Enforced behavior
An agent’s authority is the delegation proof it presents, not a scope string. Every dispatch pins an explicitdelegationQHash, and the authority is re-validated at the moment of dispatch. A missing,
expired, or revoked permission fails closed.
Every intercepted dispatch persists a signed authority-decision receipt — outcome, reason code,
controller and agent identity, the pinned delegation, and an args digest — so a denial is auditable,
not silent. Receipts are private by default.
Known gaps
Stated plainly, because the group’s value is in the comparison, not in a perfect row.Self-operated, no independent peer witness
Self-operated, no independent peer witness
The run is self-custodied: an ordinary non-admin Pro review tenant drives it with a dedicated
agent. There is no independent peer witness and no second tenant on the public surface.
Committed effect and recovery are the relying party's fields
Committed effect and recovery are the relying party's fields
After a decision, committed effect, retries and recovery belong to the relying party. Proofable
fills what its records carry and marks the rest outside the implementation.
A public mount is narrower than the protocol engine
A public mount is narrower than the protocol engine
The published
@proofable/sdk mount evaluator does not expose a per-call delegation chain, a
per-user rate counter, a second tenant, or an unreachable-gateway path. Those are declared, not
scored.Evidence
The run records are versioned in the publicproofable/docs repository and reachable without an
account:
Each record carries the pinned protocol revision, the exact command, and the trace field. Custody is
SELF; receipts are private and referenced only by their private-visibility qHash. This packet is
bounded implementation evidence, not a matched or certified result.
Run it yourself
The live authority suite runs through the hosted MCP surface:hosted_allow, binding_veto, approval_reachable, approval_unavailable,
revoke_before_dispatch, expiry_before_dispatch, stale_authority, post_dispatch_revoke.