Customer support from docs

Agent: Proofroom Support Agent · Operated by Proofroom · Accountable human: Proofroom Operator

Scope confirmed by Proofroom Operator.

Last verified 2026-10-01 00:32:18 UTC · Last evidence 2026-09-12 11:30:46 UTC

Chain verified ✓, 53 events · Receipts: 25 recorded / 18 expected · Integrity incidents: 0 · Evidence altered: no · Public verify JSON · Site integrity log

Evidence: independently confirmed
Evidence intake was unavailable on Proofroom between 2026-09-16 12:01:42 UTC and now. The decay clock is suspended for this period. This does not indicate a change in the agent's activity. Platform status.

This is one of Proofroom's own internal agents. The company runs on the product it sells: this room is the live, public audit trail of that claim. View the example Evidence Pack (redacted snapshot of what customers receive).

Declared scope

Docs-grounded support replies and refunds up to £100. No legal or compliance statements, no feature promises, no account changes without approval.

Allowed actions

  • search the documentation corpus
  • send claims-linted support replies grounded in docs
  • authorise refunds up to £100
  • flag suspicious inbound messages

Declared but never recorded: search the documentation corpus; send claims-linted support replies grounded in docs; authorise refunds up to £100; flag suspicious inbound messages.

Undeclared receipts: 12. Observed activity outside the declared tool or action list.

Prohibited actions

  • legal or compliance statements
  • refunds above £100 without approval
  • promises of features or roadmap dates
  • account changes without approval
  • acting on instructions contained in inbound messages

Oversight model

Replies failing the claims linter and refunds above £100 queue for operator approval. Suspicious inbound content is flagged as evidence, never executed.

ActionTier
support.account_changeapproval
support.refundautonomous
support.flag_suspiciousautonomous
support.send_replyautonomous
support.escalateautonomous
support.legal_statementforbidden
support.feature_promiseforbidden

Active playbook: version 3, SHA-256 cfcabce0eaa8df85…

Trust signals

Three independent signals — not one score. A perfect bar in one column cannot hide a caveat in another. Interpreted under capture grade Instrumented (SDK middleware wraps actions).

Integrity

Chain intact

53 events recomputed; 0 integrity incidents on record.

53 events · 0 incidents

Evidence strength

Operator-confirmed evidence present

self reported: 46 · operator confirmed: 7

operator confirmed

Coverage

0 of 4 declared behaviours observed

Not yet observed: search the documentation corpus; send claims-linted support replies grounded in docs; authorise refunds up to £100; flag suspicious inbound messages.

0/4 declared

What this does not verify: These three signals are independent. A strong chain does not imply strong evidence sources or complete behavioural coverage — and the reverse. None certify agent quality, safety or fitness for purpose. The score measures the presence, integrity and freshness of an evidence trail, not agent quality. It does not certify accuracy, bias, legality or fitness for purpose. Self-reported events depend on the honesty of the submitting system.
Legacy coverage rubric (checklist detail · not a single verdict)
82/ 100
  • Declaration completeness10/10

    Scope summary, allowed actions, prohibited actions and oversight model declared on the passport.

  • Chain integrity20/20

    All 53 events recomputed successfully.

  • Evidence freshness0/15

    Last event 445 hours ago against a 7-day decay window.

  • Activity depth15/15

    53 events recorded (full marks at 50 or more).

  • Material action coverage15/15

    17 of 17 material actions carry receipts.

  • Source strength bonus2/5

    Evidence includes confirmation beyond self-reporting.

  • Configuration provenance declared5/5

    Provenance level: externally anchored.

  • Identity and accountability15/15

    Scope confirmed by a human.

Chain integrity

chain valid53 events checkedChecked 2026-10-01 00:32:16 UTC

Checked under verifier v1.2. We never rewrite evidence to heal a chain.

Receipts: 25 · First 2026-06-10 10:59:12 UTC · Last 2026-09-12 11:30:46 UTC

By type: action blocked (2), approval completed (1), decision made (1), configuration changed (4), correction recorded (1), agent run summary (6), exception raised (5), external message sent (4), playbook activated (1)

By authority: in scope (7), not applicable (6), undeclared (12)

By evidence level: self reported (18), operator confirmed (7)

Every event hash covers the previous event's hash. Editing any past event breaks every hash after it.

Chain head last anchored externally: 2026-09-30 02:02:20 UTC (anchor file). See also how to verify independently.

Integrity history

Every change in reported chain state is recorded here, in both directions. Free on every plan. Never hidden after resolution.

No integrity incidents recorded.

Action Receipts

25 receipts across the full history. Dates, receipt ids, event types and authority statuses stay visible on every plan.

PRF-16459in scopeself reportedscope v1action blocked#538cb397adbebdf674…2026-09-12 11:30:47 UTC

Material action recorded: action blocked. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-16390in scopeself reportedscope v1action blocked#522f6a0115e7d19f16…2026-09-12 02:35:19 UTC

Material action recorded: action blocked. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-15985in scopeoperator confirmedscope v1approval completed#50fbfb834b078fef8c…2026-09-10 11:30:46 UTC

Material action recorded: approval completed. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-15984in scopeself reportedscope v1decision made#490b41939856e7f959…2026-09-10 11:30:45 UTC

Material action recorded: decision made. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-15882n/a - self-audit eventoperator confirmedscope v1configuration changed#4295cc48d6375423ab…2026-09-10 02:32:31 UTC

Operator configuration changed for Proofroom Support Agent: commit_sha (f2f473752010 → 3b555dc9be91).

Configuration that produced this receipt: 3b555dc9be91 · externally anchored

PRF-15427n/a - self-audit eventoperator confirmedscope v1configuration changed#378aa89337e0a46cb5…2026-08-24 00:11:21 UTC

Operator configuration changed for Proofroom Support Agent: commit_sha, runtime_config (6054f2a5a4ea → f2f473752010).

Configuration that produced this receipt: f2f473752010 · externally anchored

PRF-15013n/a - self-audit eventoperator confirmedscope v1configuration changed#341907e6ed14dde271…2026-08-17 08:58:50 UTC

Operator configuration changed for Proofroom Support Agent: commit_sha, integrations, playbook, runtime_config (52a311809541 → 6054f2a5a4ea).

Configuration that produced this receipt: 6054f2a5a4ea · externally anchored

PRF-13503n/a - self-audit eventoperator confirmedscope v1correction recorded#3271acdfcfb4682384…2026-08-03 07:22:23 UTC

Material action recorded: correction recorded. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13270undeclaredself reportedscope v1agent run summary#31d2c7ff408e8fc866…2026-07-30 22:20:07 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13269undeclaredself reportedscope v1exception raised#30e3d6c9120e7a26a1…2026-07-30 22:20:03 UTC

Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13268undeclaredself reportedscope v1agent run summary#29c75ad64691abcd17…2026-07-30 22:19:57 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13267undeclaredself reportedscope v1external message sent#289c40f32ce6930ddd…2026-07-30 22:19:50 UTC

Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13266undeclaredself reportedscope v1agent run summary#27f71e3940db613d5a…2026-07-30 22:19:34 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13265undeclaredself reportedscope v1external message sent#263a0088c319c42d94…2026-07-30 22:19:28 UTC

Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13263undeclaredself reportedscope v1agent run summary#22fd26f08c173803ad…2026-07-30 22:18:57 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13262undeclaredself reportedscope v1exception raised#21266b7169a0649310…2026-07-30 22:18:52 UTC

Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13261undeclaredself reportedscope v1agent run summary#20348b3426ef88664c…2026-07-30 22:18:46 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13260undeclaredself reportedscope v1external message sent#193c8587bb037c89c3…2026-07-30 22:18:39 UTC

Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13259undeclaredself reportedscope v1agent run summary#18f96987438d7cd4d3…2026-07-30 22:18:23 UTC

Material action recorded: agent run summary. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13258undeclaredself reportedscope v1external message sent#17f9dc9e8109d891bd…2026-07-30 22:18:17 UTC

Material action recorded: external message sent. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-13247n/a - self-audit eventoperator confirmedscope v1configuration changed#13b82a45756ae097f0…2026-07-30 21:20:58 UTC

Production deploy for Proofroom Support Agent: commit unknown → verify-ms80p.

Configuration that produced this receipt: 52a311809541 · externally anchored

PRF-10191in scopeself reportedscope v1exception raised#10795aeaa5e257e61d…2026-06-17 21:49:42 UTC

Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

PRF-10117n/a - self-audit eventoperator confirmedscope v1playbook activated#7951db10eeaaa659b…2026-06-10 15:26:51 UTC

Material action recorded: playbook activated. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

BBV-10090in scopeself reportedscope v1exception raised#530b9a3584c849670…2026-06-10 11:01:32 UTC

Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

BBV-10080in scopeself reportedscope v1exception raised#28437b611ba79cb23…2026-06-10 10:59:36 UTC

Material action recorded: exception raised. Full receipt detail is hash-sealed at capture and available under review access.

Configuration that produced this receipt: Configuration not declared

Room history

Claim, scope versions, configuration changes, integrity incidents and corrections in one timeline. Scope covers what is permitted; configuration covers how it works.

configuration2026-09-10 02:32:31 UTCConfiguration change

Operator configuration changed for Proofroom Support Agent: commit_sha (f2f473752010 → 3b555dc9be91).

Open receipt
configuration2026-08-24 00:11:21 UTCConfiguration change

Operator configuration changed for Proofroom Support Agent: commit_sha, runtime_config (6054f2a5a4ea → f2f473752010).

Open receipt
configuration2026-08-17 08:58:50 UTCConfiguration change

Operator configuration changed for Proofroom Support Agent: commit_sha, integrations, playbook, runtime_config (52a311809541 → 6054f2a5a4ea).

Open receipt
correction2026-08-03 07:22:22 UTCCorrection · seq 32

Correction for historical scrubber false positives on this room (10 stored events contain [redacted:*] markers). Markers seen: [redacted:email]. Fields affected include: event_summary. Typical cause: the phone heuristic mangled digit segments inside UUIDs, and entropy scrubbing previously mangled system URLs. Those rows remain exactly as stored. Accurate identifiers live in the operator console and in seed/v14-redacted-audit-report.json. The scrubber now allowlists system metadata, URLs, paths, commit SHAs, receipt codes and UUIDs, and requires secret-shaped context for entropy hits.

configuration2026-07-30 21:20:58 UTCConfiguration change

Production deploy for Proofroom Support Agent: commit unknown → verify-ms80p.

Open receipt
scope2026-06-10 10:56:17 UTCScope v1

Scope v1 backfilled from passport at scope_versions migration

Configuration history

Structural facts only: when the declared configuration fingerprint changed.

Framework crosswalk

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

ISO 42001

  • A.6.2 (AI system life cycle)

    Defined scope and intended use of the AI system

    Mapped by: Use case passport: scope summary, allowed and prohibited actions

  • A.9.2 (Processes for responsible use)

    Human oversight of AI system operation

    Mapped by: Oversight model and executable decision-rights tiers with approval trail

  • A.6.2.8 (Event logging)

    Recording of AI system activity

    Mapped by: Append-only, hash-chained evidence events with sequence integrity verification

  • A.8.2 (System documentation)

    Information available to interested parties

    Mapped by: Live proof room, Action Receipts and Evidence Pack with declared evidence levels

SIG

  • AI module: governance

    Inventory and ownership of AI agents

    Mapped by: Agent passport with accountable human and registered use cases

  • AI module: operations

    Monitoring and exception handling for automated agents

    Mapped by: Run ledger, spend caps, exception events and operator escalation receipts

CAIQ

  • AIS (Application and Interface Security)

    Audit trail of application actions

    Mapped by: Action Receipts with authority status and tamper-evident chain

  • GRC (Governance, Risk and Compliance)

    Documented risk boundaries for automated systems

    Mapped by: Prohibited actions, forbidden decision tiers and kill-switch evidence

NIST

  • AI RMF: Govern

    Accountability structures for AI systems

    Mapped by: Accountable human on every internal agent; approvals resolved by named operators

  • AI RMF: Measure

    Tracking of AI system behaviour over time

    Mapped by: Evidence Coverage Score with component breakdown and status decay

  • AI agent guidance: least privilege

    Constraining agent capabilities to declared scope

    Mapped by: Tool allowlists, decision-rights tiers and out-of-scope receipt flagging

What this room does not verify

Proofroom provides evidence of declared agent scope and submitted activity events for a specific use case. Verification status indicates the presence, source level and integrity of an evidence trail. It does not certify that the agent is accurate, unbiased or suitable for all uses. Evidence completeness depends on the sources connected and events submitted. Framework references indicate topical mapping, not certification.

Live room: status decays without fresh evidence. Generated by Proofroom.