Proofroom

Evidence Pack

Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.

Weekly security posture sweep

Agent: Proofroom Security Agent · Operated by Proofroom

Generated 2026-07-29 23:18:08 UTC

Status at generation: Evidence Verified · Chain: chain valid (22 events)

2. Executive summary

This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Weekly security posture sweep. At generation time the evidence chain contained 22 hash-chained events, of which 11 material actions carry Action Receipts. The Evidence Coverage Score was 91 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.

3. How to read this pack

Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

4. Agent passport

NameProofroom Security Agent
DescriptionInternal security agent for Proofroom. Runs the Monday posture ritual (RLS status, key age, queue hygiene, failure scan) and reports honestly, including what it cannot check. Remediation is proposed, never executed autonomously.
StackAnthropic claude-sonnet-4-5 via Inngest
Internal company agentYes
Accountable humanSimon Brown

5. Use case passport

Use caseWeekly security posture sweep
DescriptionThe Security Agent runs a weekly read-only posture sweep across RLS status, API key age, approval queue hygiene and run failures, and reports findings by severity with proposed remediations.
ScopeRead-only posture checks and operator reports. Dependency upgrades and key rotations are proposed for approval; disabling logging or modifying RLS is forbidden.
Allowed actionsrun read-only posture checks; produce severity-ranked posture reports; propose remediations for operator approval
Prohibited actionsdisable or modify logging; modify row level security; execute remediations without approval; suppress findings
Evidence decay window10 days

6. Oversight model and decision rights

The sweep and report are autonomous and receipted. Every remediation (dependency upgrades, key rotations) is tier-2 operator approval.

Action keyTier
security.rotate_keyapproval
security.dependency_upgradeapproval
security.send_reportautonomous
security.disable_loggingforbidden
security.modify_rlsforbidden

Active playbook at generation: version 2, SHA-256 c5f1c6dd4964ad2c2afee43b3c1bf25b7c4d30131f0fc60b53db3db2c71a554a

7. Evidence methodology

Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.

8. Evidence Coverage Score

91 / 100

ComponentPointsDetail
Declaration completeness20/20Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
Chain integrity25/25All 22 events recomputed and verified.
Evidence freshness15/15Last event 2 hours ago against a 10-day decay window.
Activity depth12/1522 events recorded (full marks at 50 or more).
Material action coverage15/1510 of 10 material actions carry receipts.
Source strength bonus4/10Evidence includes confirmation beyond self-reporting.

9. Chain integrity verification

State at generationchain valid
Events recomputed22
Verified at2026-07-29 23:18:08 UTC

10. Action Receipts register

ReceiptAuthorityEvidence levelSummaryDate
BBV-10094in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10116n/a - self-audit eventoperator confirmedMaterial action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10739in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-06-22
PRF-11081in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-06-28
PRF-11234in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-06-29
PRF-11479in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-03
PRF-11932in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-06
PRF-12302in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-13
PRF-12671in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-20
PRF-13043in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-27
PRF-13178in scopeself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.2026-07-29

11. Evidence log summary

Total events22
By sourcesystem: 1; internal_agent: 21
By evidence levelself reported: 21; operator confirmed: 1

12. Framework crosswalk: ISO 42001

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

ReferenceTopicMapped by
A.6.2 (AI system life cycle)Defined scope and intended use of the AI systemUse case passport: scope summary, allowed and prohibited actions
A.9.2 (Processes for responsible use)Human oversight of AI system operationOversight model and executable decision-rights tiers with approval trail
A.6.2.8 (Event logging)Recording of AI system activityAppend-only, hash-chained evidence events with sequence integrity verification
A.8.2 (System documentation)Information available to interested partiesLive proof room, Action Receipts and Evidence Pack with declared evidence levels

13. Framework crosswalk: SIG, CAIQ and NIST

FrameworkReferenceTopicMapped by
SIGAI module: governanceInventory and ownership of AI agentsAgent passport with accountable human and registered use cases
SIGAI module: operationsMonitoring and exception handling for automated agentsRun ledger, spend caps, exception events and operator escalation receipts
CAIQAIS (Application and Interface Security)Audit trail of application actionsAction Receipts with authority status and tamper-evident chain
CAIQGRC (Governance, Risk and Compliance)Documented risk boundaries for automated systemsProhibited actions, forbidden decision tiers and kill-switch evidence
NISTAI RMF: GovernAccountability structures for AI systemsAccountable human on every internal agent; approvals resolved by named operators
NISTAI RMF: MeasureTracking of AI system behaviour over timeEvidence Coverage Score with component breakdown and status decay
NISTAI agent guidance: least privilegeConstraining agent capabilities to declared scopeTool allowlists, decision-rights tiers and out-of-scope receipt flagging

14. Limitations and verification

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

Use your browser's Print function (Ctrl+P) and choose "Save as PDF" to export this pack. Back to Proofroom · Open live proof room