Origin
Every submission arrives knowing where it came from.
Origin is a field on the submission, not a score we guessed from mouse movement. Human, Agent, or Unverified — recorded at the moment it lands, exportable, filterable, and auditable in the source.
What it is
Origin is a stamp on every submission with three values — Human, Agent, or Unverified — set by which surface the submission came through.
Where this stands
Endpoint Forms is pre-launch. Origin is designed and specified; it is not running anywhere you can sign up for today.
Submissions
| Received | Submitted by | Surface used | Origin | Routed to |
|---|---|---|---|---|
| 14:22 | dana@northgate.io | Human page | Human | CRM · new lead |
| 14:19 | procurement agent · Acme Foods | Manifest | Agent | CRM · tagged Agent |
| 14:11 | no email captured | Human page | Unverified | Quarantine |
| 13:58 | m.okonjo@setterfield.co | Human page | Human | CRM · new lead |
| 13:51 | buying assistant · unnamed | Manifest | Agent | CRM · tagged Agent |
| 13:44 | qwtn@mailinator.com | Human page | Unverified | Quarantine |
The stamp is not inferred from behaviour. It is the answer to which door was used — which is why Unverified means “submitted the human page while acting like software” and not “scored 82 on a risk model”.
How it works
01
One form definition publishes two surfaces
The form you build renders a page for people, and publishes a machine-callable tool definition for software. Same fields, same validation, same required rules. That second surface is Manifest, and it is the thing that makes Origin possible rather than probabilistic.
02
The surface used is the stamp
A submission through the human page, behaving like a browser session, is Human. A submission through the manifest, identifying itself as software, is Agent. Anything that submits the human form while behaving like software is Unverified — it told on itself by using the wrong door.
03
Origin travels with the record
It is a column in the dashboard, a field in the webhook payload, a column in the export, and a filter on every report. Not a badge in a UI you have to go look at.
04
Unverified is quarantined, not deleted
Suspect submissions land in a separate bucket. Not your CRM, not your conversion count, and not training your ad platform to send you more of the same. You can still read them, because sometimes we will be wrong.
The problem it solves
Spam and junk leads are the angriest complaint in this category, and every defense people reach for asks the visitor to prove something rather than asking software to declare itself. CAPTCHA asks whether you can solve a puzzle. A $2 solving service answers that in about thirty seconds. Honeypots catch the naive scripts and nothing else.
The people who have tried all of it say the same thing:
“We have recaptcha enabled, and I have a honeypot, but it didn’t stop.”
Origin does not raise the obstacle. It changes the question from “can you do the puzzle?” to “what are you?” — and gives the honest answer a clean way through instead of a harder maze.
The full case, including the strongest arguments against it, is in the argument.
The catch
The honest limitation
Unverified is a suspicion, not a verdict. That is why the value is called Unverified and not “Bot” — we report what we know, not what we assume. Real people will sometimes land there: hardened privacy browsers, aggressive extensions, corporate proxies, a person on a network we cannot read.
That is the reason quarantine is a reviewable bucket rather than a delete. If you run a form where a false negative costs you a real deal, you should read the quarantine. We would rather build the feature that admits it can be wrong than the one that pretends it can’t.
What Origin doesn’t do
- It is not a spam filter that promises zero spam.
- Nothing promises that honestly. Origin makes the composition of your submissions visible and keeps the suspect ones out of the numbers that matter.
- It does not tell you whether the person is a good fit.
- A real human can still be a tire-kicker. Whether a submission was worth anything is Verdict’s job, and it can only be answered later.
- It is not a behavioural risk score.
- There is no 0–100 confidence number derived from typing cadence. Three values, set by which surface was used, and the rules that decide are in the open-source core so you can read them.
Waitlist
Nothing on this page is running yet.
Endpoint Forms is pre-launch. Leave your email and we’ll write once, when there’s something to look at — not a drip sequence about Origin.