Skip to main content
This page records Proofable’s behavior for the AAIF working-group use case “authorization when the escalation authority is unreachable.” It follows the same three headings the group uses — enforced behavior, known gaps, and separate simulation evidence — so a reviewer can compare implementations without mixing evidence. The behavior below is the deployed protocol, read live. Every claim names what was run, on which revision, and where it stops.

Enforced behavior

An agent’s authority is the delegation proof it presents, not a scope string. Every dispatch pins an explicit delegationQHash, and the authority is re-validated at the moment of dispatch. A missing, expired, or revoked permission fails closed. Every intercepted dispatch persists a signed authority-decision receipt — outcome, reason code, controller and agent identity, the pinned delegation, and an args digest — so a denial is auditable, not silent. Receipts are private by default.

Known gaps

Stated plainly, because the group’s value is in the comparison, not in a perfect row.
The engine has a fail-closed gateway branch, but Proofable has not run the verifier-or-remote-authority-unreachable case live. Proofable’s result for that specific case is unknown until it is run with the group.
The run is self-custodied: an ordinary non-admin Pro review tenant drives it with a dedicated agent. There is no independent peer witness and no second tenant on the public surface.
After a decision, committed effect, retries and recovery belong to the relying party. Proofable fills what its records carry and marks the rest outside the implementation.
The published @proofable/sdk mount evaluator does not expose a per-call delegation chain, a per-user rate counter, a second tenant, or an unreachable-gateway path. Those are declared, not scored.

Evidence

The run records are versioned in the public proofable/docs repository and reachable without an account: Each record carries the pinned protocol revision, the exact command, and the trace field. Custody is SELF; receipts are private and referenced only by their private-visibility qHash. This packet is bounded implementation evidence, not a matched or certified result.

Run it yourself

The live authority suite runs through the hosted MCP surface:
Cases: hosted_allow, binding_veto, approval_reachable, approval_unavailable, revoke_before_dispatch, expiry_before_dispatch, stale_authority, post_dispatch_revoke.
Last modified on October 6, 2026