runs in your browser · sub-msmeasure, don't assumeApache-2.0 · zero-dep

Know what you can’t take back — before it runs.

A compensating entry reverses a record. It does not reverse a consequence: burned compute, a delivered email, a disclosed secret, a model trained on the wrong corpus. This kernel measures the difference — the recoverable share, the residue a reversal leaves behind, and the undo horizon: how long the window stays open. When your review is slower than that window, the approval is theatre — and it says so. Edit the action and watch it decide, live.

Action under test (editable)kernel source →
Review policy (editable)
Effect kindstaxonomy →

record.write · payment.captured · communication.sent · compute.consumed · tokens.consumed · record.deleted · secret.disclosed · deployment.released · data.trained … unknown → irreversible

Honest scope. This measures and signs reversibility — it posts no bond, holds no collateral, slashes nothing, and prices nothing: sunk resources are reported in the unit you state and totalled per unit, never converted (EcoCloud has no market data and will not invent an exchange rate). The postures are configurable defaults, not measurements of your stack — tune any effect via policy.effects. It is fail-closed: an unknown effect is irreversible, a missing window is shut, a delete is terminal unless a restorable backup is positively declared. For a verifiable record, the endpoint /api/v1/agent/irreversibility returns an ES256-signed assessment you can check against the published JWKS. Source: flowdesk-irreversibility-kernel.js.