
For high-impact agent actions, Good Proof enforces fail-closed execution: if Status Link is not VALID, execution is blocked or escalated.
Not a certification. Scope-limited verification.
Prompt injection and goal hijack remain persistent risk classes.
Status Link verification before high-impact execution.
Evidence Pack for IR, audit, and legal review.
Limits blast radius; does not claim prevention or blanket compliance.

Done means: your selected workflow blocks automatically when status ≠ VALID.

No Stamp → No high-impact execution
Source withdrawal propagates under policy-bounded enforcement
Exportable Evidence Pack for IR/audit/underwriting
Timeout/TLS/mismatch → NOT_VERIFIED → block/escalate
Agent requests a high-impact action
Gate verifies Status Link from official verifier
Policy evaluates status + scope + expiry
Execute only if VALID, otherwise block/escalate
Log Gate Decision + evidence fields
Explicit condition → state → action mapping
| Condition | State | Action |
|---|---|---|
| Verifier timeout | NOT_VERIFIED | Block/Escalate |
| TLS failure | NOT_VERIFIED | Block/Escalate |
| Domain mismatch | NOT_VERIFIED | Block/Escalate |
| Malformed response / signature failure | NOT_VERIFIED | Block/Escalate |
| WITHDRAWN | WITHDRAWN | Block |
| NEEDS_REFRESH | NEEDS_REFRESH | Escalate/Review |
| Out-of-scope / expired | NOT_VERIFIED | Block/Escalate |

In incidents: Status Link = reliance state now. Evidence Pack = decision-time record.
Fields per Gate Decision
Designed for decision-time reconstruction and external review.
Compensating control, not replacement
No. Verification uses references, hashes, and scope identifiers. Sensitive payloads excluded by default.
Fail-closed. Any verification failure returns NOT_VERIFIED → block or escalate.
No. Scope-limited verification within contract-defined action classes.
Buyer-controlled. Retention periods defined in Order Form. Minimal disclosure by default.
"Reliance on agent-executed high-impact actions is contractually conditioned on VALID status at decision time."
Verification path excludes raw PII/PHI payloads by default.
"High-impact [ACTION CLASS] SHALL require a valid externally-verifiable Status Link (No Stamp → No Ship)."

One lane live with fail-closed gating, Status Link verification, and Evidence Pack output.
3 action classes, boundaries, success criteria
Verification checks, logging, Status Link endpoint wiring
Timeout/TLS/mismatch drills + tabletop incident
Metrics, control gaps, rollout plan
Designed to limit blast radius, not eliminate compromise.


Definition of done: your workflow blocks on status ≠ VALID.
Each month without execution gating extends unbounded reliance risk during compromise.
Scope-limited verification. Not a certification.