Output Intake & Replayable Evidence
Treat every provider output as untrusted until evidence is verified.
ForgeLayer validates a bounded envelope, preserves provenance, normalizes safe metadata, and prepares a Verification handoff. Public production receives no provider output.
Repository provenance
Evidence scope is deterministic; repository truth remains unavailable.
Workspace repository inventory
1 repository host recognized
3 scenario-isolated GitHub repository previews. Installation, ownership, permissions, metadata, and contents remain unverified or unavailable.
Inspect Repository ConnectionsTrust model
Provenance and trust are related, not interchangeable
Provenance
Trust level
Deterministic fixtures
Three bounded intake records, zero provider events
deterministic demo
Secure a payment webhook
- Intake
output-intake-ad49b550482bacea- Dispatch
dispatch-preview-db15b2cd- Provider output received
- false
- Validation
- valid demo fixture
- Normalization
- normalized demo fixture
- Redaction / quarantine
- not required / not quarantined
- Provenance / trust
- deterministic demo / normalized unverified
Changed-file manifest
app/api/payments/webhook.tsmodified · inside scopetests/payment-webhook.test.tsmodified · inside scopeNo source body is stored and no file is applied.
Verification handoff
- security_review_evidenceineligible demo · satisfied: false
- rollback_planineligible demo · satisfied: false
- payment_webhook_securityineligible demo · satisfied: false
- auth_session_boundaryineligible demo · satisfied: false
4 evidence requirements remain unsatisfied.
Replay control and evidence lifecycle
- 01task createdControlled Tasks · system control
Deterministic Controlled Task record created.
- 02policy evaluatedExecutable Policy Engine · system control
Policy snapshot policy-snapshot-5cc8bbf1 evaluated.
- 03capability package builtTask Capability Packages · system control
Inactive capability package capability-package-secure-payment-webhook-v1 built.
- 04dispatch evaluatedControlled Dispatch · system control
Dispatch evaluated and blocked; no request was sent.
- 05demo output fixture createdOutput Intake · deterministic demo
Simulated fixture created; no provider output was received.
- 06intake validatedOutput Intake · deterministic demo
Fixture schema and dispatch binding validated.
- 07evidence normalizedOutput Intake · deterministic demo
4 safe evidence entries normalized without applying changes.
- 08verification requiredVerification Center · system control
Normalized demo evidence remains ineligible to satisfy production verification.
- 09approval requiredApproval Center · system control
Historical Event: Human approval remains required after independent verification.
- 10work record updatedAgent Work Records · deterministic demo
Work Record preview linked to the safe evidence manifest.
- 11ledger event recordedAI Work Ledger · deterministic demo
Non-persistent replay snapshot linked to the Ledger preview.
5374192946bc1fac15a91689e93521f424a1c0213990bdf325c808b93be0cb77Not proof of external action and not an immutable audit record.deterministic demo
Harden a risky prompt
- Intake
output-intake-32625a0dc0f64f4f- Dispatch
dispatch-preview-ec038137- Provider output received
- false
- Validation
- valid demo fixture
- Normalization
- normalized demo fixture
- Redaction / quarantine
- not required / not quarantined
- Provenance / trust
- deterministic demo / normalized unverified
Changed-file manifest
lib/prompts/refund-assistant.tsmodified · inside scopeprompts/refund-assistant-security.mdadded · inside scopeNo source body is stored and no file is applied.
Verification handoff
- promptforge_analysisineligible demo · satisfied: false
- prompt_injection_security_testsineligible demo · satisfied: false
2 evidence requirements remain unsatisfied.
Replay control and evidence lifecycle
- 01task createdControlled Tasks · system control
Deterministic Controlled Task record created.
- 02policy evaluatedExecutable Policy Engine · system control
Policy snapshot policy-snapshot-d8a299d8 evaluated.
- 03capability package builtTask Capability Packages · system control
Inactive capability package capability-package-harden-risky-prompt-v1 built.
- 04dispatch evaluatedControlled Dispatch · system control
Dispatch evaluated and blocked; no request was sent.
- 05demo output fixture createdOutput Intake · deterministic demo
Simulated fixture created; no provider output was received.
- 06intake validatedOutput Intake · deterministic demo
Fixture schema and dispatch binding validated.
- 07evidence normalizedOutput Intake · deterministic demo
4 safe evidence entries normalized without applying changes.
- 08verification requiredVerification Center · system control
Normalized demo evidence remains ineligible to satisfy production verification.
- 09approval requiredApproval Center · system control
Historical Event: Human approval remains required after independent verification.
- 10work record updatedAgent Work Records · deterministic demo
Work Record preview linked to the safe evidence manifest.
- 11ledger event recordedAI Work Ledger · deterministic demo
Non-persistent replay snapshot linked to the Ledger preview.
12452062313a5ee894d6d02e654d336d154112f8de0a7efff35a416df46ce001Not proof of external action and not an immutable audit record.deterministic demo
Investigate failing tests
- Intake
output-intake-ef19cdff8788f824- Dispatch
dispatch-preview-683d375f- Provider output received
- false
- Validation
- valid demo fixture
- Normalization
- normalized demo fixture
- Redaction / quarantine
- not required / not quarantined
- Provenance / trust
- deterministic demo / normalized unverified
Changed-file manifest
tests/checkout-confirmation.test.tsmodified · inside scopeapp/checkout/confirmation.tsxmodified · inside scopepackage.jsonunchanged · inside scopeNo source body is stored and no file is applied.
Verification handoff
- failing_test_outputineligible demo · satisfied: false
- passing_rerun_outputineligible demo · satisfied: false
- test_failure_reproducedineligible demo · satisfied: false
- test_remediation_verifiedineligible demo · satisfied: false
4 evidence requirements remain unsatisfied.
Replay control and evidence lifecycle
- 01task createdControlled Tasks · system control
Deterministic Controlled Task record created.
- 02policy evaluatedExecutable Policy Engine · system control
Policy snapshot policy-snapshot-69ecde00 evaluated.
- 03capability package builtTask Capability Packages · system control
Inactive capability package capability-package-investigate-failing-tests-v1 built.
- 04dispatch evaluatedControlled Dispatch · system control
Dispatch evaluated and blocked; no request was sent.
- 05demo output fixture createdOutput Intake · deterministic demo
Simulated fixture created; no provider output was received.
- 06intake validatedOutput Intake · deterministic demo
Fixture schema and dispatch binding validated.
- 07evidence normalizedOutput Intake · deterministic demo
6 safe evidence entries normalized without applying changes.
- 08verification requiredVerification Center · system control
Normalized demo evidence remains ineligible to satisfy production verification.
- 09approval requiredApproval Center · system control
Historical Event: Human approval remains required after independent verification.
- 10work record updatedAgent Work Records · deterministic demo
Work Record preview linked to the safe evidence manifest.
- 11ledger event recordedAI Work Ledger · deterministic demo
Non-persistent replay snapshot linked to the Ledger preview.
bf2e238602fc979e9c80abeb447b300ebe7a7a4df9a9c5fa947369b08ed56649Not proof of external action and not an immutable audit record.