Scope and drift
Scope in Proofroom is a human commitment, not a fact nobody can prove complete. An operator confirms what an agent is permitted to do. Observation may propose changes; only a human may amend.
Claimed scope
At claim time the operator confirms allowed actions, prohibited actions and tools. That confirmation becomes scope version 1. Accurate copy is "claimed" and "scope confirmed by <name or role>", never verified.
Amendments are dated and versioned
Editing scope in the console produces a draft with a diff (added, removed,
unchanged). Confirming with Confirm scope and amend increments the
version, appends a receipted scope_amended evidence event, and updates the
room history. Agents, including Proofroom's own internal agents, cannot amend
scope.
Authority is judged against the scope in force at the time
Each Action Receipt is stamped with the scope_version current when it was
minted. Authority status (in_scope, out_of_scope, undeclared,
not_applicable) is never re-graded when scope later changes. A receipt that
was in scope under v1 remains shown as in scope under v1.
Two drift signals
- Observed but not declared — tools or action types recorded with
authority
undeclared, with counts and last-seen dates. - Declared but never recorded — allowed actions with no receipt signal, with time since claiming.
Both appear on the console Scope review panel and on public rooms at Tier 1. From the panel an operator can start an amendment draft prefilled with proposed additions or removals. Confirm remains human-only. Never auto-apply.
Notify-and-amend
When a receipt is minted with authority undeclared or out_of_scope, the
owner is alerted on Telegram (if bound) and in the approvals inbox. The alert
names the agent, use case, action and why it was flagged, and offers one-tap
paths: add to allowed scope, mark prohibited, leave as is, or open the receipt.
The first two open a scope amendment draft; Confirm scope and amend is
still required. Leave as is records an evidence event that the owner saw the
alert and chose no change. Batches of the same undeclared tool within an hour
share one alert.
This action already happened and was recorded. Choose what its scope should be. Nothing is blocked or delayed by Proofroom. A prohibited match is shown more prominently than a merely undeclared action, because the agent did something its accountable human said it must not.
Observe vs require_ack
The default is that Proofroom observes and notifies, never blocks. Notify-and-
amend is the evidence-side answer to undeclared or out-of-scope activity after
the fact. If a customer needs an action to wait for confirmation before
proceeding, that is opt-in require_ack on a designated critical action: the
customer's agent (not Proofroom) decides what to do if acknowledgement is not
given, and the customer accepts that those actions depend on our availability.
See Getting started
and MCP.
Configuration vs scope
Configuration provenance covers how the agent works changing (fingerprints, components). Scope versions cover what it is permitted to do changing. An evolving agent typically shows both; the room history timeline tells that story together with claims, integrity incidents and corrections.
Honest limitation
A scope can never be proven complete. Undeclared activity and never-recorded declarations are visible gaps, not theatre that the commitment was exhaustive.