# letopis — one evidence chain for agent-built software

> A chronicle keeps records. It does not have views.

letopis is four products that write down agent-era software work: the time it
took, the reasoning behind it, the process that governed it, and what the
next one should cost.

- Canonical page: https://dirahq.sh/letopis
- Compare: https://dirahq.sh/letopis/compare
- AI Act & CRA: https://dirahq.sh/letopis/ai-act
- Contact: hello@dirahq.sh

Four records of the same work, so none of them has to be believed. Most tools
ask you to trust a number someone typed in. Every number here traces back to
something signed and checkable: a session, a commit, a written decision, a
merge. That is the only reason a client, an auditor or a CFO ever accepts it.

## The chain

signed sessions → anchored artifacts → recorded intent → notarized process →
priced future — and calibration feeds back into capture, which is why the
ring closes.

## The gap every invoice hides

Your agents worked far more wall-clock hours than you were engaged for. That
gap is either a dispute or your margin. One person supervising three parallel
agents is still one human-minute per minute: engaged time never exceeds real
elapsed time, no matter how many sessions run alongside it.

Three ways to bill the same day of work:

- **Wall-clock** — billing every agent hour is the number a client disputes
  the second they ask which human worked a 19-hour day.
- **Engaged, anchored** — dira's number: defensible line by line, and lower.
  Honest hours make you cheaper.
- **miara, fixed price** — quoted from evidenced comparables, so the leverage
  lands in the price instead of in a discount you never meant to give.

The loop that closes the gap runs through all four books, in order, each
handing the next one something it could not otherwise know:

1. **dira** keeps agent time and engaged time apart and anchors both to
   commits that provably exist in the remote — then hands zavet a signed
   session to attach reasoning to.
2. **zavet** captures the decisions behind that session as a byproduct of the
   work and guards them, so the next agent cannot quietly undo the thinking
   you were paid for — then hands proba a recorded intent to grade the change
   against.
3. **proba** witnesses the process per merged change — CI at the merge
   commit, a non-author review, the supervision minutes, no branch
   protection bypassed — then hands miara a fineness floor, so only governed
   work sets the price.
4. **miara** prices the next job from your own evidenced deliveries instead
   of a guess — and hands dira the next job to record. The ring closes.

## Five questions, one sequence

Every tool you already own answers one of these and goes blind at the next.
They are not five separate problems — they are one sequence, and the fifth
answer feeds the first.

| Question | You'd reach for | What it cannot see | letopis |
| --- | --- | --- | --- |
| How long did this actually take? | Toggl · Harvest · Clockify | Whether the timer was a human or a forgotten tab — and it never touches the artifact the hour produced. | dira |
| Who — or what — wrote this code? | git blame · co-author trailers · Copilot metrics | The workstation. A trailer is a claim anyone can type; the code host cannot witness the session that produced the diff. | dira |
| Why is it built this way? | Confluence · Notion · ADR folders · kiro.dev specs | Whether anyone followed it. A wiki page enforces nothing, and a generated spec is a plan the next agent run can quietly rewrite to agree with itself. | zavet |
| Was this change governed? | CI · branch protection · compliance collectors | That a check ran is not that a human supervised. They record the gate, never the supervision behind it. | proba |
| What should the next one cost? | Spreadsheets · story points · gut feel | That its calibration died in 2024. Every input is a self-reported number from before agent leverage existed. | miara |

Full comparison, including kiro.dev: https://dirahq.sh/letopis/compare

## The European AI Act

In force since 2 August 2026. The EU AI Act is clumsy; producing the evidence
for it shouldn't be. Every deliverable the Act asks a software team for is a
question about the past — a compliance project answers with archaeology,
letopis answers with a lookup, because the answer was recorded while the work
was happening.

| Provision | Via | Book | What it records |
| --- | --- | --- | --- |
| Annex IV §2(b) | Art. 11 · technical documentation | zavet | The key design choices, including the rationale and assumptions made — dated, attributed, and guarded against the next agent. |
| Art. 14 · 26(2) | Human oversight | dira + proba | Engaged supervision minutes per change, deduped across parallel agents. A number, not a policy page. |
| Art. 17 | Quality management system | proba | Design control and change control per merge: CI at the merge commit, non-author review, no branch protection bypassed. |
| Art. 73 | Serious incident · 15 days, or 2 if widespread or risking serious injury, 10 on a death | zavet /zavet:why | The decision and change history of one subsystem, answered with citations in seconds rather than a fortnight. |
| Art. 12 · 19 · 26(6) | Record-keeping & retention | the whole chain | Signed at capture on the workstation, append-only afterwards — tamper-evident at six months and at ten years. |

letopis is not a compliance badge, not runtime logging and not legal advice —
and it says so on its own page. What it removes is the archaeology. Full
article-by-article case: https://dirahq.sh/letopis/ai-act

## The four books

Two ship today, two are next — and the last one ships warm, because its
history has been accruing since the third step.

### dira — the trail (shipping)

One person supervising three agents is still one human-minute per minute.
dira counts the minutes you were actually engaged while Claude Code, Codex
and OpenCode did the work — deduped across parallel sessions — then anchors
every billable hour to commits a client can inspect.

- Engaged, agent, compute — three numbers, kept honestly separate.
- Anchored to git — signed on your machine, confirmed against the remote.
- Unverified is quarantined — never billed until you resolve it.
- dira won't bill an hour it cannot anchor to a real commit.

https://dirahq.sh

### zavet — the covenant (shipping)

dira knows where the time went. zavet knows what it produced: every decision
behind your agent-built code, captured as a byproduct of the work — guarded
against agent reverts, answerable with `/zavet:why`, and tied to the exact minutes
it cost.

- Capture — commit trailers & 25-line decision records. No chore.
- Enforce — guards block agents from reverting what you decided.
- Recall — `/zavet:why` answers with decision citations, offline, in seconds.
- zavet won't invent a rationale. Backfilled specs stay marked unverified
  until a human confirms.

https://dirahq.sh/zavet

### proba — the assay stamp (next in the sequence)

Nobody can say, per shipped change, whether a human really supervised the
agent. Proba mints a signed hallmark for every merged PR — CI state,
non-author review, which harness wrote it, supervision-minutes spent, guards
respected. It grades the process, never the code.

- 585 → 750 → 999 — fineness rises as you add dira capture, then zavet.
- Observe · Signal · Enforce — an opt-in dial, starting at zero risk.
- Break-glass is recorded — overrides become evidence, never blockers.
- proba won't say whether the code is good. It grades the process, at a
  stated fineness of evidence.

https://dirahq.sh/proba

### miara — the measure (history accruing now)

Honest hours make you cheaper. Miara is how you get paid for the leverage
instead: a quoting surface inside dira cloud that prices future work from
your own recent, evidenced deliveries — ranges only, with n and spread, and a
flat refusal below three confirmed comparables.

- Human picks, machine computes — you confirm every comparable.
- It grades itself — quoted vs. actual hit-rate, drift by client and work
  type.
- Never pooled — your leverage isn't theirs. Your history only.
- miara won't answer below three confirmed comparables. It returns no number
  at all.

https://dirahq.sh/miara

## Fineness — 585 / 750 / 999

How deep the evidence behind a shipped change goes.

| Grade | Requires | Adds |
| --- | --- | --- |
| 585 | proba App only | CI state, non-author review, agent authorship inferred from trailers and bot accounts. Weak provenance — and labelled as such. |
| 750 | + dira on the workstation | Cryptographically attributed sessions, which harness wrote it, engaged supervision-minutes per change. The layer a code host structurally cannot see. |
| 999 | + zavet in the repo | Decisions referenced by the change; guards respected, not bypassed. |

## The one rule

No product in letopis ever states an opinion — only records that can be
checked.

- **dira won't** bill an hour it cannot anchor to a real commit. Unverified
  time is quarantined.
- **zavet won't** invent a rationale. Backfilled specs stay marked unverified
  until a human confirms.
- **proba won't** say whether the code is good. It grades the process, at a
  stated fineness of evidence.
- **miara won't** answer below three confirmed comparables. It returns no
  number at all.

## Pricing — free where the chronicle is public, paid where it's yours

One price for all four books — splitting the chain into four SKUs would
contradict the entire product. You are billed per developer who actually
recorded something that month, and for nothing else — from two active
developers up to fifty. Above fifty, per contract.

| Plan | Price | For |
| --- | --- | --- |
| Personal | €0 forever | Solo developers, on your own machine — dira capture, zavet in full, proba on public repos, offline reports, self-host the whole stack |
| Open Source | €0 forever | Maintainers & community projects — everything in Personal, hosted, all three fineness grades, unlimited contributors, README badge |
| Team | €18 / active dev / mo, or €180 a year — two months free | Private repos, real clients, real invoices — 2–50 active devs, 51+ → talk to us. The whole suite: dira, zavet, proba (private-repo hallmarks, Observe + Signal), miara |
| Enterprise & on-prem | Quoted per contract | 51+ developers, your infra — proba Enforce, SSO, SCIM, data residency, audit export |

The honest part:

- **A quiet month costs nothing.** A developer who recorded no sessions is
  not billed. Not prorated — not billed.
- **One price, four books.** No per-product SKUs and no upsell between links
  in the chain.
- **Nothing free becomes paid.** Local capture, guards, `/zavet:why` and
  self-hosting stay free permanently.
- **Your data leaves on request.** The repo and your machine are the source
  of truth; the cloud is a projection. Cancel and you keep every record.

---

Start the chronicle with one command:

```
curl -fsSL https://dirahq.sh/install | sh
```

dira is free forever for solo work and open source. Everything else is
written on top of it. Made in Bulgaria by DODI SMART OOD. See also
[/index.md](https://dirahq.sh/index.md), [/zavet.md](https://dirahq.sh/zavet.md).
