Proofroom
Evidence Pack
Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.
Issue-to-merge product delivery
Agent: Proofroom Product Agent · Operated by Proofroom
Generated 2026-07-29 23:18:08 UTC
Status at generation: Action Verified (Degraded) · Chain: chain valid (14 events)
Live proof room
Scan the QR code or open the URL for the current status, receipts and chain. This pack is a snapshot; the live room updates and decays with fresh evidence.
https://proofroom.ai/trust/proofroom-product?from=pack_example-proofroom-product2. Executive summary
This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Issue-to-merge product delivery. At generation time the evidence chain contained 14 hash-chained events, of which 10 material actions carry Action Receipts. The Evidence Coverage Score was 80 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.
3. How to read this pack
Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.
4. Agent passport
| Name | Proofroom Product Agent |
| Description | Internal product agent for Proofroom. Triages GitHub issues, drafts specs, and dispatches approved coding tasks to the Cursor background agent API. It never writes code itself; every step is receipted on its public chain. |
| Stack | Anthropic claude-sonnet-4-5 via Inngest; dispatches to Cursor Background Agents API |
| Internal company agent | Yes |
| Accountable human | Simon Brown |
5. Use case passport
| Use case | Issue-to-merge product delivery |
| Description | The Product Agent receives GitHub issues, triages and labels them, drafts implementation specs, dispatches approved coding tasks to the Cursor API, and merges approved pull requests to staging. Production deploys and schema migrations are forbidden to it. |
| Scope | GitHub issue triage, spec drafting, approved Cursor dispatches and approved staging merges for Proofroom repositories. No production deploys, no schema migrations, no evidence table edits. |
| Allowed actions | triage and label GitHub issues; draft implementation specs; dispatch coding tasks to the Cursor background agent API (with approval); merge pull requests to staging (with approval); trigger staging deploys (with approval) |
| Prohibited actions | deploy to production; run schema migrations without the operator; edit evidence tables; write code directly; merge to production branches |
| Evidence decay window | 7 days |
6. Oversight model and decision rights
Decision-rights tiers enforced by the product runtime. Triage and spec drafting are autonomous; Cursor dispatch, PR merge and staging deploys each require one-tap operator approval; production actions are forbidden.
| Action key | Tier |
|---|---|
| product.merge_pr | approval |
| product.deploy_staging | approval |
| product.dispatch_cursor | approval |
| product.triage_issue | autonomous |
| product.draft_spec | autonomous |
| product.deploy_production | forbidden |
| product.schema_migration | forbidden |
| product.edit_evidence | forbidden |
Active playbook at generation: version 2, SHA-256 9cbb44e5988a0ca25d6bdd186c71bae4d791e62878a12aecef9f39007e04eead
7. Evidence methodology
Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.
8. Evidence Coverage Score
80 / 100
| Component | Points | Detail |
|---|---|---|
| Declaration completeness | 20/20 | Scope summary, allowed actions, prohibited actions and oversight model declared on the passport. |
| Chain integrity | 25/25 | All 14 events recomputed and verified. |
| Evidence freshness | 0/15 | Last event 988 hours ago against a 7-day decay window. |
| Activity depth | 10/15 | 14 events recorded (full marks at 50 or more). |
| Material action coverage | 15/15 | 9 of 9 material actions carry receipts. |
| Source strength bonus | 10/10 | Evidence includes confirmation beyond self-reporting. |
9. Chain integrity verification
| State at generation | chain valid |
| Events recomputed | 14 |
| Verified at | 2026-07-29 23:18:07 UTC |
10. Action Receipts register
| Receipt | Authority | Evidence level | Summary | Date |
|---|---|---|---|---|
| BBV-10013 | in scope | self reported | Material action recorded: decision made. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| BBV-10014 | in scope | self reported | Material action recorded: output generated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| BBV-10076 | in scope | self reported | Material action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| BBV-10085 | in scope | self reported | Material action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| BBV-10086 | n/a - self-audit event | system confirmed | Material action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10115 | n/a - self-audit event | operator confirmed | Material action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10180 | in scope | self reported | Material action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-17 |
| PRF-10181 | n/a - self-audit event | system confirmed | Material action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-17 |
| PRF-10186 | in scope | self reported | Material action recorded: system updated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-17 |
| PRF-10187 | n/a - self-audit event | system confirmed | Material action recorded: system confirmed. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-17 |
11. Evidence log summary
| Total events | 14 |
| By source | system: 4; internal_agent: 10 |
| By evidence level | self reported: 10; system confirmed: 3; operator confirmed: 1 |
12. Framework crosswalk: ISO 42001
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
| Reference | Topic | Mapped by |
|---|---|---|
| A.6.2 (AI system life cycle) | Defined scope and intended use of the AI system | Use case passport: scope summary, allowed and prohibited actions |
| A.9.2 (Processes for responsible use) | Human oversight of AI system operation | Oversight model and executable decision-rights tiers with approval trail |
| A.6.2.8 (Event logging) | Recording of AI system activity | Append-only, hash-chained evidence events with sequence integrity verification |
| A.8.2 (System documentation) | Information available to interested parties | Live proof room, Action Receipts and Evidence Pack with declared evidence levels |
13. Framework crosswalk: SIG, CAIQ and NIST
| Framework | Reference | Topic | Mapped by |
|---|---|---|---|
| SIG | AI module: governance | Inventory and ownership of AI agents | Agent passport with accountable human and registered use cases |
| SIG | AI module: operations | Monitoring and exception handling for automated agents | Run ledger, spend caps, exception events and operator escalation receipts |
| CAIQ | AIS (Application and Interface Security) | Audit trail of application actions | Action Receipts with authority status and tamper-evident chain |
| CAIQ | GRC (Governance, Risk and Compliance) | Documented risk boundaries for automated systems | Prohibited actions, forbidden decision tiers and kill-switch evidence |
| NIST | AI RMF: Govern | Accountability structures for AI systems | Accountable human on every internal agent; approvals resolved by named operators |
| NIST | AI RMF: Measure | Tracking of AI system behaviour over time | Evidence Coverage Score with component breakdown and status decay |
| NIST | AI agent guidance: least privilege | Constraining agent capabilities to declared scope | Tool allowlists, decision-rights tiers and out-of-scope receipt flagging |
14. Limitations and verification
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify safety, accuracy, bias, legality or compliance.
- Self-reported events depend on the honesty of the submitting system.
- This pack is a snapshot generated 2026-07-29 23:18:08 UTC; the live room decays without fresh evidence.
- Verify the current state at the live proof room: https://proofroom.ai/trust/proofroom-product?from=pack_example-proofroom-product (public).
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.