Weekly security posture sweep
Agent: Proofroom Security Agent · Operated by Proofroom · Accountable human: Proofroom Operator
Scope confirmed by Proofroom Operator.
Last verified 2026-10-01 01:05:44 UTC · Last evidence 2026-09-28 08:01:26 UTC
Chain verified ✓, 57 events · Receipts: 27 recorded / 25 expected · Integrity incidents: 0 · Evidence altered: no · Public verify JSON · Site integrity log
This is one of Proofroom's own internal agents. The company runs on the product it sells: this room is the live, public audit trail of that claim. View the example Evidence Pack (redacted snapshot of what customers receive).
Declared scope
Read-only posture checks and operator reports. Dependency upgrades and key rotations are proposed for approval; disabling logging or modifying RLS is forbidden.
Allowed actions
- run read-only posture checks
- produce severity-ranked posture reports
- propose remediations for operator approval
Declared but never recorded: run read-only posture checks; produce severity-ranked posture reports; propose remediations for operator approval.
Undeclared receipts: 2. Observed activity outside the declared tool or action list.
Prohibited actions
- disable or modify logging
- modify row level security
- execute remediations without approval
- suppress findings
Oversight model
The sweep and report are autonomous and receipted. Every remediation (dependency upgrades, key rotations) is tier-2 operator approval.
| Action | Tier |
|---|---|
| security.rotate_key | approval |
| security.dependency_upgrade | approval |
| security.send_report | autonomous |
| security.disable_logging | forbidden |
| security.modify_rls | forbidden |
Active playbook: version 3, SHA-256 f005f10e7a104f2f…
Trust signals
Three independent signals — not one score. A perfect bar in one column cannot hide a caveat in another. Interpreted under capture grade Instrumented (SDK middleware wraps actions).
Integrity
Chain intact
57 events recomputed; 0 integrity incidents on record.
57 events · 0 incidents
Evidence strength
Operator-confirmed evidence present
self reported: 50 · operator confirmed: 7
operator confirmed
Coverage
0 of 3 declared behaviours observed
Not yet observed: run read-only posture checks; produce severity-ranked posture reports; propose remediations for operator approval.
0/3 declared
Legacy coverage rubric (checklist detail · not a single verdict)
- Declaration completeness10/10
Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
- Chain integrity20/20
All 57 events recomputed successfully.
- Evidence freshness15/15
Last event 65 hours ago against a 10-day decay window.
- Activity depth15/15
57 events recorded (full marks at 50 or more).
- Material action coverage15/15
25 of 25 material actions carry receipts.
- Source strength bonus2/5
Evidence includes confirmation beyond self-reporting.
- Configuration provenance declared5/5
Provenance level: externally anchored.
- Identity and accountability15/15
Scope confirmed by a human.
Chain integrity
Checked under verifier v1.2. We never rewrite evidence to heal a chain.
Receipts: 27 · First 2026-06-10 11:07:01 UTC · Last 2026-09-28 08:01:26 UTC
By type: external message sent (19), configuration changed (6), agent run summary (1), playbook activated (1)
By authority: in scope (18), not applicable (7), undeclared (2)
By evidence level: self reported (20), operator confirmed (7)
Every event hash covers the previous event's hash. Editing any past event breaks every hash after it.
Chain head last anchored externally: 2026-09-30 02:02:20 UTC (anchor file). See also how to verify independently.
Integrity history
Every change in reported chain state is recorded here, in both directions. Free on every plan. Never hidden after resolution.
No integrity incidents recorded.
Action Receipts
27 receipts across the full history. Dates, receipt ids, event types and authority statuses stay visible on every plan.
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Operator configuration changed for Proofroom Security Agent: commit_sha (d18595a36bf4 → 5392ec2289a8).
Configuration that produced this receipt: 5392ec2289a8 · externally anchored
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Operator configuration changed for Proofroom Security Agent: commit_sha (0c97dcfe3027 → d18595a36bf4).
Configuration that produced this receipt: d18595a36bf4 · externally anchored
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Operator configuration changed for Proofroom Security Agent: commit_sha (26923688991e → 0c97dcfe3027).
Configuration that produced this receipt: 0c97dcfe3027 · externally anchored
Operator configuration changed for Proofroom Security Agent: commit_sha, runtime_config (41b95bb701a7 → 26923688991e).
Configuration that produced this receipt: 26923688991e · externally anchored
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Operator configuration changed for Proofroom Security Agent: commit_sha, integrations, playbook, runtime_config (56e0e300e7f8 → 41b95bb701a7).
Configuration that produced this receipt: 41b95bb701a7 · externally anchored
Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Production deploy for Proofroom Security Agent: commit unknown → verify-ms80p.
Configuration that produced this receipt: 56e0e300e7f8 · externally anchored
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.
Configuration that produced this receipt: Configuration not declared
Room history
Claim, scope versions, configuration changes, integrity incidents and corrections in one timeline. Scope covers what is permitted; configuration covers how it works.
Operator configuration changed for Proofroom Security Agent: commit_sha (d18595a36bf4 → 5392ec2289a8).
Open receiptOperator configuration changed for Proofroom Security Agent: commit_sha (0c97dcfe3027 → d18595a36bf4).
Open receiptOperator configuration changed for Proofroom Security Agent: commit_sha (26923688991e → 0c97dcfe3027).
Open receiptOperator configuration changed for Proofroom Security Agent: commit_sha, runtime_config (41b95bb701a7 → 26923688991e).
Open receiptOperator configuration changed for Proofroom Security Agent: commit_sha, integrations, playbook, runtime_config (56e0e300e7f8 → 41b95bb701a7).
Open receiptProduction deploy for Proofroom Security Agent: commit unknown → verify-ms80p.
Open receiptScope v1 backfilled from passport at scope_versions migration
Configuration history
Structural facts only: when the declared configuration fingerprint changed.
Operator configuration changed for Proofroom Security Agent: commit_sha (d18595a36bf4 → 5392ec2289a8).
Components changed: commit_sha · d18595a36bf4 → 5392ec2289a8
Operator configuration changed for Proofroom Security Agent: commit_sha (0c97dcfe3027 → d18595a36bf4).
Components changed: commit_sha · 0c97dcfe3027 → d18595a36bf4
Operator configuration changed for Proofroom Security Agent: commit_sha (26923688991e → 0c97dcfe3027).
Components changed: commit_sha · 26923688991e → 0c97dcfe3027
Operator configuration changed for Proofroom Security Agent: commit_sha, runtime_config (41b95bb701a7 → 26923688991e).
Components changed: commit_sha, runtime_config · 41b95bb701a7 → 26923688991e
Operator configuration changed for Proofroom Security Agent: commit_sha, integrations, playbook, runtime_config (56e0e300e7f8 → 41b95bb701a7).
Components changed: commit_sha, integrations, playbook, runtime_config · 56e0e300e7f8 → 41b95bb701a7
Production deploy for Proofroom Security Agent: commit unknown → verify-ms80p.
Components changed: commit_sha, decision_rights, integrations, playbook, runtime_config · none → 56e0e300e7f8
Framework crosswalk
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
ISO 42001
- A.6.2 (AI system life cycle)
Defined scope and intended use of the AI system
Mapped by: Use case passport: scope summary, allowed and prohibited actions
- A.9.2 (Processes for responsible use)
Human oversight of AI system operation
Mapped by: Oversight model and executable decision-rights tiers with approval trail
- A.6.2.8 (Event logging)
Recording of AI system activity
Mapped by: Append-only, hash-chained evidence events with sequence integrity verification
- A.8.2 (System documentation)
Information available to interested parties
Mapped by: Live proof room, Action Receipts and Evidence Pack with declared evidence levels
SIG
- AI module: governance
Inventory and ownership of AI agents
Mapped by: Agent passport with accountable human and registered use cases
- AI module: operations
Monitoring and exception handling for automated agents
Mapped by: Run ledger, spend caps, exception events and operator escalation receipts
CAIQ
- AIS (Application and Interface Security)
Audit trail of application actions
Mapped by: Action Receipts with authority status and tamper-evident chain
- GRC (Governance, Risk and Compliance)
Documented risk boundaries for automated systems
Mapped by: Prohibited actions, forbidden decision tiers and kill-switch evidence
NIST
- AI RMF: Govern
Accountability structures for AI systems
Mapped by: Accountable human on every internal agent; approvals resolved by named operators
- AI RMF: Measure
Tracking of AI system behaviour over time
Mapped by: Evidence Coverage Score with component breakdown and status decay
- AI agent guidance: least privilege
Constraining agent capabilities to declared scope
Mapped by: Tool allowlists, decision-rights tiers and out-of-scope receipt flagging
What this room does not verify
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify accuracy, bias, legality or fitness for purpose.
- Self-reported events depend on the honesty of the submitting system.
- Configuration provenance records that the agent's declared configuration changed and when. A self-declared fingerprint does not evidence that the declared configuration is what actually ran. Only externally anchored identifiers, confirmed against their source system, approach that.
- External anchoring proves this chain head existed at the anchor time. It bounds any retrospective alteration to the period since the last anchor. It does not prove that events recorded before an anchor were genuine at the moment they were reported.
- This trail evidences what was recorded. It cannot evidence actions the agent did not report. Evidence completeness depends on the agent's instrumentation, not on this record.
- We never rewrite evidence. Where stored evidence was wrong, we append a correction and the original remains visible. A chain may therefore show a permanent, explained discontinuity. We regard that as more credible than a chain that appears to heal.
- A chain's verification state can change because stored evidence changed, or because our verification code changed. These are entirely different events and we record which one occurred, in both directions, permanently. Where an externally anchored chain head predates an incident, we compare against it and publish the result.
- Evidence sources: internal_agent (54), system (2), webhook (1). Evidence levels: self reported (50), operator confirmed (7). Declared but never recorded: run read-only posture checks; produce severity-ranked posture reports; propose remediations for operator approval.
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.
Live room: status decays without fresh evidence. Generated by Proofroom.