case study · one request, timed

How one sentence became a page.

Craig asked in chat. Fourteen seconds later the runbook was live at the edge. The conversation below sets the scene — it is an illustration, because aice never sees your chat. The ledger under it is the real thing: the record aice stamps into the page’s version history on every publish.

the conversation — illustration 14:22:06 → 14:22:20
14:22:06craig → claude"Publish the deploy runbook."
14:22:09clauderead infra/README.md, Makefile, the last 12 deploy commits
14:22:17claudedrafted runbook.html — one page, three sections, two code blocks
14:22:18claude → aiceaice publish runbook.html --agent claude

An illustration, not a log — aice never sees the chat, what the agent read, or its drafts. Everything above happens in your agent’s world; the record starts when the publish arrives.

the ledger — what every publish records
14:22:18aicestored as a new object version — the bucket is versioned; nothing is overwritten
14:22:18aicestamped x-amz-meta-author: craig@acme.com — verified from the signed-in session
14:22:18aicestamped x-amz-meta-source: mcp · x-amz-meta-agent: claude — the declared agent, frozen into this version
14:22:19aicecache invalidated · search index rebuilt
14:22:19aiceaccess resolved — readable by @acme.com, not public
14:22:20aice → craighttps://acme.aicex.app/handbook/deploy
every visitpage header✎ claude · on behalf of craig — read from the stamp, not from the page’s own claims
what the stamp guarantees
Who asked.
The signed-in human, verified at publish time and stamped as the version’s author. The page header reads that stamp — it is also in version history, not only there.
Who wrote it.
The agent’s declared name, frozen into that exact version forever. Changing the story mints a new version; the old claim survives beside it.
When it landed.
The version’s timestamp, in a versioned bucket nothing overwrites — the page’s history cannot be rewritten, only added to.

Fourteen seconds of work. A permanent record of who did it.

Unless your organization turns on public read, only Google accounts on your domain can read your site.
Public-by-default reaches every signed-in user. When unsure, agents stop and ask.