{"schema":"VGS-LIMITS-v1","version":"1.0","published":"2026-07-30","doi_reference":"https://doi.org/10.5281/zenodo.20627386","description":"Authoritative statement of VeriSigil's proof boundaries. Updated with each specification revision.","what_verisigil_proves":{"governance_disposition_produced":{"answer":"YES","detail":"VeriSigil proves that a governance disposition (ALLOW/DENY/ESCALATE) was produced for a specific agent, action, authority state, consequence tier, and timestamp before execution was permitted to proceed."},"disposition_not_altered":{"answer":"YES","detail":"The Ed25519 governance signature proves the sealed record has not been altered since it was produced. Verifiable offline using the published public key without trusting VeriSigil."},"authority_continuity_evaluated":{"answer":"YES","detail":"Gate 3 evaluates whether the agent's authority delegation remains current, unrevoked, and unexpired at the exact moment of the governance decision."},"mandate_scope_evaluated":{"answer":"YES","detail":"Gate 2 evaluates whether the proposed action falls within the agent's declared mandate scope."},"consequence_tier_evaluated":{"answer":"YES","detail":"Gate 4 evaluates the consequence tier of the proposed action and applies the appropriate governance response including human oversight requirements."},"behavioral_continuity_evaluated":{"answer":"YES","detail":"Gate 1 evaluates whether the agent's behavioral state has drifted from its approved baseline."},"same_condition_replay":{"answer":"YES","detail":"A governance decision can be deterministically replayed from the sealed evidence record under the same conditions, producing the same result. Endpoint: POST /v1/governance/replay"},"changed_condition_replay":{"answer":"YES","detail":"Changing one governing condition (e.g. authority_status VALID → EXPIRED) produces a different ruling. Demonstrable via POST /v1/proof/scenario/run with condition=A or condition=B."},"offline_verification":{"answer":"YES","detail":"Any sealed governance record can be verified offline using the published public key and canonical JSON specification without calling VeriSigil. Public key: lJWG0Wabt6uATPu5Upo6UEHWGXQqMyi6LMKQC0xwpY8="},"cryptographic_tamper_evidence":{"answer":"YES","detail":"Any modification to a sealed governance record invalidates the Ed25519 signature, making tampering detectable without trusting VeriSigil."},"bypass_attempt_rejection":{"answer":"YES","detail":"Replayed receipts, modified payloads, expired signatures, and timestamp manipulation all produce deterministic rejections. Demonstrable via POST /v1/challenge/bypass."},"autonomous_agent_deny":{"answer":"YES","detail":"Autonomous agents (human_present=false) at CRITICAL or EMERGENCY consequence tier receive DENY not ESCALATE, because there is no human available to receive an escalation. Validated by CLARA Runtime Validation Program Run 2."},"external_independent_validation":{"answer":"YES — PARTIAL","detail":"External attestation by OMNIX QUANTUM LTD (POGC-EXT-A7F3C2B1D9E4F508, ML-DSA-65 signed, 4 production traces, zero invariant violations). CLARA Runtime Validation Program provides independent autonomous agent battery validation. Full institutional witnessing infrastructure is in formal agreement phase."},"sink_acceptance_proof":{"answer":"PARTIAL","detail":"VeriSigil proves the governance disposition was produced and delivered to the governed boundary. Proof that the protected execution sink accepted or refused the action requires sink-side integration evidence that VeriSigil cannot produce unilaterally. This is a known architectural boundary."},"consequence_boundary_coverage":{"answer":"NO — by design","detail":"VeriSigil proves governance operated on a specifically protected execution route. It does not prove that no alternate execution path exists outside the governed boundary. Establishing complete consequence-boundary coverage requires an authoritative sink inventory, non-bypassability evidence, and independent deployment attestation — architectural objects that require client-side integration and are not produced by VeriSigil alone."},"predicate_truth":{"answer":"NO","detail":"VeriSigil evaluates governance conditions based on the values presented to it. A signed authority_status field is an assertion about authority, not independent proof that the authority is factually current. Establishing predicate truth requires the authority state to be linked to an independently attributable, versioned, freshness-bounded evidence source."},"replace_iam":{"answer":"NO","detail":"VeriSigil governs AI agent execution decisions. It does not replace identity and access management infrastructure."},"replace_siem":{"answer":"NO","detail":"VeriSigil produces governance evidence records. It integrates with SIEM but does not replace it."},"replace_edr":{"answer":"NO","detail":"VeriSigil operates at the AI execution boundary. It does not perform endpoint detection and response."},"govern_entire_operating_system":{"answer":"NO","detail":"VeriSigil governs consequential AI agent actions at the execution boundary. It does not govern general OS operations."},"legal_admissibility":{"answer":"NOT CLAIMED","detail":"VeriSigil produces cryptographically verifiable governance evidence. Whether that evidence meets legal admissibility standards in any jurisdiction is a legal determination VeriSigil does not make."},"regulatory_certification":{"answer":"NOT CLAIMED","detail":"VeriSigil maps to EU AI Act, ISO 42001, and NIST AI RMF requirements. It is not a certified conformity assessment body and does not issue regulatory certifications."}},"canonical_claim":"Decision-to-consequence evidence for a specifically protected execution route, with complete consequence-boundary coverage explicitly remaining unproven.","public_key":"lJWG0Wabt6uATPu5Upo6UEHWGXQqMyi6LMKQC0xwpY8=","verify_endpoint":"POST /v1/crypto/verify","bypass_challenge":"POST /v1/challenge/bypass","carrier_endpoint":"GET /v1/carrier/{execution_id}","timestamp":"2026-09-12T13:52:47.350451+00:00"}