Scope and drift

Scope in Proofroom is a human commitment, not a fact nobody can prove complete. An operator confirms what an agent is permitted to do. Observation may propose changes; only a human may amend.

Claimed scope

At claim time the operator confirms allowed actions, prohibited actions and tools. That confirmation becomes scope version 1. Accurate copy is "claimed" and "scope confirmed by <name or role>", never verified.

Amendments are dated and versioned

Editing scope in the console produces a draft with a diff (added, removed, unchanged). Confirming with Confirm scope and amend increments the version, appends a receipted scope_amended evidence event, and updates the room history. Agents, including Proofroom's own internal agents, cannot amend scope.

Authority is judged against the scope in force at the time

Each Action Receipt is stamped with the scope_version current when it was minted. Authority status (in_scope, out_of_scope, undeclared, not_applicable) is never re-graded when scope later changes. A receipt that was in scope under v1 remains shown as in scope under v1.

Two drift signals

  1. Observed but not declared — tools or action types recorded with authority undeclared, with counts and last-seen dates.
  2. Declared but never recorded — allowed actions with no receipt signal, with time since claiming.

Both appear on the console Scope review panel and on public rooms at Tier 1. From the panel an operator can start an amendment draft prefilled with proposed additions or removals. Confirm remains human-only. Never auto-apply.

Notify-and-amend

When a receipt is minted with authority undeclared or out_of_scope, the owner is alerted on Telegram (if bound) and in the approvals inbox. The alert names the agent, use case, action and why it was flagged, and offers one-tap paths: add to allowed scope, mark prohibited, leave as is, or open the receipt. The first two open a scope amendment draft; Confirm scope and amend is still required. Leave as is records an evidence event that the owner saw the alert and chose no change. Batches of the same undeclared tool within an hour share one alert.

This action already happened and was recorded. Choose what its scope should be. Nothing is blocked or delayed by Proofroom. A prohibited match is shown more prominently than a merely undeclared action, because the agent did something its accountable human said it must not.

Observe vs require_ack

The default is that Proofroom observes and notifies, never blocks. Notify-and- amend is the evidence-side answer to undeclared or out-of-scope activity after the fact. If a customer needs an action to wait for confirmation before proceeding, that is opt-in require_ack on a designated critical action: the customer's agent (not Proofroom) decides what to do if acknowledgement is not given, and the customer accepts that those actions depend on our availability. See Getting started and MCP.

Configuration vs scope

Configuration provenance covers how the agent works changing (fingerprints, components). Scope versions cover what it is permitted to do changing. An evolving agent typically shows both; the room history timeline tells that story together with claims, integrity incidents and corrections.

Honest limitation

A scope can never be proven complete. Undeclared activity and never-recorded declarations are visible gaps, not theatre that the commitment was exhaustive.