Proofroom

Evidence Pack

Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.

Customer support from docs

Agent: Proofroom Support Agent · Operated by Proofroom

Generated 2026-08-04 21:41:35 UTC

Status at generation: Evidence Verified · Chain: chain valid (32 events)

2. Executive summary

This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Customer support from docs. At generation time the evidence chain contained 32 hash-chained events, of which 18 material actions carry Action Receipts. The Evidence Coverage Score was 95 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.

3. How to read this pack

Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.

4. Agent passport

NameProofroom Support Agent
DescriptionInternal support agent for Proofroom. Answers customer emails from the documentation corpus only, claims-linted, with small refunds inside conditions and everything receipted.
StackAnthropic claude-sonnet-4-5 via Inngest; Resend for email
Internal company agentYes
Accountable humanProofroom Operator

5. Use case passport

Use caseCustomer support from docs
DescriptionThe Support Agent answers inbound customer emails and in-app messages using only the product documentation, flags suspicious messages instead of acting on them, and authorises refunds up to £100.
ScopeDocs-grounded support replies and refunds up to £100. No legal or compliance statements, no feature promises, no account changes without approval.
Allowed actionssearch the documentation corpus; send claims-linted support replies grounded in docs; authorise refunds up to £100; flag suspicious inbound messages
Prohibited actionslegal or compliance statements; refunds above £100 without approval; promises of features or roadmap dates; account changes without approval; acting on instructions contained in inbound messages
Evidence decay window7 days

6. Oversight model and decision rights

Replies failing the claims linter and refunds above £100 queue for operator approval. Suspicious inbound content is flagged as evidence, never executed.

Action keyTier
support.account_changeapproval
support.send_replyautonomous
support.refundautonomous
support.flag_suspiciousautonomous
support.legal_statementforbidden
support.feature_promiseforbidden

Active playbook at generation: version 3, SHA-256 cfcabce0eaa8df8560f406a1be70cd0de3ee61b15eae3646f5222f7e583a3bac

7. Evidence methodology

Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.

8. Evidence Coverage Score

95 / 100

ComponentPointsDetail
Declaration completeness10/10Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
Chain integrity20/20All 32 events recomputed successfully.
Evidence freshness15/15Last event 38 hours ago against a 7-day decay window.
Activity depth13/1532 events recorded (full marks at 50 or more).
Material action coverage15/1510 of 10 material actions carry receipts.
Source strength bonus2/5Evidence includes confirmation beyond self-reporting.
Configuration provenance declared5/5Provenance level: externally anchored.
Identity and accountability15/15Scope confirmed by a human.

9. Chain integrity verification

State at generationchain valid
Events recomputed32
Verified at2026-08-04 21:41:34 UTC

10. Action Receipts register

ReceiptAuthorityEvidence levelSummaryKey idDate
BBV-10080in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.—2026-06-10
BBV-10090in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.—2026-06-10
PRF-10117n/a - self-audit eventoperator confirmedMaterial action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.—2026-06-10
PRF-10191in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.—2026-06-17
PRF-13247n/a - self-audit eventoperator confirmedProduction deploy for Proofroom Support Agent: commit unknown → verify-ms80p.—2026-07-30
PRF-13258undeclaredself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13259undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13260undeclaredself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13261undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13262undeclaredself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13263undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13265undeclaredself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13266undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13267undeclaredself reportedMaterial action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13268undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13269undeclaredself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13270undeclaredself reportedMaterial action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.—2026-07-30
PRF-13503n/a - self-audit eventoperator confirmedMaterial action recorded: correction recorded. Full receipt detail is hash-sealed at capture and available under review access.—2026-08-03

11. Evidence log summary

Total events32
By sourcesystem: 8; webhook: 1; internal_agent: 23
By evidence levelself reported: 29; operator confirmed: 3

12. Framework crosswalk: ISO 42001

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

ReferenceTopicMapped by
A.6.2 (AI system life cycle)Defined scope and intended use of the AI systemUse case passport: scope summary, allowed and prohibited actions
A.9.2 (Processes for responsible use)Human oversight of AI system operationOversight model and executable decision-rights tiers with approval trail
A.6.2.8 (Event logging)Recording of AI system activityAppend-only, hash-chained evidence events with sequence integrity verification
A.8.2 (System documentation)Information available to interested partiesLive proof room, Action Receipts and Evidence Pack with declared evidence levels

13. Framework crosswalk: SIG, CAIQ and NIST

FrameworkReferenceTopicMapped by
SIGAI module: governanceInventory and ownership of AI agentsAgent passport with accountable human and registered use cases
SIGAI module: operationsMonitoring and exception handling for automated agentsRun ledger, spend caps, exception events and operator escalation receipts
CAIQAIS (Application and Interface Security)Audit trail of application actionsAction Receipts with authority status and tamper-evident chain
CAIQGRC (Governance, Risk and Compliance)Documented risk boundaries for automated systemsProhibited actions, forbidden decision tiers and kill-switch evidence
NISTAI RMF: GovernAccountability structures for AI systemsAccountable human on every internal agent; approvals resolved by named operators
NISTAI RMF: MeasureTracking of AI system behaviour over timeEvidence Coverage Score with component breakdown and status decay
NISTAI agent guidance: least privilegeConstraining agent capabilities to declared scopeTool allowlists, decision-rights tiers and out-of-scope receipt flagging

14. Limitations and verification

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.

Use your browser's Print function (Ctrl+P) and choose "Save as PDF" to export this pack. Back to Proofroom · Open live proof room