Watchbill: Our First Release

Today we shipped our first public release: Watchbill — a plain-text ledger protocol for AI agent crews.

A watchbill is the roster that assigns a ship’s crew to their watches: who is on duty, for which hours, answerable to the officer of the deck. Ours does the same for AI agents — any number of sessions, from any vendor, and one human, sharing a single working tree for months without silently clobbering each other.

It’s free, Apache-2.0 licensed, and it is deliberately small: markdown files, a few Python scripts, and a written protocol. No server, no database, no vendor, no account.

Where it came from

We didn’t design Watchbill for release. We extracted it from our own lab, where it has run for roughly ninety days — one human operator, multiple concurrent AI sessions, more than one vendor’s agents, one shared repository. Every rule in it exists because we hit the failure it prevents: the lease that expires visibly because an ownership claim once went silently stale; the append-only log because a months-old entry that no process was allowed to erase later turned out to be the key witness in reconstructing a lost artifact; the checker fixtures because our own guard was once silently disarmed by a formatting quirk — and we only found out by auditing it.

What it does — and what it honestly doesn’t

Watchbill gives an agent crew four shared surfaces: an ownership ledger with time-bounded leases, a shared diary whose log is never rewritten, a private per-session notebook that must reconcile and be deleted, and an index. On top of that sit the instruments: a claims auditor, an ownership guard, a heartbeat, and a test suite whose fixtures are real traps from our production history.

What it does not do is police. A determined or broken agent can ignore a markdown file, and we won’t pretend otherwise. What you buy is visibility: ownership you can see, leases that expire loudly, violations that show up, and a record that makes after-the-fact reconstruction possible. If you need hard isolation, use hard isolation — underneath this, not instead of it.

The part we’re proudest of

The repo ships its own adoption audit — including the day it failed.

Before release, we handed the repo to a deliberately fresh agent session that knew nothing about how it was built and told it to follow the quickstart, literally, in a virgin repository. Its verdict on our documentation was “would not succeed — as written.” It filed eleven findings, including one critical: a piece of hook wiring that would have silently never worked, leaving the ownership guard disarmed for every adopter while looking fully installed. Two adversarial security reviews had missed it. The first stranger who actually followed the instructions found it in minutes.

We fixed everything the same day, replayed the corrected quickstart end to end, and then published the full report — findings, receipts, and fixes — inside the repository at docs/ADOPTION_AUDIT.md. A protocol whose whole thesis is visible state should have visibly-stated flaws, and their fixes.

Try it

The README has a four-step quickstart — copying the kit into a repo and proving the install takes a few minutes, and the third step is proving the shipped safety traps actually get caught on your machine, not just ours.

If you run agent crews and it saves you one silent collision, it has paid for itself. Issues and pull requests are welcome — and, in keeping with the protocol itself, everything outward from us goes through a human.

Watchbill is the first release from Sovereign Labs AU. It won’t be the last.