ForgeLayer

Output Intake & Replayable Evidence

Treat every provider output as untrusted until evidence is verified.

ForgeLayer validates a bounded envelope, preserves provenance, normalizes safe metadata, and prepares a Verification handoff. Public production receives no provider output.

Demo fixtures: 3Real outputs: 0Verified: 0Persisted: 0

Repository provenance

Evidence scope is deterministic; repository truth remains unavailable.

Each intake fixture binds to one scenario-owned repository preview and deterministic path manifest. Provider output was not received, repository content and GitHub PRs/checks were not fetched, comments were not posted, and repository verification did not run.

Workspace repository inventory

1 repository host recognized

3 scenario-isolated GitHub repository previews. Installation, ownership, permissions, metadata, and contents remain unverified or unavailable.

Inspect Repository Connections
3Recorded previews
0Verified installations
0Verified repositories
0Metadata read enabled
0Contents read enabled
0Write enabled
0Webhooks configured
0Repository executions
Deterministic previewGitHub requests: 0GitHub writes: 0Provider inventory remains separate

Trust model

Provenance and trust are related, not interchangeable

Schema validation can normalize an item for review. It cannot promote provider claims into observed or independently verified evidence.

Provenance

system controlprovider reportedforgelayer observedindependently verifiedhuman attesteddeterministic demounknownrejected

Trust level

informationaluntrustednormalized unverifiedobserved unverifiedindependently verifiedhuman confirmedrejected

Deterministic fixtures

Three bounded intake records, zero provider events

Each fixture is scoped to one workspace, task, dispatch preview, provider/adapter pair, policy snapshot, and inactive capability package.

deterministic demo

Secure a payment webhook

demo fixture
Intake
output-intake-ad49b550482bacea
Dispatch
dispatch-preview-db15b2cd
Provider output received
false
Validation
valid demo fixture
Normalization
normalized demo fixture
Redaction / quarantine
not required / not quarantined
Provenance / trust
deterministic demo / normalized unverified

Changed-file manifest

app/api/payments/webhook.tsmodified · inside scope
tests/payment-webhook.test.tsmodified · inside scope

No source body is stored and no file is applied.

Verification handoff

  • security_review_evidenceineligible demo · satisfied: false
  • rollback_planineligible demo · satisfied: false
  • payment_webhook_securityineligible demo · satisfied: false
  • auth_session_boundaryineligible demo · satisfied: false

4 evidence requirements remain unsatisfied.

Replay control and evidence lifecycle
  1. 01
    task createdControlled Tasks · system control

    Deterministic Controlled Task record created.

  2. 02
    policy evaluatedExecutable Policy Engine · system control

    Policy snapshot policy-snapshot-5cc8bbf1 evaluated.

  3. 03
    capability package builtTask Capability Packages · system control

    Inactive capability package capability-package-secure-payment-webhook-v1 built.

  4. 04
    dispatch evaluatedControlled Dispatch · system control

    Dispatch evaluated and blocked; no request was sent.

  5. 05
    demo output fixture createdOutput Intake · deterministic demo

    Simulated fixture created; no provider output was received.

  6. 06
    intake validatedOutput Intake · deterministic demo

    Fixture schema and dispatch binding validated.

  7. 07
    evidence normalizedOutput Intake · deterministic demo

    4 safe evidence entries normalized without applying changes.

  8. 08
    verification requiredVerification Center · system control

    Normalized demo evidence remains ineligible to satisfy production verification.

  9. 09
    approval requiredApproval Center · system control

    Historical Event: Human approval remains required after independent verification.

  10. 10
    work record updatedAgent Work Records · deterministic demo

    Work Record preview linked to the safe evidence manifest.

  11. 11
    ledger event recordedAI Work Ledger · deterministic demo

    Non-persistent replay snapshot linked to the Ledger preview.

Deterministic integrity reference5374192946bc1fac15a91689e93521f424a1c0213990bdf325c808b93be0cb77Not proof of external action and not an immutable audit record.

deterministic demo

Harden a risky prompt

demo fixture
Intake
output-intake-32625a0dc0f64f4f
Dispatch
dispatch-preview-ec038137
Provider output received
false
Validation
valid demo fixture
Normalization
normalized demo fixture
Redaction / quarantine
not required / not quarantined
Provenance / trust
deterministic demo / normalized unverified

Changed-file manifest

lib/prompts/refund-assistant.tsmodified · inside scope
prompts/refund-assistant-security.mdadded · inside scope

No source body is stored and no file is applied.

Verification handoff

  • promptforge_analysisineligible demo · satisfied: false
  • prompt_injection_security_testsineligible demo · satisfied: false

2 evidence requirements remain unsatisfied.

Replay control and evidence lifecycle
  1. 01
    task createdControlled Tasks · system control

    Deterministic Controlled Task record created.

  2. 02
    policy evaluatedExecutable Policy Engine · system control

    Policy snapshot policy-snapshot-d8a299d8 evaluated.

  3. 03
    capability package builtTask Capability Packages · system control

    Inactive capability package capability-package-harden-risky-prompt-v1 built.

  4. 04
    dispatch evaluatedControlled Dispatch · system control

    Dispatch evaluated and blocked; no request was sent.

  5. 05
    demo output fixture createdOutput Intake · deterministic demo

    Simulated fixture created; no provider output was received.

  6. 06
    intake validatedOutput Intake · deterministic demo

    Fixture schema and dispatch binding validated.

  7. 07
    evidence normalizedOutput Intake · deterministic demo

    4 safe evidence entries normalized without applying changes.

  8. 08
    verification requiredVerification Center · system control

    Normalized demo evidence remains ineligible to satisfy production verification.

  9. 09
    approval requiredApproval Center · system control

    Historical Event: Human approval remains required after independent verification.

  10. 10
    work record updatedAgent Work Records · deterministic demo

    Work Record preview linked to the safe evidence manifest.

  11. 11
    ledger event recordedAI Work Ledger · deterministic demo

    Non-persistent replay snapshot linked to the Ledger preview.

Deterministic integrity reference12452062313a5ee894d6d02e654d336d154112f8de0a7efff35a416df46ce001Not proof of external action and not an immutable audit record.

deterministic demo

Investigate failing tests

demo fixture
Intake
output-intake-ef19cdff8788f824
Dispatch
dispatch-preview-683d375f
Provider output received
false
Validation
valid demo fixture
Normalization
normalized demo fixture
Redaction / quarantine
not required / not quarantined
Provenance / trust
deterministic demo / normalized unverified

Changed-file manifest

tests/checkout-confirmation.test.tsmodified · inside scope
app/checkout/confirmation.tsxmodified · inside scope
package.jsonunchanged · inside scope

No source body is stored and no file is applied.

Verification handoff

  • failing_test_outputineligible demo · satisfied: false
  • passing_rerun_outputineligible demo · satisfied: false
  • test_failure_reproducedineligible demo · satisfied: false
  • test_remediation_verifiedineligible demo · satisfied: false

4 evidence requirements remain unsatisfied.

Replay control and evidence lifecycle
  1. 01
    task createdControlled Tasks · system control

    Deterministic Controlled Task record created.

  2. 02
    policy evaluatedExecutable Policy Engine · system control

    Policy snapshot policy-snapshot-69ecde00 evaluated.

  3. 03
    capability package builtTask Capability Packages · system control

    Inactive capability package capability-package-investigate-failing-tests-v1 built.

  4. 04
    dispatch evaluatedControlled Dispatch · system control

    Dispatch evaluated and blocked; no request was sent.

  5. 05
    demo output fixture createdOutput Intake · deterministic demo

    Simulated fixture created; no provider output was received.

  6. 06
    intake validatedOutput Intake · deterministic demo

    Fixture schema and dispatch binding validated.

  7. 07
    evidence normalizedOutput Intake · deterministic demo

    6 safe evidence entries normalized without applying changes.

  8. 08
    verification requiredVerification Center · system control

    Normalized demo evidence remains ineligible to satisfy production verification.

  9. 09
    approval requiredApproval Center · system control

    Historical Event: Human approval remains required after independent verification.

  10. 10
    work record updatedAgent Work Records · deterministic demo

    Work Record preview linked to the safe evidence manifest.

  11. 11
    ledger event recordedAI Work Ledger · deterministic demo

    Non-persistent replay snapshot linked to the Ledger preview.

Deterministic integrity referencebf2e238602fc979e9c80abeb447b300ebe7a7a4df9a9c5fa947369b08ed56649Not proof of external action and not an immutable audit record.