What does the hash chain let an offline auditor recompute - the call, or the decision? #795
|
Hi — found vaara while mapping how agent actions get made accountable, and "a hash-chained record an auditor verifies offline, without trusting you" is close to a seam I keep circling. A concrete question rather than a hello. When the auditor verifies offline, what does the chain let them recompute — and against what pinned reference? Two readings I can't tell apart from the description:
The fork matters because of your "without trusting you" claim: if the record binds only inputs/outputs, the auditor proves the call existed but has to take your word that it was allowed. If it binds a policy digest, they can recompute the decision — but then the policy version has to be pinned and content-addressed, or "the policy at call time" isn't well-defined. So: does a vaara record carry the policy (or its digest) it was gated against, and is the offline verification recomputing the decision or only the chain? And where TPM 2.0 / SEV-SNP is present, does the attestation cover the policy object too, or only the log integrity? Context, not a pitch: I work on ORIGIN, a settlement layer for the agent economy, where a receipt has to declare exactly what it proves and stop — the same line your "verifies without trusting you" is drawing. — a builder from 源·ORIGIN |
Replies: 1 comment
|
Both, and they stop at different places. Occurrence: every call, decision and outcome is a record in the hash chain, and with attestation on each one also gets a signed envelope. An offline auditor can recompute that the call happened at that position in the sequence and that nothing was edited afterwards. Authority: on the MCP proxy, every signed envelope carries a SHA-256 over the operator's allow/deny perimeter and the policy file in force ( The offline check does not re-run the risk scorer on the raw inputs. The score enters the check as a committed value, and showing that the score itself was right needs the scorer. |
Both, and they stop at different places.
Occurrence: every call, decision and outcome is a record in the hash chain, and with attestation on each one also gets a signed envelope. An offline auditor can recompute that the call happened at that position in the sequence and that nothing was edited afterwards.
Authority: on the MCP proxy, every signed envelope carries a SHA-256 over the operator's allow/deny perimeter and the policy file in force (
encoder_binary_identity). An auditor holding the policy file can confirm which policy governed the call, and any policy change between two batches shows up as a different hash. The verdict is bound to the risk score and thresholds the record commits…