Skip to content
Discussion options

You must be logged in to vote

Both, and they stop at different places.

Occurrence: every call, decision and outcome is a record in the hash chain, and with attestation on each one also gets a signed envelope. An offline auditor can recompute that the call happened at that position in the sequence and that nothing was edited afterwards.

Authority: on the MCP proxy, every signed envelope carries a SHA-256 over the operator's allow/deny perimeter and the policy file in force (encoder_binary_identity). An auditor holding the policy file can confirm which policy governed the call, and any policy change between two batches shows up as a different hash. The verdict is bound to the risk score and thresholds the record commits…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by vaaraio
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants