An open protocol for human sign-off

Let AI do the work.
You approve
the action.

As AI agents take on more of the internet, an action alone won’t tell you whether a person approved it.

Enthade helps services require human sign-off for a specific action. In the service’s iPhone app, review the request and authorize it with Face ID or Touch ID. The app sends a receipt—evidence its backend can check.

Experimental v0.1 External audit pending

The actionIllustrative example
An agent prepares the final request

To: Alex · Message: “Let’s meet at 3 pm on Friday.”

You authorize this action
Action receiptv0.1

An approval
the service can check.

Action
Send this message to Alex
Authorized with
A protected phone key requiring Face ID or Touch ID
Bound to
This message · this recipient · this service
Biometrics stay on your device

AI can prepare it. The receipt covers your authorization.

Let the agent prepare.
Keep your approval where it matters.

An agent can research, draft, and plan. The service chooses which actions need your approval: sending a message, publishing a post, or granting a specific permission. Its app shows the exact request; its backend requires and checks the receipt before proceeding.

Use the pause where it matters.

Biometric approval adds friction in exchange for stronger evidence of human sign-off. Keep it at the actions that need that assurance. The receipt covers the selected action, not the quality of the agent’s work or every later step.

Stop unattended
mass posting.

Require fresh biometric sign-off for every accepted post or comment. The social network rejects missing, reused, or mismatched approvals. A script cannot turn one approval into a burst of different posts.

With approval required for every post

A thousand posts.
A thousand approvals.

Every accepted post needs its own approval. That puts human time into the cost of mass spam. AI can still help you write; you authorize publication.

1 accepted post
1 fresh approval
1,000 accepted posts
1,000 fresh approvals

Where human sign-off
is worth the pause.

Sending, publishing, voting, or granting permission: a service chooses its approval points. AI can help with the work leading up to them.

Human approval at a chosen point

Let the agent prepare.
You authorize the final action.

Let an agent research, draft, and prepare a request. Before the selected final action, the app asks you to review and approve it. The service checks the receipt before proceeding.

Example protected actionSend a prepared message

To: Alex · Message: “Let’s meet at 3 pm on Friday.”

This receipt covers the final action. It does not authorize every later action or certify the agent’s earlier work.

Walk through this action

Potential applications, not announced customer deployments. Enthade Forum is the first-party experimental reference app.

One approval.
One specific action.

Review the request. Approve on your phone. The service checks the receipt. Follow the final step of an agent’s workflow.

Interactive illustration · no biometric check or real proof
Agent workflow exampleStep 1 of 4

See what you’re approving.

The app shows exactly what will happen before you authorize it. A one-time request from the service keeps the approval tied to this submission.

Send a prepared message

To: Alex · Message: “Let’s meet at 3 pm on Friday.”

Service requestFresh and tied to this action

A protected action has no passcode fallback. If the required biometric authorization is unavailable, the action cannot satisfy that policy.

Why this matters

Know what
the evidence says.

Three different questions. Three distinct layers. A receipt should state which evidence was actually evaluated.

Protocol

Was this exact action
cryptographically authorized?

A qualifying key signed a record tied to this exact action. The trusted app and platform require biometric approval; a verifier checks the cryptographic evidence.

Cryptographic foundation

Integrity

Did the app and device
meet the required trust profile?

Platform evidence is checked against a published profile. The service chooses which environments and evidence qualify under its policy.

Platform trust evidence

Presence Planned

Does the interaction add evidence
that someone is physically there?

An additional, adaptive layer can assess interaction signals. It provides confidence under a versioned policy, rather than cryptographic certainty.

Probabilistic assessment
Authorization is the claim.

These layers do not establish authorship, legal identity, unique personhood, truth, or whether someone read and understood the content.

Evidence travels.
Your biometrics don’t.

The protocol is designed around minimal disclosure: give the service the evidence it needs to assess an action.

Read the privacy model

Biometrics stay on the device.

Face ID or Touch ID controls access to the key locally. Enthade does not receive your face, fingerprint, or raw biometric data.

Verification can be independent.

A service can check a receipt with an open verifier and published issuer keys, without calling Enthade servers or relying on a secret verification algorithm.

No universal identifier.

The current design gives each service’s app separate credentials and issuer keys. A receipt hides the underlying phone key; it does not provide a shared identity across services.

Precise claims, visible limits.

A service can still link actions within its own context. Privacy depends on implementation, operational separation, and the service’s own data practices.

Open foundations.
A wider ecosystem.

Enthade is the umbrella project. The protocol is its foundation; the apps and services build on top.

Enthade Protocol

The open rules for creating and verifying action-bound evidence.

Frozen v0.1 specification

Enthade SDK

Platform libraries and verifier implementations for builders.

iOS + Node proof of concept

Enthade Forum

A reference community app for human-attended ideas and votes.

Internal test app

Enthade Verify

The hosted verification service envisioned for teams that want managed infrastructure.

Planned service

Enthade Presence

Additional adaptive assessments of physical interaction and automation.

Planned

Enthade Log

Public transparency through verifiable commitments and checkpoints.

Planned
Where we are

Enthade is experimental and pre-audit. The current work demonstrates the flow on iOS with local services. External cryptographic review, production validation, and Android support remain ahead.

Implementation status

Good questions.
Clear boundaries.

A few things to understand before
putting Enthade to work.

Can AI agents work with Enthade?

Yes. An agent can research, draft, plan, and take the steps an app allows it to take autonomously. The service chooses which actions need human authorization. Its app shows the request and asks for biometric approval; its backend requires and checks the receipt before proceeding.

Can it approve a permission rather than a final action?

Yes. A service can make a specific permission grant a protected action. The receipt covers the scope that was authorized. The service must enforce that scope and any limits. It does not mean a person separately approved every later action the agent takes.

Does it automatically tell human actions from AI actions?

No. Enthade gives a service a way to require authorization evidence for a chosen action. An action without that receipt is missing the required evidence; it is not automatically classified as AI. A receipt also makes no claim about who prepared the content.

Does Enthade prove a human wrote something?

No. Enthade concerns the authorization of an action. AI-assisted writing is compatible with the project. A signed contribution can still be inaccurate, copied, or AI-generated.

How is this different from a CAPTCHA?

A CAPTCHA asks someone to complete a challenge. Enthade binds authorization evidence to a specific action, receiving service, challenge, and policy. The verifier assesses that evidence; Enthade does not claim to eliminate every form of automation.

Is this identity verification or one person, one vote?

No. Enthade does not establish a person’s name, legal identity, or uniqueness. A credential is not a unique human. Polls and services still need their own account, eligibility, and duplicate-vote rules.

What happens if Face ID or Touch ID is unavailable?

The protected action cannot satisfy the policy. Reading, drafting, or recovery can remain available, but a password or passcode cannot substitute for the required authorization. Recovery can enroll a new qualifying key; it cannot sign the protected action itself.

Does Enthade receive my biometric data?

No. Biometric processing happens on the device. The verifier checks cryptographic evidence and trusts the service’s app and platform to enforce the biometric gate. It does not observe your face, fingerprint, or biometric check.

Can someone reuse my approval for a different action?

The design binds evidence to the exact action, receiving service, policy, challenge, and expiry. Changing the protected content changes its hash. The receiving backend must also enforce challenge consumption and replay rules.

What does it prevent on a social network?

With fresh biometric approval required for each protected post or comment, the service blocks publication without that approval. It also rejects spent receipts and approvals for different content or a different service. A script cannot publish thousands of posts using one sign-off: each accepted submission needs its own.

Can I use it in production today?

The current implementations are experimental prototypes and internal test apps. External audit and production validation are pending. The developer guide explains the design and the current implementation boundaries.

Human sign-off.
Where it matters.

Choose the actions that deserve a deliberate human approval. Keep the rest of the workflow moving.

Read the developer guideἐνθάδε · “here, in this place”