Why agent-native operations need evidence

An agent that can touch production needs a stricter contract than a human with a terminal. It needs a bounded tool, scoped identity, risk policy, approval when the blast radius is real, and evidence that survives the chat.

Weppa models that contract as operation_run. The record contains the actor, parameters, events, evidence, final decision and rollback path. Visor, CLI and external agents render the same contract instead of inventing separate ways to operate a customer app.