Resources
Start with the doctrine. Understand the protocol. Then implement with ZTI Core. This page gives you every reference point along that path.
Getting started
Understand the doctrine
Before protocol or platform, understand the belief system. Three principles. Ten minutes. The foundation for everything else.
Explore the protocol
The open protocol for governed AI action. Five steps. Defined schemas. Transport-agnostic. Read the spec and understand how verification actually works.
Implement with ZTI Core
ZTI Core is the operational control plane for ZTIP. It is complete and in early access. Ask for a free 30-day trial, or a free individual key if you work on your own repos, and run it against your own agents.
All resources
On this site · Doctrine
ZTI Doctrine
The principles and beliefs that guide responsible AI action. The full text lives here.
GitHub · Open protocol
ZTIP Protocol
Envelope schema, receipt format, conformance rules. The full protocol specification.
ZTI Core · Early access
Get early access
Ask for a free 30-day trial or a free individual key for the commercial control plane.
Essay · Agent governance
Everyone signs decisions. Nobody verifies done.
Why signed receipts notarize an agent's claims without verifying its work — and the fail-closed semantics that close the gap.
Internet-Draft · Individual submission
draft-mccormack-ztip
The protocol summary, filed with the IETF as an individual draft so the design has a public date. Not an adopted standard.
Specification
ZTIP SPEC.md
The normative spec: envelope types, RFC 8785 canonicalization, SHA-256 hash chain, and the fail-closed lifecycle.
Conformance
ZTIP CONFORMANCE.md
How an implementation proves it conforms to the ZTIP specification, requirement by requirement.
GitHub · Open client (MIT)
The zti client
The CLI, the gate library, the git and CI receipt gates, and the Claude Code hook pair.
Live demo · No signup
Watch an agent get caught
The public demo repo: a receipted green PR, a bypass PR blocked red in CI, and a 2-minute walkthrough.
Philosophy
AI agents are shipping to production. They are writing code, deploying services, accessing systems, sending messages, and making decisions that were once human-only territory. The speed is real. The capability is real.
What is not yet real, for most organizations, is the governance infrastructure to match. There is no standard way to record what an AI agent did. No standard way to say it was authorized. No standard way to prove it to an auditor.
ZTI, ZTIP, and ZTI Core are the answer to that gap — built in the open, designed for the enterprise, and grounded in a simple principle: don't trust AI. Verify it.