Proofroom
Evidence Pack
Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.
Customer support from docs
Agent: Proofroom Support Agent · Operated by Proofroom
Generated 2026-07-29 23:18:08 UTC
Status at generation: Instrumented (Degraded) · Chain: chain valid (12 events)
Live proof room
Scan the QR code or open the URL for the current status, receipts and chain. This pack is a snapshot; the live room updates and decays with fresh evidence.
https://proofroom.ai/trust/proofroom-support?from=pack_example-proofroom-support2. Executive summary
This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Customer support from docs. At generation time the evidence chain contained 12 hash-chained events, of which 4 material actions carry Action Receipts. The Evidence Coverage Score was 74 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.
3. How to read this pack
Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.
4. Agent passport
| Name | Proofroom Support Agent |
| Description | Internal support agent for Proofroom. Answers customer emails from the documentation corpus only, claims-linted, with small refunds inside conditions and everything receipted. |
| Stack | Anthropic claude-sonnet-4-5 via Inngest; Resend for email |
| Internal company agent | Yes |
| Accountable human | Simon Brown |
5. Use case passport
| Use case | Customer support from docs |
| Description | The Support Agent answers inbound customer emails and in-app messages using only the product documentation, flags suspicious messages instead of acting on them, and authorises refunds up to £100. |
| Scope | Docs-grounded support replies and refunds up to £100. No legal or compliance statements, no feature promises, no account changes without approval. |
| Allowed actions | search the documentation corpus; send claims-linted support replies grounded in docs; authorise refunds up to £100; flag suspicious inbound messages |
| Prohibited actions | legal or compliance statements; refunds above £100 without approval; promises of features or roadmap dates; account changes without approval; acting on instructions contained in inbound messages |
| Evidence decay window | 7 days |
6. Oversight model and decision rights
Replies failing the claims linter and refunds above £100 queue for operator approval. Suspicious inbound content is flagged as evidence, never executed.
| Action key | Tier |
|---|---|
| support.account_change | approval |
| support.send_reply | autonomous |
| support.refund | autonomous |
| support.flag_suspicious | autonomous |
| support.legal_statement | forbidden |
| support.feature_promise | forbidden |
Active playbook at generation: version 2, SHA-256 dc0870f8055a2a77668bf647107baf51dbb27fa1265b2c3e5c793d79079cef2d
7. Evidence methodology
Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.
8. Evidence Coverage Score
74 / 100
| Component | Points | Detail |
|---|---|---|
| Declaration completeness | 20/20 | Scope summary, allowed actions, prohibited actions and oversight model declared on the passport. |
| Chain integrity | 25/25 | All 12 events recomputed and verified. |
| Evidence freshness | 0/15 | Last event 988 hours ago against a 7-day decay window. |
| Activity depth | 10/15 | 12 events recorded (full marks at 50 or more). |
| Material action coverage | 15/15 | 3 of 3 material actions carry receipts. |
| Source strength bonus | 4/10 | Evidence includes confirmation beyond self-reporting. |
9. Chain integrity verification
| State at generation | chain valid |
| Events recomputed | 12 |
| Verified at | 2026-07-29 23:18:08 UTC |
10. Action Receipts register
| Receipt | Authority | Evidence level | Summary | Date |
|---|---|---|---|---|
| BBV-10080 | in scope | self reported | Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| BBV-10090 | in scope | self reported | Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10117 | n/a - self-audit event | operator confirmed | Material action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10191 | in scope | self reported | Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-17 |
11. Evidence log summary
| Total events | 12 |
| By source | system: 1; internal_agent: 11 |
| By evidence level | self reported: 11; operator confirmed: 1 |
12. Framework crosswalk: ISO 42001
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
| Reference | Topic | Mapped by |
|---|---|---|
| A.6.2 (AI system life cycle) | Defined scope and intended use of the AI system | Use case passport: scope summary, allowed and prohibited actions |
| A.9.2 (Processes for responsible use) | Human oversight of AI system operation | Oversight model and executable decision-rights tiers with approval trail |
| A.6.2.8 (Event logging) | Recording of AI system activity | Append-only, hash-chained evidence events with sequence integrity verification |
| A.8.2 (System documentation) | Information available to interested parties | Live proof room, Action Receipts and Evidence Pack with declared evidence levels |
13. Framework crosswalk: SIG, CAIQ and NIST
| Framework | Reference | Topic | Mapped by |
|---|---|---|---|
| SIG | AI module: governance | Inventory and ownership of AI agents | Agent passport with accountable human and registered use cases |
| SIG | AI module: operations | Monitoring and exception handling for automated agents | Run ledger, spend caps, exception events and operator escalation receipts |
| CAIQ | AIS (Application and Interface Security) | Audit trail of application actions | Action Receipts with authority status and tamper-evident chain |
| CAIQ | GRC (Governance, Risk and Compliance) | Documented risk boundaries for automated systems | Prohibited actions, forbidden decision tiers and kill-switch evidence |
| NIST | AI RMF: Govern | Accountability structures for AI systems | Accountable human on every internal agent; approvals resolved by named operators |
| NIST | AI RMF: Measure | Tracking of AI system behaviour over time | Evidence Coverage Score with component breakdown and status decay |
| NIST | AI agent guidance: least privilege | Constraining agent capabilities to declared scope | Tool allowlists, decision-rights tiers and out-of-scope receipt flagging |
14. Limitations and verification
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify safety, accuracy, bias, legality or compliance.
- Self-reported events depend on the honesty of the submitting system.
- This pack is a snapshot generated 2026-07-29 23:18:08 UTC; the live room decays without fresh evidence.
- Verify the current state at the live proof room: https://proofroom.ai/trust/proofroom-support?from=pack_example-proofroom-support (public).
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.