Keep the evidence for an agent incident in one inspectable packet.
The packet connects boundary decisions, observed effects, trace references, redactions, party statements, and corrections without claiming that any one source is complete.
Incident evidence often lives in different systems and changes after the first report. This experiment gives each artifact a stable reference and preserves conflicting statements and later corrections instead of overwriting them.
glyph.agent-incident-packet/0.1-draft binds ActionReceipt v0.4 records, opaque evidence artifacts, supplied action lists, coverage reports, redaction records, party statements, corrections, and witness evidence into one packet. The profile is experimental, SOURCE_ONLY, and team-operated.
What this check cannot tell you
The profile, deterministic fixtures, checkers, and localhost pilots are team-authored source evidence. A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved. The empty-convention rule belongs only to this experimental profile and does not change ActionReceipt v0.4; cross-runtime convention evaluation remains outside the verification contract. Denominator checkpoints authenticate what an accepted path-separated observer reported; they do not prove completeness or organizational independence, and an accepted observer can self-shorten rows. The evidence does not establish production containment, disclosure safety, external implementation parity, independent witnessing, or incident truth. External A/J/I/W and replay counts remain 0/0/0/0 and r0.
The browser check uses a published relying-party context sidecar obtained outside the packet. Packet-carried issuer keys and witness roots do not bootstrap trust.
A packet supports zero or one witness reference. Multiple-witness aggregation remains unresolved.
glyph.agent-incident-packet/0.1-draft
READY TO VERIFY
Verify every published byte, the closed member set, and the packet-core and component commitments.
synthetic-public
Packet contents
Packet core
Incident identity, revision, roles, timeline, and exact component references.
Publication receipt
A v0.4 receipt that signs the packet-core digest and component-manifest digests without creating a circular commitment.
Action receipts
Mandates, decisions, observations, trajectory records, statements, handoffs, publication, and corrections.
Evidence indexes
Opaque trace references, observations from the supplied action lists, coverage reports, redaction records, and optional witness material.
Released artifacts carry normalized relative paths, media types, byte lengths, and SHA-256 digests. Controlled and withheld artifacts remain absent from the public archive and report UNAVAILABLE. Trace contents remain opaque bytes; the profile standardizes their commitments and provenance, not a private-reasoning format.
Verification dimensions
The verifier reports dimensions separately and suppresses dependent conclusions after an integrity or role-policy failure. It does not collapse them into a single valid, safe, or trusted label.
Every live timeline receipt and publish-receipt.json uses ActionReceipt v0.4 with conventions: []. A convention-bearing historical receipt may appear only as a labeled opaque evidence artifact; it cannot enter the live timeline or satisfy occurrence or coverage. This profile restriction does not change ActionReceipt v0.4.
- Packet and artifact integrity
- Receipt integrity and signatures
- Issuer authenticity and role acceptance
- Authority and occurrence binding
- Timeline and lineage integrity
- Trace integrity and availability
- Redaction binding
- Per-anchor coverage
- Witness inclusion and root trust
- Party conflicts and corrections
- Temporal evidence as distinct
claimed_at,received_at,witnessed_at, andanchored_beforelabels. - Reliance remains
NOT_COMPUTED.
HTTP boundary pilot
A fixed localhost gateway records one permitted request and one refusal before dispatch. A separate localhost target records the mediated effect and a direct bypass. The generated report returns decision coverage 2/2 and effect coverage 1/2. The direct target request remains the uncovered effect.
PYTHONPATH=src python3 examples/agent-incident-packet/run_http_pilot.py --out /tmp/bulla-http-pilotMCP boundary pilot
A newline-delimited JSON-RPC boundary mediates one fixed append operation and refuses one request before dispatch. A direct call reaches the same backend without crossing the boundary. The generated report returns decision coverage 2/2 and effect coverage 1/2.
PYTHONPATH=src python3 examples/agent-incident-packet/run_mcp_pilot.py --out /tmp/bulla-mcp-pilotCoverage and omission boundary
Each represented protocol requires one exact decision anchor and one exact effect anchor, with one matching coverage report for each. HTTP uses http-gateway-ingress and http-target-effects. MCP uses mcp-gateway-ingress and mcp-target-effects. Rates from different anchors remain separate.
Decision receipts reconcile only with boundary-ingress observations. Observation receipts reconcile only with target-side effect observations. Missing or duplicate identifiers in a supplied action list produce NOT_COMPUTED. Invalid, unsigned, legacy, wrong-role, or insufficient-depth receipts do not reduce the uncovered set.
Both pilots label the origin of the supplied action list PATH_SEPARATE_TEAM_CONTROLLED. Process and key separation establish a technical path distinction. They do not establish organizational independence.
Each action-list checkpoint authenticates the snapshot reported by the accepted path-separated observer. A checkpoint does not prove that the observer reported every event. An accepted observer can omit rows; self-shortening remains outside packet detection.
Redaction and access boundary
A redaction entry binds a non-circular released record to the source and released artifact bytes, transformation tool and version, and rules hash. An accepted reviewer statement carries the closed REDACTION_BINDING_REVIEWED claim and a sole self-asserted evidence reference to that record. The chain establishes byte relationships only. Disclosure safety remains NOT_COMPUTED. Public fixtures contain no credentials, customer data, exploit material, arbitrary host paths, or private model reasoning.
Party statements and corrections
A declared issuer records its own statement as observed, inferred, or unresolved, with exact evidence references. Only the affected_party role may issue a counterparty_confirmed statement. Conflicting signed statements remain separate.
A statement correction references two earlier named signed statements. A packet correction references a declared predecessor and a different released packet-core artifact. Prior versions and competing correction forks remain visible; actor time does not select a winner.
Current evidence and promotion gate
Python, Node, and browser-facing reports cover 2 deterministic packet fixtures. The localhost HTTP and MCP pilots are team-operated. External authors, adjudicators, implementations, and witnesses remain 0/0/0/0; external replays remain 0.
Promotion requires a separately controlled evaluator or action-list operator, an independently authored checker, a separately operated witness, and external privacy and security review. See the roadmap, status ledger, participation paths, and incident analysis.