The talk
A 20 minute talk for engineers, security teams and auditors: what an AI agent may do, and proof of what it did. Thirteen slides, each with speaker notes.
The background for each slide is in the technical paper,
How Parmana compares, the case studies and
Limitations. To give this talk, write to founder@parmanasystems.com.
Download the slides (PDF)
All 13 slides, 16:9.
Demo videos
Four short videos. Each script below is the exact sequence to follow, so you can also run it yourself. Every step uses the public sandbox and its published demo key, so nothing real is acted on. Send only demo text: everything sent to the sandbox is visible to every visitor.1. Parmana in 90 seconds
2. The whole flow against the sandbox, about 3 minutes
- Open a terminal. Show the two
exportlines from the Playground cURL tab. Say: this is a published demo key; it can only callsandbox:receipt. - Run step 1,
GET /callers/me. Point atsandbox-visitorand its one capability. - Run step 2, the policy in effect. Point at the approval signal: this policy approves only with a signed approval for the request’s target.
- Run step 3 with no approval. Point at the refusal and its reason. Say: no approval, no action, and the refusal is recorded.
- Run step 4,
POST /sandbox/approvals. Say: in production a person signs this; the sandbox signs one for the demo. Point at its expiry, 5 minutes. - Run step 5 with the approval. Allow 10 to 15 seconds. Point at the receipt from the release endpoint and the signed Execution Trust Record.
- Run step 6, the offline check. Point at
valid: true. - Run step 7, the same approval again. Point at the refusal: the approval was spent.
3. Verify a record yourself, about 2 minutes
- Open Verify in browser. Say: nothing is sent to a server; the check runs in this page.
- Load the example, then Verify: valid.
- Load the example, changed: the amount went from 100 to 100000. Verify: the hash no longer matches. Say: change any signed field and verification fails.
- Paste the record from video 2, click Use the sandbox key, Verify: valid.
- Close with what this proves: the record is unchanged and was signed by the key holder. It does not prove the key holder was honest; see Limitations.
4. Attack it yourself, about 3 minutes
On a local copy of the repository (Node 24,npm ci, npm run build):
- Show the scenario list in
evaluations/scenarios.json. Say: 16 attacks, each passes only when the attack is refused or detected. - Run
npm run evaluate -- EV-04: act without a person’s signed approval, the prompt injection case. Show the result. - Run
npm run evaluate -- EV-01: replay a used authorization. Show the result. - Run
npm run evaluate -- EV-14: alter a signed record after the fact. Show the result. - Run
npm run evaluatefor all 16. Point to the Security challenge: if you find a way through, report it privately.
.env file or signing key.