Skip to main content

The talk

A 20 minute talk for engineers, security teams and auditors: what an AI agent may do, and proof of what it did. Thirteen slides, each with speaker notes. The background for each slide is in the technical paper, How Parmana compares, the case studies and Limitations. To give this talk, write to founder@parmanasystems.com.

Download the slides (PDF)

All 13 slides, 16:9.

Demo videos

Four short videos. Each script below is the exact sequence to follow, so you can also run it yourself. Every step uses the public sandbox and its published demo key, so nothing real is acted on. Send only demo text: everything sent to the sandbox is visible to every visitor.

1. Parmana in 90 seconds

2. The whole flow against the sandbox, about 3 minutes

  1. Open a terminal. Show the two export lines from the Playground cURL tab. Say: this is a published demo key; it can only call sandbox:receipt.
  2. Run step 1, GET /callers/me. Point at sandbox-visitor and its one capability.
  3. Run step 2, the policy in effect. Point at the approval signal: this policy approves only with a signed approval for the request’s target.
  4. Run step 3 with no approval. Point at the refusal and its reason. Say: no approval, no action, and the refusal is recorded.
  5. Run step 4, POST /sandbox/approvals. Say: in production a person signs this; the sandbox signs one for the demo. Point at its expiry, 5 minutes.
  6. Run step 5 with the approval. Allow 10 to 15 seconds. Point at the receipt from the release endpoint and the signed Execution Trust Record.
  7. Run step 6, the offline check. Point at valid: true.
  8. Run step 7, the same approval again. Point at the refusal: the approval was spent.

3. Verify a record yourself, about 2 minutes

  1. Open Verify in browser. Say: nothing is sent to a server; the check runs in this page.
  2. Load the example, then Verify: valid.
  3. Load the example, changed: the amount went from 100 to 100000. Verify: the hash no longer matches. Say: change any signed field and verification fails.
  4. Paste the record from video 2, click Use the sandbox key, Verify: valid.
  5. Close with what this proves: the record is unchanged and was signed by the key holder. It does not prove the key holder was honest; see Limitations.

4. Attack it yourself, about 3 minutes

On a local copy of the repository (Node 24, npm ci, npm run build):
  1. Show the scenario list in evaluations/scenarios.json. Say: 16 attacks, each passes only when the attack is refused or detected.
  2. Run npm run evaluate -- EV-04: act without a person’s signed approval, the prompt injection case. Show the result.
  3. Run npm run evaluate -- EV-01: replay a used authorization. Show the result.
  4. Run npm run evaluate -- EV-14: alter a signed record after the fact. Show the result.
  5. Run npm run evaluate for all 16. Point to the Security challenge: if you find a way through, report it privately.
Recording notes: use a terminal font of at least 18 points, show one command at a time, and keep the demo key on screen only where the docs already publish it. Never show a real API key, .env file or signing key.