Proofroom
Evidence Pack
Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.
Chain head anchoring
Agent: Proofroom Ops Agent · Operated by Proofroom
Generated 2026-08-04 21:41:30 UTC
Status at generation: Instrumented · Chain: chain valid (12 events)
Live proof room
Scan the QR code or open the URL for the current status, receipts and chain. This pack is a snapshot; the live room updates and decays with fresh evidence.
https://proofroom.ai/trust/proofroom-chain-anchors?from=pack_example-proofroom-chain-anchors2. Executive summary
This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Chain head anchoring. At generation time the evidence chain contained 12 hash-chained events, of which 12 material actions carry Action Receipts. The Evidence Coverage Score was 90 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.
3. How to read this pack
Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.
4. Agent passport
| Name | Proofroom Ops Agent |
| Description | Internal operations agent for Proofroom. Monitors platform health, sweeps chain integrity, and sends the daily operator digest. Customer zero: every run is hash-chained into its own public evidence trail. |
| Stack | Anthropic claude-sonnet-4-5 via Inngest on Vercel |
| Internal company agent | Yes |
| Accountable human | Proofroom Operator |
5. Use case passport
| Use case | Chain head anchoring |
| Description | Records each external chain-head anchoring run. Manifests are published to the public proofroom-anchors repository. |
| Scope | Publish daily Merkle-rooted chain-head manifests to an external public repository and OpenTimestamps. |
| Allowed actions | publish chain head anchor; retry OpenTimestamps stamp |
| Prohibited actions | publish customer free text; publish use case UUIDs |
| Evidence decay window | 3 days |
6. Oversight model and decision rights
Automated system job with operator visibility on the anchoring proof room.
| Action key | Tier |
|---|---|
| ops.restart_agent | approval |
| ops.change_caps | approval |
| ops.retry_failed_job | autonomous |
| ops.flag_anomaly | autonomous |
| ops.send_digest | autonomous |
| ops.billing_action | forbidden |
| ops.touch_customer_data | forbidden |
Active playbook at generation: version 7, SHA-256 e60842a495e57c298083f48fdd79e99e16a6acec126eeca70fcf6b8d44d1d16f
7. Evidence methodology
Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.
8. Evidence Coverage Score
90 / 100
| Component | Points | Detail |
|---|---|---|
| Declaration completeness | 10/10 | Scope summary, allowed actions, prohibited actions and oversight model declared on the passport. |
| Chain integrity | 20/20 | All 12 events recomputed successfully. |
| Evidence freshness | 15/15 | Last event 24 hours ago against a 3-day decay window. |
| Activity depth | 10/15 | 12 events recorded (full marks at 50 or more). |
| Material action coverage | 15/15 | 10 of 10 material actions carry receipts. |
| Source strength bonus | 5/5 | Evidence includes confirmation beyond self-reporting. |
| Configuration provenance declared | 0/5 | Configuration not declared. |
| Identity and accountability | 15/15 | Scope confirmed by a human. |
9. Chain integrity verification
| State at generation | chain valid |
| Events recomputed | 12 |
| Verified at | 2026-08-04 21:41:29 UTC |
10. Action Receipts register
| Receipt | Authority | Evidence level | Summary | Key id | Date |
|---|---|---|---|---|---|
| PRF-13249 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-07-30): 8 entries, status timestamped, merkle c44a0b8fca5d. | — | 2026-07-30 |
| PRF-13253 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-07-30): 9 entries, status timestamped, merkle 32d6d4b1ad84. | — | 2026-07-30 |
| PRF-13439 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-02): 11 entries, status timestamped, merkle 1bc7317008ea. | — | 2026-08-02 |
| PRF-13447 | in scope | operator confirmed | Material action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access. | — | 2026-08-02 |
| PRF-13500 | n/a - self-audit event | operator confirmed | Material action recorded: correction recorded. Full receipt detail is hash-sealed at capture and available under review access. | — | 2026-08-03 |
| PRF-13501 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 17 entries, status timestamped, merkle 697548e21483. | — | 2026-08-03 |
| PRF-13505 | n/a - self-audit event | operator confirmed | Material action recorded: correction recorded. Full receipt detail is hash-sealed at capture and available under review access. | — | 2026-08-03 |
| PRF-13518 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 22 entries, status timestamped, merkle 4d94720eced9. | — | 2026-08-03 |
| PRF-13519 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 22 entries, status failed, merkle 5483542dd630. | — | 2026-08-03 |
| PRF-13538 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 22 entries, status timestamped, merkle fbf7e7d3a93e. | — | 2026-08-03 |
| PRF-13566 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 23 entries, status failed, merkle 5d80d56e103a. | — | 2026-08-03 |
| PRF-13567 | n/a - self-audit event | system confirmed | Chain heads anchored externally (2026-08-03): 23 entries, status timestamped, merkle 5d80d56e103a. | — | 2026-08-03 |
11. Evidence log summary
| Total events | 12 |
| By source | system: 12 |
| By evidence level | system confirmed: 9; operator confirmed: 3 |
12. Framework crosswalk: ISO 42001
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
| Reference | Topic | Mapped by |
|---|---|---|
| A.6.2 (AI system life cycle) | Defined scope and intended use of the AI system | Use case passport: scope summary, allowed and prohibited actions |
| A.9.2 (Processes for responsible use) | Human oversight of AI system operation | Oversight model and executable decision-rights tiers with approval trail |
| A.6.2.8 (Event logging) | Recording of AI system activity | Append-only, hash-chained evidence events with sequence integrity verification |
| A.8.2 (System documentation) | Information available to interested parties | Live proof room, Action Receipts and Evidence Pack with declared evidence levels |
13. Framework crosswalk: SIG, CAIQ and NIST
| Framework | Reference | Topic | Mapped by |
|---|---|---|---|
| SIG | AI module: governance | Inventory and ownership of AI agents | Agent passport with accountable human and registered use cases |
| SIG | AI module: operations | Monitoring and exception handling for automated agents | Run ledger, spend caps, exception events and operator escalation receipts |
| CAIQ | AIS (Application and Interface Security) | Audit trail of application actions | Action Receipts with authority status and tamper-evident chain |
| CAIQ | GRC (Governance, Risk and Compliance) | Documented risk boundaries for automated systems | Prohibited actions, forbidden decision tiers and kill-switch evidence |
| NIST | AI RMF: Govern | Accountability structures for AI systems | Accountable human on every internal agent; approvals resolved by named operators |
| NIST | AI RMF: Measure | Tracking of AI system behaviour over time | Evidence Coverage Score with component breakdown and status decay |
| NIST | AI agent guidance: least privilege | Constraining agent capabilities to declared scope | Tool allowlists, decision-rights tiers and out-of-scope receipt flagging |
14. Limitations and verification
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify accuracy, bias, legality or fitness for purpose.
- Self-reported events depend on the honesty of the submitting system.
- This trail evidences what was recorded. It cannot evidence actions the agent did not report. Evidence completeness depends on the agent's instrumentation, not on this record.
- External anchoring proves this chain head existed at the anchor time. It bounds any retrospective alteration to the period since the last anchor. It does not prove that events recorded before an anchor were genuine at the moment they were reported.
- We never rewrite evidence. Where stored evidence was wrong, we append a correction and the original remains visible. A chain may therefore show a permanent, explained discontinuity. We regard that as more credible than a chain that appears to heal.
- Declared but never recorded: publish chain head anchor; retry OpenTimestamps stamp.
- This pack is a snapshot generated 2026-08-04 21:41:30 UTC; the live room decays without fresh evidence.
- Verify the current state at the live proof room: https://proofroom.ai/trust/proofroom-chain-anchors?from=pack_example-proofroom-chain-anchors (public).
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.