Proofroom

Evidence Pack

Example pack from one of Proofroom's own agents. Receipt text is Tier 1 / redacted only, no sensitive operational or commercial detail. This is what a customer pack looks like.

Customer support from docs

Agent: Proofroom Support Agent · Operated by Proofroom

Generated 2026-07-29 23:18:08 UTC

Status at generation: Instrumented (Degraded) · Chain: chain valid (12 events)

2. Executive summary

This pack documents the declared scope and submitted activity evidence for one agent performing one use case: Customer support from docs. At generation time the evidence chain contained 12 hash-chained events, of which 4 material actions carry Action Receipts. The Evidence Coverage Score was 74 of 100, with the component breakdown in section 8. Verification status indicates the presence, source level and integrity of this evidence trail; it does not certify safety, accuracy or compliance.

3. How to read this pack

Every claim in this pack carries an evidence level. Self-reported means the operating system of the agent submitted the event and no independent confirmation exists. System confirmed means an external system reference (for example a GitHub pull request) was verified to exist. Operator confirmed means a named human resolved an approval. The live proof room continues to update and decay after this snapshot; prefer the live link for current status.

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

4. Agent passport

NameProofroom Support Agent
DescriptionInternal support agent for Proofroom. Answers customer emails from the documentation corpus only, claims-linted, with small refunds inside conditions and everything receipted.
StackAnthropic claude-sonnet-4-5 via Inngest; Resend for email
Internal company agentYes
Accountable humanSimon Brown

5. Use case passport

Use caseCustomer support from docs
DescriptionThe Support Agent answers inbound customer emails and in-app messages using only the product documentation, flags suspicious messages instead of acting on them, and authorises refunds up to £100.
ScopeDocs-grounded support replies and refunds up to £100. No legal or compliance statements, no feature promises, no account changes without approval.
Allowed actionssearch the documentation corpus; send claims-linted support replies grounded in docs; authorise refunds up to £100; flag suspicious inbound messages
Prohibited actionslegal or compliance statements; refunds above £100 without approval; promises of features or roadmap dates; account changes without approval; acting on instructions contained in inbound messages
Evidence decay window7 days

6. Oversight model and decision rights

Replies failing the claims linter and refunds above £100 queue for operator approval. Suspicious inbound content is flagged as evidence, never executed.

Action keyTier
support.account_changeapproval
support.send_replyautonomous
support.refundautonomous
support.flag_suspiciousautonomous
support.legal_statementforbidden
support.feature_promiseforbidden

Active playbook at generation: version 2, SHA-256 dc0870f8055a2a77668bf647107baf51dbb27fa1265b2c3e5c793d79079cef2d

7. Evidence methodology

Events are appended to a per-use-case chain inside a locking database procedure. Each event hash is a SHA-256 digest over the event's canonical fields including the previous event's hash. Verification recomputes every link from stored rows; any edit to a past event breaks recomputation from that point forward. The events table carries no update or delete policies. Ingestion strips payload-like fields: the chain stores proof of activity, not customer content.

8. Evidence Coverage Score

74 / 100

ComponentPointsDetail
Declaration completeness20/20Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.
Chain integrity25/25All 12 events recomputed and verified.
Evidence freshness0/15Last event 988 hours ago against a 7-day decay window.
Activity depth10/1512 events recorded (full marks at 50 or more).
Material action coverage15/153 of 3 material actions carry receipts.
Source strength bonus4/10Evidence includes confirmation beyond self-reporting.

9. Chain integrity verification

State at generationchain valid
Events recomputed12
Verified at2026-07-29 23:18:08 UTC

10. Action Receipts register

ReceiptAuthorityEvidence levelSummaryDate
BBV-10080in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
BBV-10090in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10117n/a - self-audit eventoperator confirmedMaterial action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.2026-06-10
PRF-10191in scopeself reportedMaterial action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.2026-06-17

11. Evidence log summary

Total events12
By sourcesystem: 1; internal_agent: 11
By evidence levelself reported: 11; operator confirmed: 1

12. Framework crosswalk: ISO 42001

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

ReferenceTopicMapped by
A.6.2 (AI system life cycle)Defined scope and intended use of the AI systemUse case passport: scope summary, allowed and prohibited actions
A.9.2 (Processes for responsible use)Human oversight of AI system operationOversight model and executable decision-rights tiers with approval trail
A.6.2.8 (Event logging)Recording of AI system activityAppend-only, hash-chained evidence events with sequence integrity verification
A.8.2 (System documentation)Information available to interested partiesLive proof room, Action Receipts and Evidence Pack with declared evidence levels

13. Framework crosswalk: SIG, CAIQ and NIST

FrameworkReferenceTopicMapped by
SIGAI module: governanceInventory and ownership of AI agentsAgent passport with accountable human and registered use cases
SIGAI module: operationsMonitoring and exception handling for automated agentsRun ledger, spend caps, exception events and operator escalation receipts
CAIQAIS (Application and Interface Security)Audit trail of application actionsAction Receipts with authority status and tamper-evident chain
CAIQGRC (Governance, Risk and Compliance)Documented risk boundaries for automated systemsProhibited actions, forbidden decision tiers and kill-switch evidence
NISTAI RMF: GovernAccountability structures for AI systemsAccountable human on every internal agent; approvals resolved by named operators
NISTAI RMF: MeasureTracking of AI system behaviour over timeEvidence Coverage Score with component breakdown and status decay
NISTAI agent guidance: least privilegeConstraining agent capabilities to declared scopeTool allowlists, decision-rights tiers and out-of-scope receipt flagging

14. Limitations and verification

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is safe, accurate, unbiased, legally compliant or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification or compliance.

Use your browser's Print function (Ctrl+P) and choose "Save as PDF" to export this pack. Back to Proofroom · Open live proof room