SCRIVENER
Engagement letters that cannot be quietly rewritten, and an evidence chain instead of email archaeology.
Open the live chamber in the app
Who this serves
- Audit and advisory firm. Engagement letters whose exact version the client can prove.
- Law practice. Escrowed retainers with releases behind a partner's physical presence.
- Consultancy. Milestone billing that cannot be quietly renegotiated mid-dispute.
- Trustee and notary services. A hash chain instead of a mailbox when the insurer calls.
The problem
An engagement letter is a PDF. What was actually agreed, by whom, under which version of the firm’s standard terms, is reconstructed from email archaeology at the exact moment reconstruction is adversarial, which is during a dispute. The firm’s own records answer "what do our terms say now," not "what did they say when this client signed," and the difference is where malpractice claims live.
The system
SCRIVENER is the engagement layer of a mid-sized audit and advisory firm: forty-one agents, one partner mandate per engagement, and a template library whose published versions cannot be edited by anyone, including the firm that owns them. When the firm updates its standard terms, it publishes version 12 beside version 11. Nothing that instantiated version 11 changes, ever. A client who signed under version 11 can prove, from the ledger, exactly which wording they bought, because instantiation copies the frozen text rather than referencing something mutable.
An engagement begins when the intake agent instantiates the template and fills its terms schema: scope, fee cap, deadline, annex references. The work decomposes into milestones with the money in escrow from acceptance. Associate agents submit, a reviewer verifies, and any release above 5,000 units requires the partner, a named human being whose mandate underwrites the releasing agent for this scope and nothing else. Her authority is re-derived on every request. The firm suspends her for a conflict check on Tuesday morning; by Tuesday’s next request, every mandate leaning on her flags conveys nothing, with no token rotation and no cache to chase.
In November a client contests milestone three. The money does not move. It sits in escrow while the dispute runs its four phases, and when the ruling lands, the ruling itself drives the split: the escrow divides per the arbiter’s decision, exactly once, and a second ruling on the same dispute is refused as a conflict. The file that reaches the firm’s insurer afterwards is not a narrative reconstructed from mailboxes. It is a hash chain: who held what authority at each moment, which facts a present human confirmed, and which confirmations expired unanswered, because here an expired approval is not a gap in the record. It is a recorded denial.
The cast and their ceilings
| Agent | Role | Ceiling |
|---|---|---|
intake-clerk | Instantiates the engagement from a template, fills the terms schema | Template instantiate. Cannot publish versions, cannot release. |
associate-1..n | Performs the work, submits milestones | Milestone submit. Cannot approve its own submission. |
qa-reviewer | Verifies deliverables before release | Verify only. Holds no release permission. |
partner (human) | The mandate behind releases above threshold | Cockpit Card scope: this engagement class only. Presence proof above 5,000. |
records-clerk | Serves the evidentiary chain to auditors and insurers | Read-only on events and attestations. |
The flow, step by step
- Intake instantiates the engagement and fills the terms schema.
- The frozen text of version 11 is copied in. Nothing references anything mutable.
- The associate submits milestone three.
- Review verifies before any money moves.
- Release needs the partner. The facts reach her as the server computed them.
- Her presence signs. An expired confirmation would be recorded as a denial.
- Release, exactly once.
- The insurer reads a hash chain, not a mailbox.
Each need, mapped to a live primitive
| The need | The protocol primitive | Status |
|---|---|---|
| Frozen standard terms | Contract templates: publish is an irreversible version freeze | LIVE (gated) |
| Which wording the client bought | Instantiation copies the version; the ledger records which | LIVE (gated) |
| Structured engagement terms | terms_schema JSON Schema forms with annex references | LIVE (gated) |
| Money held from acceptance | Escrow at agreement, staged strict-order milestones | LIVE |
| Named liable partner | Cockpit Card mandate, scope-clamped, re-derived per request | SHADOW |
| Human really present | WebAuthn presence; an expired confirmation is a recorded denial | LIVE |
| Contested milestone | Four-phase dispute; the ruling drives the escrow split | LIVE |
| Ruling executes once | Double-drive guard: a second ruling on the linked dispute is refused | LIVE |
| Referral economics | Royalty carved at settle, basis points, capped | LIVE (gated) |
| The insurer’s file | Per-mandate hash chain, authority snapshot on every event | SHADOW |
The attack this chamber refuses: The retroactive amendment
The attack. After the dispute is filed, the firm quietly edits clause 7 of its standard terms to favour its position.
Why it fails. Publishing is an irreversible freeze behind a confirmation that says exactly that, and instantiation copied the text into the engagement. There is no reference to rewrite. The client’s copy is not protected from tampering; it is structurally incapable of being tampered with from the firm’s side.
What actually happens. The only lit path out of the template library is publishing version 13, which changes nothing the client holds.
The attack this chamber refuses: The mid-dispute clawback
The attack. The client, mid-dispute, invokes the self-serve failure path to claw back the full escrow over work already delivered.
Why it fails. A contested engagement is frozen for the arbiter. A unilateral full refund from the disputed state is refused as a conflict, while the provider’s option to concede remains open.
What actually happens. Neither side can move contested value. The escrow waits for the ruling, the ruling executes exactly once, and both facts land in the evidentiary chain.
Deep architecture
SCRIVENER deployed: the firm’s frame holds the templates, the escrow and the evidence chain; the client acts from its own registry; the fabric couriers signed bytes between them. The partner’s mandate sits where the money moves, and the document system receives evidence instead of producing archaeology. The trace replays one engagement from matter-open to evidence chain.
The deployment, traced
- A matter opens in practice management, where matters already open.
- The clerk instantiates the engagement from a published template. Published means frozen.
- The letter crosses as signed bytes, not as an attachment.
- The client accepts the exact bytes. There is no quiet rewrite of clause seven.
- Milestone one funds from the client’s frame.
- The escrow lands on the engagement’s home frame, exactly once.
- QA verifies the deliverable. The verification is itself evidence.
- Above threshold, the partner’s mandate releases: named, present, recorded.
- The release is one append-only event.
- The client’s mirror carries the same chain. Both sides hold the truth.
- The chain exports to the DMS. Discovery becomes a query, not archaeology.
Adoption, phase by phase
Discover: Read your own letters as schemas.
- Runs. Nothing. Two of your standard engagement letters redrawn as terms schemas and milestones.
- Agents. None. Partners argue about the schema, which is the productive argument.
- Integrates. Nothing. The DMS and practice management are untouched.
- Deliberately not yet. No template is published, so nothing is frozen.
- Proof that gates the next phase. One real historic engagement re-expressed as template + milestones with no clause left unrepresentable.
Pilot: One engagement class, live, small.
- Runs. A hosted registry seat, or a single-VM frame if client confidentiality demands your walls.
- Agents. intake-clerk, one associate agent, qa-reviewer; the partner holds a pilot-ceiling mandate.
- Integrates. Matter-open events from practice management; evidence exports to a supervised DMS folder.
- Deliberately not yet. One template only; releases capped; clients join as accounts, not registries.
- Proof that gates the next phase. Three engagements run template-to-release with the evidence chain accepted by your own risk partner.
Production: The template library becomes the firm’s law.
- Runs. Sovereign frame in the firm’s estate; versioned template library; the evidence chain is the record.
- Agents. Full cast; associates submit, QA verifies, the partner mandate gates releases above threshold with presence.
- Integrates. DMS receives the chain continuously; billing reads settled milestones instead of timesheets arguing with invoices.
- Deliberately not yet. Cross-registry clients. The next phase makes the client a peer, not just an account.
- Proof that gates the next phase. An external audit samples engagements and reconstructs each from the chain alone, without one email produced.
Federation: Clients and counsel as peers.
- Runs. Unchanged. Corporate clients connect their own registries; opposing counsel can too.
- Agents. Client desks act from their own frames; the letter is the same bytes on both.
- Integrates. Each new peer is a signed card and a license.
- Deliberately not yet. Nothing structural. Growth is template instantiations.
- Proof that gates the next phase. A contested engagement survives discovery with both parties citing the same chain, because there is only one.
Sizing
| Level | What | Containers |
|---|---|---|
| L1 | Clients join engagements with accounts and agents only | 0 of theirs |
| L2 | The firm runs agents against a hosted registry seat | agents only |
| L3 | The firm runs its sovereign frame; the chain lives under its walls | ~9, one VM up |
One release, submission to evidence
sequenceDiagram
participant Assoc as associate agent
participant QA as qa-reviewer
participant Gate as partner mandate
participant TEG as firm TEG escrow
participant ES as evidence chain
participant Cli as client mirror
Assoc->>QA: milestone submitted
QA-->>ES: verification recorded
QA->>Gate: release requested (above threshold)
Gate->>TEG: release with presence proof
TEG-->>ES: release event, append-only
ES-->>Cli: signed mirror update
ES-->>ES: chain grows; discovery is a query
Topology, as declared
flowchart LR
T["contract template<br/>publish = version freeze"] -->|"instantiate copies text"| C["contract<br/>terms_schema + annexes"]
C -->|"escrow at accept"| TEG["TEG escrow"]
A["associate agent"] -->|"milestone submit"| C
C -->|"release above threshold"| M["Cockpit mandate<br/>authority re-derived"]
M -->|"WebAuthn presence<br/>expiry = recorded denial"| TEG
D["dispute (4 phases)"] -->|"ruling drives split<br/>second ruling = 409"| TEG
TEG --> ES[("event store<br/>hash chain + snapshots")]
Standing it up
- Infrastructure. A firm-run registry, or a hosted one. 9 containers, about two minutes, or nothing at all.
- Agents. 5 roles, and most firms start with intake and one associate.
- Integration. The document management system and the practice management suite. The protocol carries agreement, authority, and money; the working papers stay where they are.
What this does not claim
- SCRIVENER is not a qualified electronic signature scheme under eIDAS and makes no claim about evidentiary admissibility in any jurisdiction.
- The protocol stores agreements, authority and settlement, not the client’s working papers.
- Nothing here is legal advice, including the blueprint about lawyers.
Browse all 21 blueprints, read the documentation, or start at theprotocol.cloud.