What Monvera records on-chain, and how you check it
Vera signs the risk assessment, you sign the spend, and both land on-chain in one transaction anyone can read.
Every plan you invest writes Vera’s signed risk assessment onto Robinhood Chain in the same transaction that buys the stocks. Vera signs the risk assessment; you sign the spend. Because both land together, her call on a plan cannot be edited, deleted, or backdated later, and you can read the whole record from public chain data without asking Monvera for anything.
What lands on the record
Section titled “What lands on the record”Two things are recorded per plan: the values Vera actually signed, and the facts about the trade written alongside them.
| Recorded | What it is | Inside Vera’s signature |
|---|---|---|
planId |
A hash of the exact allocation, single-use | Yes |
assessedRisk |
Vera’s risk score for this plan, 0 to 10000 | Yes |
maxRisk |
The ceiling the plan was not allowed to exceed | Yes |
expiry |
The moment the assessment goes stale | Yes |
user |
The account that invested | No, recorded alongside |
agentId |
Vera’s registry id on chain 4663, which is 1 |
No, recorded alongside |
usdSpent, legCount |
Dollars committed and how many names | No, recorded alongside |
The contract emits RecommendationCommitted and AllocationExecuted on success. Those two events are Vera’s public track record: every plan she has assessed, with the risk she assessed it at, timestamped by the block it landed in.
Read a record yourself
Section titled “Read a record yourself”GET /api/vera-record is public, needs no token, and returns the recorded assessments for any account, so you can confirm a plan without trusting anything the app shows you.
curl "https://monvera.best/api/vera-record?user=<your-account-address>"const res = await fetch( "https://monvera.best/api/vera-record?user=<your-account-address>");const data = await res.json();Public reads are limited to 30 requests per 60 seconds per IP. The same events are readable straight off the chain on Blockscout; the public RPC caps a log scan at 10,000 blocks, which is why full history goes through the API rather than a raw scan.
To go further and prove authorship rather than read it, follow Verify Vera: read her agent card, recover the signer from a plan’s payload, and assert it equals the live agentSigner() on the contract. That page has the runnable procedure and every address.
You can also just ask.
Why the two signatures are separate
Section titled “Why the two signatures are separate”Vera’s signature answers “who made this risk call”. Yours answers “whose money moves”. They are produced by different keys, held by different parties, and they are never interchangeable.
Vera signs with her agent key, which lives server-side and never touches your account. That signature is an authorship claim: this agent, this plan, this risk score, before this expiry. You sign the user operation with the key in your own wallet, and only that authorizes dollars to leave. Monvera cannot produce your signature, and Vera’s signature cannot spend anything.
One transaction, or none
Section titled “One transaction, or none”The buys and the record are batched into a single gas-sponsored transaction. There is no window where the trades exist without the assessment, or the assessment without the trades. If the record fails, the buys revert with it:
| Failure | What it means |
|---|---|
PlanAlreadyRecorded |
This plan id was already recorded. Ids are single-use, so a record cannot be written twice |
InferenceExpired |
The assessment is past its expiry. A stale risk call cannot be attached to a fresh trade |
RiskCeilingBreached |
The assessed risk exceeds the ceiling the plan was built under |
BadSigner |
The recovered signer is not the live agent signer. Nobody else can write to Vera’s record |
That last one is the load-bearing guard. The contract checks the recovered signer against agentSigner() on-chain, so a forged assessment does not get quietly filed next to a real trade.
What this does and does not buy you
Section titled “What this does and does not buy you”What it buys you is a track record that cannot be curated after the fact. Vera cannot delete the plans that went badly, revise a risk score once the market disagrees with it, or claim a call she did not make. You can hold each assessment against what actually happened.
What it does not buy you is correctness. The record is honest, not clairvoyant, and reading it is the point: see how Vera picks and weights a plan for what goes into an assessment and where it can be wrong.
© 2026 Aibora · Documentation interface. Original Monvera materials retain their upstream attribution andMIT license.