Proofroom
Evidence Pack
Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.
Weekly security posture sweep
Agent: Proofroom Security Agent · Operated by Proofroom
Generated 2026-07-29 23:18:08 UTC
Status at generation: Evidence Verified · Chain: chain valid (22 events)
Live proof room
Scan the QR code or open the URL for the current status, receipts and chain. This pack is a snapshot; the live room updates and decays with fresh evidence.
https://proofroom.ai/trust/proofroom-security?from=pack_example-proofroom-security2. Executive summary
This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Weekly security posture sweep. At generation time the evidence chain contained 22 hash-chained events, of which 11 material actions carry Action Receipts. The Evidence Coverage Score was 91 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.
3. How to read this pack
Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.
4. Agent passport
| Name | Proofroom Security Agent |
| Description | Internal security agent for Proofroom. Runs the Monday posture ritual (RLS status, key age, queue hygiene, failure scan) and reports honestly, including what it cannot check. Remediation is proposed, never executed autonomously. |
| Stack | Anthropic claude-sonnet-4-5 via Inngest |
| Internal company agent | Yes |
| Accountable human | Simon Brown |
5. Use case passport
| Use case | Weekly security posture sweep |
| Description | The Security Agent runs a weekly read-only posture sweep across RLS status, API key age, approval queue hygiene and run failures, and reports findings by severity with proposed remediations. |
| Scope | Read-only posture checks and operator reports. Dependency upgrades and key rotations are proposed for approval; disabling logging or modifying RLS is forbidden. |
| Allowed actions | run read-only posture checks; produce severity-ranked posture reports; propose remediations for operator approval |
| Prohibited actions | disable or modify logging; modify row level security; execute remediations without approval; suppress findings |
| Evidence decay window | 10 days |
6. Oversight model and decision rights
The sweep and report are autonomous and receipted. Every remediation (dependency upgrades, key rotations) is tier-2 operator approval.
| Action key | Tier |
|---|---|
| security.rotate_key | approval |
| security.dependency_upgrade | approval |
| security.send_report | autonomous |
| security.disable_logging | forbidden |
| security.modify_rls | forbidden |
Active playbook at generation: version 2, SHA-256 c5f1c6dd4964ad2c2afee43b3c1bf25b7c4d30131f0fc60b53db3db2c71a554a
7. Evidence methodology
Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.
8. Evidence Coverage Score
91 / 100
| Component | Points | Detail |
|---|---|---|
| Declaration completeness | 20/20 | Scope summary, allowed actions, prohibited actions and oversight model declared on the passport. |
| Chain integrity | 25/25 | All 22 events recomputed and verified. |
| Evidence freshness | 15/15 | Last event 2 hours ago against a 10-day decay window. |
| Activity depth | 12/15 | 22 events recorded (full marks at 50 or more). |
| Material action coverage | 15/15 | 10 of 10 material actions carry receipts. |
| Source strength bonus | 4/10 | Evidence includes confirmation beyond self-reporting. |
9. Chain integrity verification
| State at generation | chain valid |
| Events recomputed | 22 |
| Verified at | 2026-07-29 23:18:08 UTC |
10. Action Receipts register
| Receipt | Authority | Evidence level | Summary | Date |
|---|---|---|---|---|
| BBV-10094 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10116 | n/a - self-audit event | operator confirmed | Material action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-10 |
| PRF-10739 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-22 |
| PRF-11081 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-28 |
| PRF-11234 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-06-29 |
| PRF-11479 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-03 |
| PRF-11932 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-06 |
| PRF-12302 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-13 |
| PRF-12671 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-20 |
| PRF-13043 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-27 |
| PRF-13178 | in scope | self reported | Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access. | 2026-07-29 |
11. Evidence log summary
| Total events | 22 |
| By source | system: 1; internal_agent: 21 |
| By evidence level | self reported: 21; operator confirmed: 1 |
12. Framework crosswalk: ISO 42001
Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.
| Reference | Topic | Mapped by |
|---|---|---|
| A.6.2 (AI system life cycle) | Defined scope and intended use of the AI system | Use case passport: scope summary, allowed and prohibited actions |
| A.9.2 (Processes for responsible use) | Human oversight of AI system operation | Oversight model and executable decision-rights tiers with approval trail |
| A.6.2.8 (Event logging) | Recording of AI system activity | Append-only, hash-chained evidence events with sequence integrity verification |
| A.8.2 (System documentation) | Information available to interested parties | Live proof room, Action Receipts and Evidence Pack with declared evidence levels |
13. Framework crosswalk: SIG, CAIQ and NIST
| Framework | Reference | Topic | Mapped by |
|---|---|---|---|
| SIG | AI module: governance | Inventory and ownership of AI agents | Agent passport with accountable human and registered use cases |
| SIG | AI module: operations | Monitoring and exception handling for automated agents | Run ledger, spend caps, exception events and operator escalation receipts |
| CAIQ | AIS (Application and Interface Security) | Audit trail of application actions | Action Receipts with authority status and tamper-evident chain |
| CAIQ | GRC (Governance, Risk and Compliance) | Documented risk boundaries for automated systems | Prohibited actions, forbidden decision tiers and kill-switch evidence |
| NIST | AI RMF: Govern | Accountability structures for AI systems | Accountable human on every internal agent; approvals resolved by named operators |
| NIST | AI RMF: Measure | Tracking of AI system behaviour over time | Evidence Coverage Score with component breakdown and status decay |
| NIST | AI agent guidance: least privilege | Constraining agent capabilities to declared scope | Tool allowlists, decision-rights tiers and out-of-scope receipt flagging |
14. Limitations and verification
- The score measures the presence, integrity and freshness of an evidence trail, not agent quality.
- It does not certify safety, accuracy, bias, legality or compliance.
- Self-reported events depend on the honesty of the submitting system.
- This pack is a snapshot generated 2026-07-29 23:18:08 UTC; the live room decays without fresh evidence.
- Verify the current state at the live proof room: https://proofroom.ai/trust/proofroom-security?from=pack_example-proofroom-security (public).
Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.