Evidence status
WaitingConnect to inspect coverage.
Evidence plane
A reconciled view of completed AI interactions and their source evidence.
Not connected
Evidence status
WaitingConnect to inspect coverage.
Latest observation
—Collector-observed UTC time
Reporting sources
—No installation data
Deployment assurance
Attach a content-free compatibility program report to compare endpoint, SWG, AI gateway, and mTLS qualification evidence.
Qualified lanes
—No report loaded
Candidate anomalies
—Observer-only deltas after baseline bracketing
Block readiness
—Advisory only; never activates enforcement
| Deployment lane | Disposition | Tier | Evidence | Worst added p95 | Issues | Block proof |
|---|---|---|---|---|---|---|
| No compatibility report configured. | ||||||
Metric · definition 1.2
Distinct interactions with accepted terminal evidence. Upstream 4xx/5xx responses count as completed; failed means no final response was observed.
Metadata-only assurance · definition 1.0
Connect to reconcile inspected, opaque, oversized, and legacy decisions.
Decisions
—No evidence loaded
Inspected
—Bounded request-body classification
Opaque
—Payload unavailable to the capture lane
Oversized
—Rejected from bounded inspection
Findings
—Decisions with one or more detector IDs
| Detector | Decisions |
|---|---|
| No detector findings in this window. | |
Capture-neutral evidence
No rows loaded
Every recorded decision, including endpoint sensors and decision-only integrations. Open a row to inspect capture plane and lifecycle coverage.
| Interaction | Event time | Installation | Evidence source | Effective outcome |
|---|---|---|---|---|
| Connect to load policy decision evidence. | ||||
Exact metric drilldown
No rows loaded
| Interaction | Event time | Installation | Connector source | Outcome |
|---|---|---|---|---|
| Connect to load metadata-only evidence. | ||||
Block decisions
No rows loaded
These rows are effective block decisions. Open one and require “Blocked before forwarding” plus zero forwarding and provider-response events before claiming enforcement.
| Interaction | Event time | Installation | Policy | Outcome |
|---|---|---|---|---|
| Connect to load blocked decision evidence. | ||||
All entities
—No observations
Applications
—Observed AI destinations
Identities
—Pseudonymous by contract
Agents
—Application and autonomous agents
MCP servers
—Observed tool endpoints
Tools
—Exposed capabilities
Recently observed
—Active and seen inside the selected window
Not recently observed
—Active, but no entity evidence inside the window
Explicitly retired
—Retired by every reporting source
Lifecycle unknown
—Predates source lifecycle evidence
Recently reporting sources
—No source evidence
Metadata-only · definition 1.0
No rows loaded
Connect to inspect source coverage.
| Entity | Type | Observed status | Criticality | Relationships | Last seen |
|---|---|---|---|---|---|
| Connect to load inventory metadata. | |||||
Bounded alternate view · definition 1.0
No graph loaded
The graph uses the same first 50 matching entities as the canonical table.
Total / decided
—No decisions
Unmanaged
—Requires accountable review
Review required
—Decision explicitly deferred
Sanctioned
—Approved enterprise use
Restricted
—Use subject to controls
Blocked
—Use prohibited by decision
Reconciled work queue · definition 1.0
No rows loaded
Connect to inspect governance coverage.
| Entity | Type | Disposition | Owner | Decision | Last changed / seen |
|---|---|---|---|---|---|
| Connect to load the governance queue. | |||||
Reporting coverage
—Configured enabled connectors
Reporting
—Healthy inside declared cadence
Degraded
—Reporting a degraded state
Overdue
—Past twice declared cadence
Awaiting first heartbeat
—Configured but never reported
Disabled
—Excluded from the denominator
Declared scope · definition 1.0
No status loaded
Connect to inspect configured connector coverage.
| Scope | Reporting | Expected | Coverage |
|---|---|---|---|
| No declared connector scope. | |||
| Connector | State | Declared scope | Cadence | Last heartbeat | Last completed scan |
|---|---|---|---|---|---|
| Connect to load connector status. | |||||
Connect to inspect authoritative denominators.
| Entity kind | Authority | State | Observed / expected | Gap / excess | Completeness | Snapshot |
|---|---|---|---|---|---|---|
| Connect to load authoritative scope. | ||||||
Coverage
—No snapshot
Active identities
—Canonical active inventory
Resolved
—Exactly one active directory object
Unresolved
—No active directory attribution
Ambiguous
—Multiple active directory objects
Inactive references
—Subset of unresolved identities
Authoritative reconciliation · definition 1.0
No status loaded
Connect to inspect identity attribution coverage.
Coverage is intentionally unavailable until an enabled identity authority and a current full attribution snapshot exist. Identity-based enforcement must not rely on this view while its state is anything other than current.
Actionable exceptions · definition 1.0
Connect to load the remediation queue.
| Identity | Reason | Candidate evidence | Last seen |
|---|---|---|---|
| Connect to load identity exceptions. | |||
Observed applications
—No configured denominator asserted
Observed sources
—Durable audit exporters
Accepted events
—Idempotent lifetime source state
Latest source observation
—No post-hoc evidence
Evidence boundary · definition 1.0
Post-hoc · metadata only
This evidence arrives after activity occurs. It supports discovery and attribution but cannot prove inline inspection, redaction, or blocking before forwarding.
Connect to inspect declared blind spots.
Constant-size projection
No sources loaded
| Application | Source | Connector | Events | Latest observation | Source lag |
|---|---|---|---|---|---|
| Connect to load application source state. | |||||
Bounded indexed query
No events loaded
| Event time | Application | Activity | Actor pseudonym | Outcome | Source lag |
|---|---|---|---|---|---|
| Connect to load metadata-only activity. | |||||
Observed destinations
—Unique hosts in this window
Known AI
—Matched by the destination catalog
Inspection planned
—Eligible for bounded request inspection
Opaque tunnels
—Routed without content decryption
Browser sessions
—Hashed extension sessions in this window
Context samples
—First host observation per browser session
Top-level destinations
—Distinct hosts first seen as the primary page
Background context
—Embedded, background, asset, or other observations
Verified inline
—Qualified pre-forward control
Experimental inline
—Controlled conformance only
Post-hoc audit
—Provider evidence surface declared
Discovery only
—Recognized without first-class evidence
Endpoint discovery · contract 1.2
No observations loaded
Extension context is a bounded first-host sample, not request volume or proof of user interaction.
| Destination | Classification | Product coverage | Inspection | Browser context | Observations | Latest |
|---|---|---|---|---|---|---|
| Connect and route a controlled browser session to observe destination coverage. | ||||||
Provider invocations
—Post-hoc metadata events
Provider-native
—Upstream audit evidence
Application-native
—AI application audit evidence
Instrumented
—Workload-reported telemetry
Observed models
—Exact provider and model pairs
Input tokens
—Source-reported usage
Output tokens
—Source-reported usage
Provenance-separated evidence · contract 1.2
No evidence loaded
Source completeness and delivery health are not yet verified.
| Model | Region | Operation | Evidence | Invocations | Input tokens | Output tokens | Latest |
|---|---|---|---|---|---|---|---|
| Connect provider-native, application-native, or instrumented evidence to populate this view. | |||||||
Direct providers
—Exact provider origins
AI gateways
—Hosted and customer-managed routes
Application sources
—Post-hoc administrative evidence
Provider evidence
—Post-hoc invocation sources
Verified blocking
—Bindings tested pre-forward
Experimental blocking
—Requires customer validation
Embedded release evidence · contract 1.0
Not loaded
The digest binds this catalog to the compiled artifact. Publisher authenticity remains “not verified” until signed catalog distribution is implemented.
Capability truth · catalog 1.0
No declarations loaded
| Integration |
|---|
| Connect to load the compiled release catalog. |
Threat-defense governance · contract 1.0
No package loaded
Packages are versioned and independently approved, but this foundation cannot activate enforcement.
Definitions contain categories, scopes, implementation versions, and latency/size budgets—never prompt bodies or secret values.
| Package | Detector set | Detectors | Status | Runtime eligibility | Version |
|---|---|---|---|---|---|
| No detector packages configured. | |||||
Pre-deployment input · contract 1.0
Analysis uses the exact compiled first-match order. Policy content remains in this request and is not persisted.
Maximum 2,000 rules and 128 values per condition dimension.
Activation gate
Not analyzedCompiled order unavailable
Shadowed
—Unreachable with a different outcome
Conflicting overlaps
—Both can match; order chooses outcome
Redundant
—Unreachable with the same outcome
Runtime-equivalent analysis · definition 1.0
No analysis loaded
Analyze a policy set before signing or activation.
| Severity | Finding | Earlier winner | Later rule | Explanation |
|---|---|---|---|---|
| No policy analysis loaded. | ||||
Executable fixtures · contract 1.0
Compare an explicit baseline and candidate using normalized, content-free facts. Expectations require both the exact outcome and winning rule.
Governed evidence · contract 1.0
Connect to load tenant-isolated fixture sets.
Maximum 2,000 rules per set and 1,000 unique fixtures.
Activation gate
Not simulatedStatic safety plus fixture expectations
Changed
—Outcome or winning rule changed
Expectations passed
—No fixtures loaded
Expectations failed
—Exact candidate mismatch
Run fixtures to inspect baseline and candidate decisions.
| Fixture | Baseline | Candidate | Change | Expectation |
|---|---|---|---|---|
| No simulation loaded. | ||||
Separation of duties · contract 1.0
No proposal loaded
Submit the current candidate and exact governed fixture-set version for independent review.
Observed traffic · contract 1.0
Not evaluated
Advisory only. This check never activates or enforces a candidate.
Controlled enforcement · contract 1.0
No rollout loaded
The server recomputes readiness. A second administrator must approve the immutable cohort before a signed authorization can be issued.
Deployment-observed propagation · contract 1.0
No bypass loaded
Load an approved bypass ID to distinguish durable control state from gateway propagation. Opaque replica IDs are diagnostics, not independent workload attestations.
Completion
—Exact fresh governed denominator
Fresh current
—Expected unknown
Missing / stale
—Not current inside freshness bound
Wrong / extra
—Version, revision, or denominator drift
| Opaque replica | Observation | Revision | First received | Last received | Fresh / exact |
|---|---|---|---|---|---|
| No deployment observations loaded. | |||||