Proofroom

Evidence Pack

Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.

Issue-to-merge product delivery

Agent: Proofroom Product Agent · Operated by Proofroom

Generated 2026-07-29 23:18:08 UTC

Status at generation: Action Verified (Degraded) · Chain: chain valid (14 events)

2. Executive summary

This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Issue-to-merge product delivery. At generation time the evidence chain contained 14 hash-chained events, of which 10 material actions carry Action Receipts. The Evidence Coverage Score was 80 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.

3. How to read this pack

Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

4. Agent passport

NameProofroom Product Agent
DescriptionInternal product agent for Proofroom. Triages GitHub issues, drafts specs, and dispatches approved coding tasks to the Cursor background agent API. It never writes code itself; every step is receipted on its public chain.
StackAnthropic claude-sonnet-4-5 via Inngest; dispatches to Cursor Background Agents API
Internal company agentYes
Accountable humanSimon Brown

5. Use case passport

Use caseIssue-to-merge product delivery
DescriptionThe Product Agent receives GitHub issues, triages and labels them, drafts implementation specs, dispatches approved coding tasks to the Cursor API, and merges approved pull requests to staging. Production deploys and schema migrations are forbidden to it.
ScopeGitHub issue triage, spec drafting, approved Cursor dispatches and approved staging merges for Proofroom repositories. No production deploys, no schema migrations, no evidence table edits.
Allowed actionstriage and label GitHub issues; draft implementation specs; dispatch coding tasks to the Cursor background agent API (with approval); merge pull requests to staging (with approval); trigger staging deploys (with approval)
Prohibited actionsdeploy to production; run schema migrations without the operator; edit evidence tables; write code directly; merge to production branches
Evidence decay window7 days

6. Oversight model and decision rights

Decision-rights tiers enforced by the product runtime. Triage and spec drafting are autonomous; Cursor dispatch, PR merge and staging deploys each require one-tap operator approval; production actions are forbidden.

Action keyTier
product.merge_prapproval
product.deploy_stagingapproval
product.dispatch_cursorapproval
product.triage_issueautonomous
product.draft_specautonomous
product.deploy_productionforbidden
product.schema_migrationforbidden
product.edit_evidenceforbidden

Active playbook at generation: version 2, SHA-256 9cbb44e5988a0ca25d6bdd186c71bae4d791e62878a12aecef9f39007e04eead

7. Evidence methodology

Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.

8. Evidence Coverage Score

80 / 100

ComponentPointsDetail
Declaration completeness20/20Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
Chain integrity25/25All 14 events recomputed and verified.
Evidence freshness0/15Last event 988 hours ago against a 7-day decay window.
Activity depth10/1514 events recorded (full marks at 50 or more).
Material action coverage15/159 of 9 material actions carry receipts.
Source strength bonus10/10Evidence includes confirmation beyond self-reporting.

9. Chain integrity verification

State at generationchain valid
Events recomputed14
Verified at2026-07-29 23:18:07 UTC

10. Action Receipts register

ReceiptAuthorityEvidence levelSummaryDate
BBV-10013in scopeself reportedMaterial action recorded: decision made. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
BBV-10014in scopeself reportedMaterial action recorded: output generated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
BBV-10076in scopeself reportedMaterial action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
BBV-10085in scopeself reportedMaterial action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
BBV-10086n/a - self-audit eventsystem confirmedMaterial action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10115n/a - self-audit eventoperator confirmedMaterial action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10180in scopeself reportedMaterial action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-17
PRF-10181n/a - self-audit eventsystem confirmedMaterial action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access.2026-06-17
PRF-10186in scopeself reportedMaterial action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-17
PRF-10187n/a - self-audit eventsystem confirmedMaterial action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access.2026-06-17

11. Evidence log summary

Total events14
By sourcesystem: 4; internal_agent: 10
By evidence levelself reported: 10; system confirmed: 3; operator confirmed: 1

12. Framework crosswalk: ISO 42001

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

ReferenceTopicMapped by
A.6.2 (AI system life cycle)Defined scope and intended use of the AI systemUse case passport: scope summary, allowed and prohibited actions
A.9.2 (Processes for responsible use)Human oversight of AI system operationOversight model and executable decision-rights tiers with approval trail
A.6.2.8 (Event logging)Recording of AI system activityAppend-only, hash-chained evidence events with sequence integrity verification
A.8.2 (System documentation)Information available to interested partiesLive proof room, Action Receipts and Evidence Pack with declared evidence levels

13. Framework crosswalk: SIG, CAIQ and NIST

FrameworkReferenceTopicMapped by
SIGAI module: governanceInventory and ownership of AI agentsAgent passport with accountable human and registered use cases
SIGAI module: operationsMonitoring and exception handling for automated agentsRun ledger, spend caps, exception events and operator escalation receipts
CAIQAIS (Application and Interface Security)Audit trail of application actionsAction Receipts with authority status and tamper-evident chain
CAIQGRC (Governance, Risk and Compliance)Documented risk boundaries for automated systemsProhibited actions, forbidden decision tiers and kill-switch evidence
NISTAI RMF: GovernAccountability structures for AI systemsAccountable human on every internal agent; approvals resolved by named operators
NISTAI RMF: MeasureTracking of AI system behaviour over timeEvidence Coverage Score with component breakdown and status decay
NISTAI agent guidance: least privilegeConstraining agent capabilities to declared scopeTool allowlists, decision-rights tiers and out-of-scope receipt flagging

14. Limitations and verification

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

Use your browser's Print function (Ctrl+P) and choose "Save as PDF" to export this pack. Back to Proofroom · Open live proof room