Skip to content

docs(profile): add the field-positioning table - #32

Merged
bdelanghe merged 1 commit into
mainfrom
feat/profile-positioning-table
Jun 28, 2026
Merged

docs(profile): add the field-positioning table#32
bdelanghe merged 1 commit into
mainfrom
feat/profile-positioning-table

Conversation

@bdelanghe

Copy link
Copy Markdown
Contributor

What

Adds a four-foil comparison table to profile/README.md, between Provenance & substrate and Contracts beyond authority — its thematic home, since the table's claim is provenance attests origin, not authority.

Rows: Sigstore · mcp-scan/Invariant · ARM/FIDES · prx. Columns: rung · enforcement point · what it attests/enforces · what it can't.

Why

The shipped agent-safety toolchain has converged on two rungs — identity (Sigstore) and integrity/scanning (mcp-scan, ARM/FIDES). Almost nothing is authority — is this privileged effect attributable to a signed owner and permitted for it. That emptiness is the positioning; the table makes it legible to a skimmer with real named tools instead of an abstraction.

Honesty calibration

  • prx's "what it can't" names the integrity axis as a gap on purpose — "composes with mcp-scan, doesn't replace it." Claims a different rung, not a better scanner.
  • Inter-contract enforcement and the prx-vs-guest-room enforcement delta live in the footnote, graded Aspirational/Partial — not in the cells.

Checklist

  • Independent PR — single section, branched clean off main
  • No generated content touchedregistry-graph block untouched; knowledge-check path not triggered
  • Signed commit — verified by GitHub (repo ruleset requires it)

🤖 Generated with Claude Code

…ung)

A four-foil comparison — Sigstore, mcp-scan/Invariant, ARM/FIDES, prx —
across {rung, enforcement point, attests/enforces, what it can't}. Makes
the positioning claim legible to a skimmer with real named tools instead
of an abstraction: the shipped agent-safety toolchain converged on
identity + integrity/scanning; the authority rung (and inter-contract
enforcement above it) is sparsely tooled and where this org works.

Honesty: prx's "what it can't" names the integrity axis as a gap on
purpose (composes with mcp-scan, doesn't replace it); inter-contract
enforcement and the prx-vs-guest-room delta live in the footnote graded
Aspirational/Partial, not in the cells. No generated block touched.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@bdelanghe
bdelanghe merged commit 9dc21cd into main Jun 28, 2026
3 of 4 checks passed
@bdelanghe
bdelanghe deleted the feat/profile-positioning-table branch June 28, 2026 23:49
@github-project-automation github-project-automation Bot moved this from Todo to Done in Front Desk Jun 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

1 participant