Cryptographic execution receipts for AI agents: signed, hash-chained proof of authorized tool use. If it changes it can't be run, if it runs, it can be proven.