
For high-impact agent actions, Good Proof enforces an externally verifiable, fail-closed gate using a revocable Status Link.
Not a certification. Scope-limited verification. Downstream acceptance depends on counterparty/programme requirements.
Guardrails reduce risk—they do not guarantee prevention.
High-impact actions require a machine-checkable, revocable external gate.
Status Link = control object for reliance.
Treat NEEDS_REFRESH as non-reliance for high-impact execution unless programme policy explicitly routes to review.
| Condition | Returned State | Default Action |
|---|---|---|
| Timeout / network unreachable | NOT_VERIFIED | Block/Escalate |
| TLS / certificate failure | NOT_VERIFIED | Block/Escalate |
| Domain mismatch / redirect | NOT_VERIFIED | Block/Escalate |
| Malformed / unauthenticated response | NOT_VERIFIED | Block/Escalate |
| WITHDRAWN status returned | WITHDRAWN | Block + stop-rely |
| NEEDS_REFRESH status returned | NEEDS_REFRESH | Escalate/Review |
| VALID but out-of-scope / expired | NOT_VERIFIED | Block/Escalate |
Designed for incident response, audit, disputes, and underwriting review.
Compensating control, not replacement.
Mapping only; not a certification claim.
"High-impact [ACTION_CLASS] SHALL require a valid externally-verifiable Status Link (No Stamp → No Ship)."
See /kill-switch for enforcement semantics and /clause-pack for template language.
Defines action classes, runs gate, enforces fail-closed
Issues Stamps, maintains Status Links, propagates refresh/withdrawal
Exceptions/appeals only, scoped human finality

One lane live with fail-closed enforcement, Status Link verification, and Evidence Pack output.
Definition of done: Selected workflow blocks on status ≠ VALID for chosen action class.


Start with one decision class. Prove verification. Then scale.
Scope-limited verification. Not a certification.