Workflow Bible
Public-safe operating rules for scoping, verification, shipping, journaling, and false-positive response.
PUBLISHEDA method description, not a guarantee of outcome quality.
EVIDENCE-GATED / BOUNDED / INSPECTABLE
A practical way to keep AI proposals from becoming unexamined facts, saved state, delegated instructions, or external actions.
THE GRAMMAR
Models can propose quickly. The control question is what those proposals are allowed to become. This approach assigns that decision to deterministic policy, narrow executors, independent checks, and receipts.
01 / OBSERVE
Identify the sourceRecord what was seen, where it came from, and what is merely generated or unverified.
02 / AUTHORIZE
Bind the boundaryApply scope, capability, data, target, and human-approval policy before action.
03 / VERIFY
Challenge the claimRun a clean control, meaningful refusal, or independent check before promotion.
04 / RECEIPT
Leave a trailPreserve evidence, verdict, execution state, outcome, uncertainty, and the next gate.
CURRENT PUBLIC REFERENCES
Public-safe operating rules for scoping, verification, shipping, journaling, and false-positive response.
PUBLISHEDA method description, not a guarantee of outcome quality.
Plug-in deny-by-default tool-call gate: policy packs, velocity/blast limits, hash-chained receipts, purple stress suite, optional FastMCP on_call_tool middleware.
Library control plane for tool execution — not a full SOC or OAuth server.
Client-readable synthetic review format built from two operator-owned local fixtures and their retained receipts.
PUBLISHEDSynthetic demonstration only; not a client, production, conformance, certification, or independent-validation result.
Controlled local reference mechanics for resource, audience, scope, session, and token-handling boundaries.
PUBLISHEDNot MCP/OAuth conformance, a production audit, or an external-server assessment.
Local native-middleware fixture with a synthetic signed-agent contract and reproduction receipt.
PUBLISHEDNot FastMCP-wide security, an identity standard, or production readiness.
Six local checks around a persisted digest-only replay record and fail-closed malformed state.
PUBLISHEDNot crash, power-loss, distributed, or production replay safety.
Systems report on a mediated control plane: mcp-assure, browser/desktop leashes, assured host, agent-plane FREEZE lockdown.
PUBLISHEDWorking paper — not peer-reviewed; not enterprise SOC or unlimited CUA claims. PDF + open repos.
CLAIMS NAVIGATOR
A public claim should make its evidence, limit, and next missing proof easy to find. A lead stays a lead until it clears that bar.
Runtime tool-call gate — not a hosted code vuln scanner. Next proof: production host routing all tool calls through the gate. Not a full SOC claim.
Inspect the public source, evidence snapshot, and local test command.
Next proof: trusted conformance evidence or a separately authorized owned-system pilot.
Inspect the six-scenario contract and local reproduction path.
Next proof: independent/blinded evaluation and durable recovery boundaries.
Inspect the direct six-test reference and sanitized receipt.
Next proof: separately scoped crash, power-loss, and distributed-storage evaluation.
ENGAGEMENT SHAPE
The first useful engagement is an authorization-control assessment and reproducible test-fixture handoff, not a broad audit claim.
Agree the owned or explicitly authorized surface, the decision-maker, the safe test method, and the out-of-bounds area.
Build the smallest useful clean control, denial path, and receipt a team can run again.
Deliver the reproduction path, limitations, and prioritized next-control plan. Production access, credentials, scanning, deployment, and public claims remain separate approvals.