Platform operations monitoring
Agent: Proofroom Ops Agent · Operated by Proofroom · Accountable human: Simon Brown
Last verified 2026-07-30 02:26:27 UTC · Last evidence 2026-07-30 02:00:18 UTC
This is one of Proofroom's own internal agents. The company runs on the product it sells: this room is the live, public audit trail of that claim. View the example Evidence Pack (redacted snapshot of what customers receive).
Declared scope
Read-only health monitoring of the Proofroom platform plus operator notifications. No customer data content access, no billing actions.
Allowed actions
- run database and platform health checks
- verify evidence chain integrity on sampled use cases
- monitor event volume and agent run failures
- flag anomalies as evidence events
- send digests and alerts to the operator
Prohibited actions
- access customer data content
- billing actions of any kind
- modify evidence tables
- restart agents without approval
- change spend caps without approval
Oversight model
Decision-rights tiers enforced by the product runtime. Monitoring and digests are autonomous; restarting agents and changing caps require operator approval; customer data content and billing are forbidden.
| Action | Tier |
|---|---|
| ops.restart_agent | approval |
| ops.change_caps | approval |
| ops.retry_failed_job | autonomous |
| ops.flag_anomaly | autonomous |
| ops.send_digest | autonomous |
| ops.billing_action | forbidden |
| ops.touch_customer_data | forbidden |
Active playbook: version 3, SHA-256 45272068b2e9db69…
Evidence Coverage Score
- Declaration completeness20/20
Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
- Chain integrity25/25
All 2973 events recomputed and verified.
- Evidence freshness15/15
Last event 0 hours ago against a 2-day decay window.
- Activity depth15/15
1000 events recorded (full marks at 50 or more).
- Material action coverage15/15
200 of 200 material actions carry receipts.
- Source strength bonus4/10
Evidence includes confirmation beyond self-reporting.
Chain integrity
Every event hash covers the previous event's hash. Editing any past event breaks every hash after it.
Recent Action Receipts
Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Framework crosswalk
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
ISO 42001
- A.6.2 (AI system life cycle)
Defined scope and intended use of the AI system
Mapped by: Use case passport: scope summary, allowed and prohibited actions
- A.9.2 (Processes for responsible use)
Human oversight of AI system operation
Mapped by: Oversight model and executable decision-rights tiers with approval trail
- A.6.2.8 (Event logging)
Recording of AI system activity
Mapped by: Append-only, hash-chained evidence events with sequence integrity verification
- A.8.2 (System documentation)
Information available to interested parties
Mapped by: Live proof room, Action Receipts and Evidence Pack with declared evidence levels
SIG
- AI module: governance
Inventory and ownership of AI agents
Mapped by: Agent passport with accountable human and registered use cases
- AI module: operations
Monitoring and exception handling for automated agents
Mapped by: Run ledger, spend caps, exception events and operator escalation receipts
CAIQ
- AIS (Application and Interface Security)
Audit trail of application actions
Mapped by: Action Receipts with authority status and tamper-evident chain
- GRC (Governance, Risk and Compliance)
Documented risk boundaries for automated systems
Mapped by: Prohibited actions, forbidden decision tiers and kill-switch evidence
NIST
- AI RMF: Govern
Accountability structures for AI systems
Mapped by: Accountable human on every internal agent; approvals resolved by named operators
- AI RMF: Measure
Tracking of AI system behaviour over time
Mapped by: Evidence Coverage Score with component breakdown and status decay
- AI agent guidance: least privilege
Constraining agent capabilities to declared scope
Mapped by: Tool allowlists, decision-rights tiers and out-of-scope receipt flagging
What this room does not verify
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify safety, accuracy, bias, legality or compliance.
- Self-reported events depend on the honesty of the submitting system.
- Evidence sources: internal_agent (993), system (7). Evidence levels: self reported (996), operator confirmed (4).
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.
Live room: status decays without fresh evidence. Generated by Proofroom.