agent or workflow has its own, with its own permissions. Every pose is stamped with the connection that made it.
Ten acts, from read to spend, on ten surfaces. A pose outside it is refused. Your own words for acts are aliases onto it.
What the same person ruled before in that scope, in their words, is put beside the new decision. Nothing rules by precedent.

A credential is a file, and a program running as you could read a file. A passkey, confirmed with a PIN or a fingerprint on the person's own device, is what a program cannot supply.
A new installation asks for a passkey on every ruling and every acknowledgment. Lowering that is the owner's act, takes the owner's passkey, and shows a plain warning first.
The row, the verb, the option, the words. A submission that differs from what was signed is refused.
The product creates none at first run. The owner enrols a passkey on the desk, then creates each connection there.
The product says this itself: run agents under a separate operating-system account or in a container, not as yourself.
An organization can name approvers and escalation chains. While your system is paused, the Judgment Layer locates authority along the chain by the clock. Approvers are never counted in the price.
Which verbs, over what scope, in what position on the chain, up to what amount, until when. Single or dual decision.
The person next in the chain gets a notice with a single-use code, on their own channel.
Every ruling is recorded with who made it. A late, out-of-scope or unproven attempt is refused.
An approver elsewhere can rule from a page on the Chorix Studio site. Your machine fetches the ruling and applies it itself. The site's half is to build.
Ruling from a phone on the same network is disabled in this release, pending a security review. The Podium and the Booth open on the machine that runs the Judgment Layer and nowhere else.
Every write is an event on a hash chain. An export of the record is sealed with a key made and kept on your own machine.
The verifier ships in the bundle. It confirms the seal, that every event follows the one before it, and that every row is the state its last event recorded.
The older export's past must be the newer one's past. The verifier says plainly what it cannot prove alone, and that this comparison is what exposes it.
An open decision can be withdrawn. A ruled one can be reopened for another pass, linked to the first. Neither removes what happened.
Records, registry and licence, with a manifest of hashes. Restore refuses a backup whose files do not match it.
> node tools/verify/chorix-record-verify.mjs export.json VALID -- chorix-record-export of workspace 91afccb8-… seal: verifies (key 5bsec/40b3UsKuA=) head: seq 15 3f7334b5998d354d... chain 91afccb8: 15 events, 7 rows matched, 0 pre-genesis chain *: 0 events, 0 rows matched, 0 pre-genesis
Printed by the verifier in the bundle, exit code 0, on the record the captures on this page came from. The workspace id is shortened here.
The copy on your machine is the original. It stays readable and exportable there with or without the service, paid or not.
The product prints what it sends when it starts, and shows the same list on the desk. The site's side of the hosted record, where it is read and exported, is to build.
Any MCP client can call it over stdio or streamable HTTP. The bundle ships a gate for LangGraph in Python that needs only the standard library, a gate for Node, and the contract for everything else.
| System | It pauses with | It resumes with | In the bundle |
|---|---|---|---|
| LangGraph · LangChain agents | an interrupt in the gate node | a Command; the node re-runs and reads the ruling by its decision key | the LangGraph gate |
| LangSmith Deployment | the thread is interrupted | a poller waits for the ruling, then starts a run on the thread | the same file |
| CrewAI · AutoGen · OpenAI Agents | a tool that blocks, or a task that parks | the tool returns the generic resume | the MCP tools, called directly |
| Temporal · Step Functions · a queue | an activity that returns waiting | the activity reads the ruling and returns it | the Node gate or the Python class |
| n8n · Make · Zapier | an HTTP node posting to the door | a wait node, then a read of the ruling | none needed |
| Claude Code · Codex · any MCP client | the tool call itself waits | the tool result | the stdio door |
A stable decision key returns the existing row with its ruling.
Whatever resumes your system, the gate reads the ruling from the record. A resume that arrives early pauses again.
Windows, macOS or Linux. Unzip, put the licence file beside START, run START.
SPEKTX is not affiliated with LangChain, Inc. or any other orchestration vendor, and none of them endorses this product. Each name belongs to its owner.
Walked means it was done on the bundle itself for this page, with the result on file. In the bundle means it was read in the bundle's code and its own documentation and not walked here. To build is not there yet. Every row still owes the principal's own walk.
A subscription, tiered by the number of principals and the number of connected systems, whichever is exceeded first. Approvers are never counted. There is no free tier. Annual is ten months' price.
$990 a year
$1,990 a year
$3,490 a year
by order
Work continues. After that, new poses are refused, and the calling system is told why.
A paused run is not left hanging by a payment event.
Records, exports and the corpus on your machine stay readable whatever the licence says.
A principal is a person whose judgment the record captures. A connected system is one graph, agent or workflow with its own credential. Checkout is not open; these are the figures the product itself enforces.
It does not promise that a person will rule within any time, that your system will honour the ruling, or that your own pause and resume will work. A ruling is the act of the person who makes it.
Life support, emergency response, medical treatment, aviation or vehicle safety, industrial safety interlocks, and uses like them.
Chorix is human-governed orchestration of several AI models, and its Ledger is where its principal rules. The Judgment Layer is that ledger, its judgment and its governance of approval, cut out to stand alone inside a system someone else built.
No. The door an agent is given carries no tool that rules, acknowledges or changes authority. Those tools are on a second door that opens only on a human credential, and by default every ruling also needs that person's passkey.
No. Your system keeps its own pause and resume. The Judgment Layer owns the pose, the authority, the ruling and the record.
On your own machine, on Windows, macOS or Linux, with Node.js 24 or later. The desk is a page on that machine.
Yes, and the product prints what. A signed copy of the record, words included, is kept on the Chorix Studio site by default so it can be read and exported if the machine is lost; the owner can turn it off with a passkey. SPEKTX can read that copy.
Yes. A record export is sealed with a key made and kept on your machine, and the verifier that ships in the bundle checks it offline.
After a 14-day grace period new poses are refused. Decisions already open stay open to rule for seven days. The record, its exports and the corpus on your machine are never locked.