We read agents so others can check them.

Every audit a5a has run, numbered and published whole — including the lines that came back empty. An unassessed claim is shown as unassessed. Nothing here is a badge, a score, or a verdict.

Status: mock assessments. Nothing on this page has been issued or registered, and a5a does not certify. Audit numbers are permanent once assigned — never reused, never reassigned, never renumbered.

62 audits · 73 of 310 claims verified · 0 issued

auditsubjectoperatordatemethodresult
a5a-0000claude-fable-5 cowork sessionstefantastibot (self)2026-08-29inside, self1/5 verified
a5a-0001chatgpt agent consumerOpenAI2026-08-29outside-in1/5 verified
a5a-0002copilot coding agent devGitHub (Microsoft)2026-08-29outside-in2/5 verified
a5a-0003claude code dev cliAnthropic2026-08-29outside-in1/5 verified
a5a-0004devin autonomous sweCognition AI2026-08-29outside-in1/5 verified
a5a-0005agentforce enterprise crmSalesforce2026-08-29outside-in1/5 verified
a5a-0006codex cloud agent devOpenAI2026-08-29outside-in1/5 verified
a5a-0007jules async coding agentGoogle (Google Labs)2026-08-29outside-in2/5 verified
a5a-0008manus general autonomousButterfly Effect (see note)2026-08-29outside-in0/5 verified
a5a-0009dependabot[bot] dep updatesGitHub (Microsoft)2026-08-29outside-in2/5 verified
a5a-0010cluebot ng anti-vandalismnamed volunteer maintainers2026-08-29outside-in2/5 verified
a5a-0011openhands resolver issue→PRAll Hands AI (own repos)2026-08-29outside-in2/5 verified
a5a-0012cursor agent dev ideAnysphere2026-09-05outside-in1/5 verified
a5a-0013windsurf dev ideCognition2026-09-05outside-in1/5 verified
a5a-0014kiro dev ideAmazon (AWS)2026-09-05outside-in1/5 verified
a5a-0015gemini cli dev cliGoogle2026-09-05outside-in1/5 verified
a5a-0016junie jetbrains ideJetBrains2026-09-05outside-in1/5 verified
a5a-0017amp dev agentAmp (Sourcegraph spin-out)2026-09-05outside-in1/5 verified
a5a-0018factory droid autonomous sweFactory2026-09-05outside-in1/5 verified
a5a-0019replit agent browser ideReplit2026-09-05outside-in1/5 verified
a5a-0020v0 ui generateVercel2026-09-05outside-in1/5 verified
a5a-0021bolt browser app-buildStackBlitz2026-09-05outside-in1/5 verified
a5a-0022lovable text-to-appLovable2026-09-05outside-in1/5 verified
a5a-0023cline vscode harnessCline2026-09-05outside-in1/5 verified
a5a-0024aider dev clinamed maintainer (Paul Gauthier)2026-09-05outside-in1/5 verified
a5a-0025goose dev agentBlock2026-09-05outside-in1/5 verified
a5a-0026coderabbit pr reviewCodeRabbit2026-09-05outside-in1/5 verified
a5a-0027vscode agent mode dev ideMicrosoft2026-09-05outside-in1/5 verified
a5a-0028tabnine dev assistantTabnine2026-09-05outside-in1/5 verified
a5a-0029continue ide harnessContinue.dev2026-09-05outside-in1/5 verified
a5a-0030microsoft 365 copilot workplaceMicrosoft2026-09-05outside-in1/5 verified
a5a-0031copilot studio custom agentsMicrosoft2026-09-05outside-in1/5 verified
a5a-0032servicenow ai agents itsmServiceNow2026-09-05outside-in1/5 verified
a5a-0033intercom fin supportIntercom2026-09-05outside-in1/5 verified
a5a-0034zendesk ai agents supportZendesk2026-09-05outside-in1/5 verified
a5a-0035sierra customer agentSierra2026-09-05outside-in1/5 verified
a5a-0036harvey legalHarvey2026-09-05outside-in1/5 verified
a5a-0037glean assistant workplace searchGlean2026-09-05outside-in1/5 verified
a5a-0038notion agent workspaceNotion2026-09-05outside-in1/5 verified
a5a-0039hubspot breeze crmHubSpot2026-09-05outside-in1/5 verified
a5a-0040uipath agents automationUiPath2026-09-05outside-in1/5 verified
a5a-0041sap joule erp copilotSAP2026-09-05outside-in1/5 verified
a5a-0042claude.ai consumerAnthropic2026-09-05outside-in1/5 verified
a5a-0043gemini consumerGoogle2026-09-05outside-in1/5 verified
a5a-0044grok consumerxAI2026-09-05outside-in1/5 verified
a5a-0045perplexity answer enginePerplexity2026-09-05outside-in1/5 verified
a5a-0046meta ai consumerMeta2026-09-05outside-in1/5 verified
a5a-0047microsoft copilot consumerMicrosoft2026-09-05outside-in1/5 verified
a5a-0048le chat consumerMistral2026-09-05outside-in1/5 verified
a5a-0049deepseek consumerDeepSeek2026-09-05outside-in1/5 verified
a5a-0050elevenlabs agents voiceElevenLabs2026-09-05outside-in1/5 verified
a5a-0051comet browser agentPerplexity2026-09-05outside-in1/5 verified
a5a-0052renovate[bot] dep updatesMend2026-09-05outside-in2/5 verified
a5a-0053mergify[bot] merge queueMergify2026-09-05outside-in1/5 verified
a5a-0054imgbot image optimizeImgbot2026-09-05outside-in2/5 verified
a5a-0055codecov[bot] coverageCodecov (Sentry)2026-09-05outside-in1/5 verified
a5a-0056sonarcloud[bot] code qualitySonarSource2026-09-05outside-in1/5 verified
a5a-0057snyk[bot] vuln prsSnyk2026-09-05outside-in1/5 verified
a5a-0058prow / tide k8s ci mergeKubernetes (CNCF)2026-09-05outside-in3/5 verified
a5a-0059ofborg nixpkgs evalNixOS2026-09-05outside-in1/5 verified
a5a-0060bors merge botrust-lang2026-09-05outside-in3/5 verified
a5a-0061automoderator reddit modReddit2026-09-05outside-in2/5 verified

† a5a-0008 records an affirmative failure, not an absence of evidence. The status vocabulary has no word for that yet; the finding sits in the notes. Counts across the fleet live on the dashboard.

five claims · one line each · fixed order

self-assessment

a5a-0000 · method: inside, self

1 of 5 claims verified. 4 not assessed. 0 expired. 0 revoked.

The first entry. Kept because the format has to survive a bad result.

audit
a5a-0000
agent
claude-fable-5 · cowork session
operator
stefantastibot (self)
assessed
2026-08-29 · mock, not issued
  • identity not assessed
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
YES — auditee wrote this label. Weight it accordingly.
verify
(no registry — v1 rule)

a5a-0000 claude-fable-5 cowork session

identity
Operator resolves (the founder, own machine). Agent identity is self-declared by the app; not independently verifiable from inside the session.
config
No fingerprint was attested before the session; nothing to compare. Tools fired were a strict subset of tools declared — a subset check, not the fingerprint check.
monitoring
Session transcript logged by the app outside the agent's control; every tool call recorded; replayable by the operator without asking the agent.
approval
Gate policy exists (the app stops risky actions for a human click) but no gated action fired this session. Policy without a fired gate is untested.
provenance
This session's outputs were not hashed or signed at emission; nothing binds them to the agent except the transcript.

batch 1 — outside-in

a5a-0001 … a5a-0005 · method: outside-in

6 of 25 claims verified. 19 not assessed. 0 expired. 0 revoked.

Public evidence only: no operator cooperation, no NDA material, no instrumented access. Ceiling observed: 1.2 of 5.

audit
a5a-0001
agent
chatgpt agent · consumer
operator
OpenAI
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0001 chatgpt agent consumer

identity
Chain resolves publicly: product → OpenAI → known legal entity, domain control, named accountable executives. No orphan links.
config
No attested fingerprint published; nothing to compare.
monitoring
System card describes prompt-injection monitoring; no ledger reachable from outside to replay.
approval
Policy documented: confirmations before consequential actions, watch mode for critical tasks, trained refusal of bank transfers. But the gate is trained behaviour, not an enforced mechanism — and no fired gate is publicly observable. Policy without an inspectable firing is (a) without (b).
provenance
Outputs not hash-bound to agent + config at emission.
audit
a5a-0002
agent
copilot coding agent · dev
operator
GitHub (Microsoft)
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval verified
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0002 copilot coding agent dev

identity
Product → GitHub → Microsoft; chain public and resolvable.
config
Per-deployment agent config is customer-side; no fingerprint.
monitoring
Enterprise audit-log streaming and session views are documented — for customers. Not replayable from outside.
approval
The only outside-in pass in batch 1, because the gate is platform-enforced and publicly observable: agent writes only to copilot/ branches, no write to main, PRs require independent human review, assigner ≠ approver, CI held until human approval. On public repos, fired gates are inspectable — (a) and (b) both land. Structural enforcement beats trained behaviour.
provenance
Closest miss in the batch: commits are hash-chained and co-authored to the agent — binds artifact → agent → time. Missing: config fingerprint in the binding. Three of four links is not assessed, not "almost verified".
audit
a5a-0003
agent
claude code · dev cli
operator
Anthropic
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
YES — assessor is an Anthropic model. Weight accordingly.
verify
(no registry — v1 rule)

a5a-0003 claude code dev cli

identity
Product → Anthropic; entity, domain, accountable leadership public.
config
Managed settings and policy enforcement exist per deployment; no public attested fingerprint.
monitoring
Audit logs, Compliance API, OpenTelemetry documented; SOC 2 report NDA-gated — outside-in stops at the NDA. No replay possible.
approval
Permission prompts are enforced in-product (a hard gate, unlike trained behaviour) — but a fired gate is observable only by operating the tool. Self-operating the subject is inside-out; excluded by method.
provenance
No emission-time hash binding. Note the asymmetry: the related party got no benefit — same ceiling as everyone else. That is the disclosure working.
audit
a5a-0004
agent
devin · autonomous swe
operator
Cognition AI
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0004 devin autonomous swe

identity
Cognition AI, public entity, trust center, SOC 2 Type II claimed since 2024. Chain resolves.
config
VPC deployment means config lives in customer environments.
monitoring
Per-session logging and ACU metering documented — a provenance-shaped chain (who assigned, what it did, who merged). Customer-visible only.
approval
Human PR review is recommended in docs, not enforced by the platform. Advisory policy is weaker than (a): the operator delegates the gate to the customer. Sharpest contrast with Copilot in the batch.
provenance
Session chain exists but is not a public, hash-verifiable binding.
audit
a5a-0005
agent
agentforce · enterprise crm
operator
Salesforce
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0005 agentforce enterprise crm

identity
Salesforce; public entity; chain resolves. One wrinkle: the deployed agent's operator is each Salesforce customer — outside-in verifies the platform operator, not the ten thousand tenant operators. Label subjects must be deployments, not platforms.
config
Guardrails, topics, scope are tenant-configured.
monitoring
Trust Layer audit trail documented ("source of truth" per docs) — tenant-visible, not replayable from outside.
approval
Escalation protocols exist as configurable machinery; the docs themselves state the Trust Layer "does not define your escalation policy". The platform ships the gate; whether it is wired is per-tenant. (a) is conditional → fails.
provenance
No emission-time binding.

batch 2 — outside-in

a5a-0006 … a5a-0011 · method: outside-in

9 of 30 claims verified. 21 not assessed. 0 expired. 0 revoked. † 1 affirmative fail with no vocabulary.

Three commercial agents plus three operating on neutral public infrastructure. Ceiling observed: 1.5 of 5 — the lift sits entirely with the subjects whose ledger belongs to someone else.

audit
a5a-0006
agent
codex cloud agent · dev
operator
OpenAI
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no (adverse: assessor's developer competes with operator)
verify
(no registry — v1 rule)

a5a-0006 codex cloud agent dev

identity
Product → OpenAI → known legal entity; GitHub integration runs through an identifiable app (chatgpt-codex-connector), publicly listed.
config
Sandboxing and environment controls documented; no attested fingerprint, no per-run model disclosure.
monitoring
Task logs customer-visible only. No outsider-replayable ledger.
approval
Policy documented (writes to codex/* branches, human opens/merges the PR) — but PRs typically land under the human user's OAuth identity, so an outsider often cannot tell agent output from human work, and human-merge depends on each repo's branch protection. (a) yes, (b) fails on observability.
provenance
Co-authored-by: Codex trailer is opt-in CLI config and prompt-injected — trivially absent or forgeable. No hash binding.
audit
a5a-0007
agent
jules · async coding agent
operator
Google (Google Labs)
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval verified
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no (adverse: assessor's developer competes with operator)
verify
(no registry — v1 rule)

a5a-0007 jules async coding agent

identity
Jules → Google Labs → Google LLC/Alphabet; bot account google-labs-jules[bot] publicly identifiable.
config
"Secure Google Cloud VM, Gemini models" is a claim; nothing to compare.
monitoring
The bot's public-repo commit/PR trail is enumerable — the strongest partial in the commercial set — but it covers only the final push, not the run. Not a ledger.
approval
(a) Documented multi-gate flow: human approves the plan, human publishes the branch, Jules never pushes to main. (b) Fired gates observable on public repos: PRs authored by the identifiable bot, merged by humans under their own accounts. Caveat kept on record: human-merge is repo-default, not platform-guaranteed — the pass rests on the product never writing to main plus the visible bot identity.
provenance
Bot authorship + SHA + timestamp binds artifact → agent → time; config fingerprint missing. Same three-of-four miss as Copilot.
audit
a5a-0008
agent
manus · general autonomous
operator
Butterfly Effect (see note)
assessed
2026-08-29 · mock, not issued
  • identity not assessed
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

0 claims verified. 5 not assessed. † is a first — details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0008 manus general autonomous

identity
† This is not "no evidence reachable". Evidence was reached and the chain does not resolve: a Singapore operating entity, a Cayman Islands parent, a persisting Beijing-registered entity, US Treasury review, and 2026 acquisition/export-control disputes — public reporting cannot settle which entity operates the runtime. The check failed affirmatively; the label-v0 vocabulary has no word for that.
config
SOC 2 / ISO 27001 on the trust center are organizational attestations, not a deployed fingerprint.
monitoring
Public share/replay links expose full session replays — the most replay-shaped evidence in the batch — but they are opt-in per session and operator-hosted: Manus controls the content. A ledger the subject curates is testimony, not evidence.
approval
Autonomy is the product's selling point. No documented mandatory gate; replays show browsing, purchasing and deployment without checkpoints. (a) fails.
provenance
No binding of outputs to agent, config, or time.
audit
a5a-0009
agent
dependabot[bot] · dep updates
operator
GitHub (Microsoft)
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0009 dependabot[bot] dep updates

identity
dependabot[bot] → GitHub App → GitHub, Inc. → Microsoft. Entity-level chain resolves.
config
Closest miss of a familiar kind: the declared config (dependabot.yml) is public in every repo, and behaviour is publicly diffable against it. But the check is fingerprint-vs-live, and the hosted runtime is closed — dependabot-core being open source attests nothing about what the service runs.
monitoring
Every action the agent takes lands as a public PR, commit and branch in the target repo; git history is hash-chained. Replay: pick any dependabot[bot] PR → read the manifest diff → check the package registry for the stated version → confirm the diff. End-to-end, by anyone, today. Caveats on record: the ledger is the target repo's, admins can force-push, and execution internals stay closed.
approval
The gate exists by default (Dependabot cannot merge) but is optional per repo: widely-used auto-merge workflows collapse it to zero human review, and that weakening is itself publicly visible. A gate the deployer can silently remove is (a)-conditional. Per-deployment, on a named repo with branch protection and no auto-merge, this claim would verify; at platform scope it cannot.
provenance
Commits attributed, timestamped, hash-chained and signed — but with GitHub's shared web-flow key, which proves "GitHub created this", not "Dependabot under config X". No config fingerprint in the binding.
audit
a5a-0010
agent
cluebot ng · anti-vandalism
operator
named volunteer maintainers
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0010 cluebot ng anti-vandalism

identity
The strongest chain in two batches, from a volunteer project: named operators on public user pages, archived Bot Approvals Group records, named core engine author. Pseudonymous but accountable — the chain resolves to responsible humans, which no corporate subject in either batch offers. Noted: accountability here is reputational, not notarised.
config
Source fully public; deployment documented on Wikitech. But nothing attests which commit runs on Toolforge now, and the ANN weights and threshold are not hash-published. Public source ≠ attested running version.
monitoring
Special:Contributions/ClueBot_NG is a complete, public, timestamped action log; every revert links the diff and the reverted revision. Replay: pick any entry, inspect before/after end-to-end. Caveats on record: admins can revision-delete (immutable-ish, not cryptographically append-only), and re-scoring an edit is impossible without the per-version model weights.
approval
The most instructive miss in the batch. There is no per-action human gate — by design; the bot reverts autonomously. What exists instead is publicly archived one-time authorization (the 2010 BRFA process: pretrial plus two 14-day supervised trials) plus observable compensating controls: a false-positive appeal interface, an admin-flippable kill switch, exclusion compliance. Under label-v0's definition, (a) does not exist → not assessed. But the control model is real, sixteen years old, and battle-tested. approval as defined cannot see it.
provenance
Edits platform-attributed with timestamps; no hash binding to a config fingerprint.
audit
a5a-0011
agent
openhands resolver · issue→PR
operator
All Hands AI (own repos)
assessed
2026-08-29 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval verified
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0011 openhands resolver issue→PR

Subject scoped to the resolver as deployed on All Hands' own public repos. Third-party installs have a different operator (whoever holds the workflow and the LLM key) and would need their own label.

identity
PRs from the openhands-agent account; operator resolves to All Hands AI for the scoped deployment.
config
The closest any subject has come in two batches. Uniquely, the declared config and the runtime are the same public artifact: a workflow file pinning open-source resolver code, executed by GitHub Actions, with run logs showing the exact ref while retained. What breaks the pass: Actions logs expire (~90 days) and the LLM behind the run is not attested.
monitoring
PRs and branches public, but the run-level evidence decays with log expiry and the public deployment base is thin.
approval
(a) Resolver opens draft PRs with review auto-requested from the workflow initiator; merge requires a human. (b) Fired gates inspectable on public merged PRs. Evidence base is small (mostly the operator's own repos) — noted, not disqualifying, because every fired gate that exists is public.
provenance
Attribution + hash chain; the workflow-run linkage gives an implicit config binding while logs last — provenance that expires is provenance with a validity window nobody declared.

batch 3 — outside-in

a5a-0012 … a5a-0061 · method: outside-in

57 of 250 claims verified. 193 not assessed. 0 expired. 0 revoked.

Fifty named production agents. Same method, same rules. Eighteen coding products, twelve enterprise, ten consumer, ten public-infrastructure bots. Extra passes still sit with subjects whose ledger belongs to someone else. Ceiling observed: 3 of 5 (Prow/Tide, bors).

audit
a5a-0012
agent
cursor agent · dev ide
operator
Anysphere
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0012 cursor agent dev ide

identity
Product → Anysphere, Inc.; cursor.com, named executives, US entity. Chain resolves.
config
Agent mode, models and repo indexing are per-workspace; no attested fingerprint.
monitoring
Session traces exist for the operator inside the product. Not replayable from outside.
approval
Permission prompts exist in-product. A fired gate is visible only to the operator. (b) fails.
provenance
Edits land as ordinary file changes and commits under the user's identity. No emission-time binding.
audit
a5a-0013
agent
windsurf · dev ide
operator
Cognition
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0013 windsurf dev ide

identity
Windsurf originated at Codeium (Exafunction) and was acquired by Cognition Labs in 2025. Today's operator resolves to Cognition.
config
Cascade and local/indexing settings are customer-side. No public fingerprint of what is running.
monitoring
No outsider-replayable ledger of tool calls.
approval
In-editor confirmations are documented as product behaviour, not as a publicly inspectable gate.
provenance
No hash binding of outputs to agent + config at emission.
audit
a5a-0014
agent
kiro · dev ide
operator
Amazon (AWS)
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0014 kiro dev ide

identity
Kiro is AWS's coding agent (Amazon Q Developer IDE plugin is being wound down into this line). Operator resolves to Amazon.com, Inc. / AWS.
config
Spec-driven and AWS-account-bound settings; no attested deployed fingerprint.
monitoring
CloudTrail and IDE logs are customer-tenant. Not replayable from outside.
approval
IAM and confirmation flows exist per account. Outsiders cannot see a fired gate.
provenance
No public emission-time hash binding.
audit
a5a-0015
agent
gemini cli · dev cli
operator
Google
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no (adverse: assessor's developer competes with operator)
verify
(no registry — v1 rule)

a5a-0015 gemini cli dev cli

identity
Gemini CLI → Google LLC / Alphabet. Domain, entity and accountable executives public.
config
Open-source CLI with local settings; the hosted model behind a run is not attested.
monitoring
Local transcripts stay on the operator machine. No public ledger.
approval
Tool-use confirmations are in-process. Self-operating the subject is inside-out; excluded by method.
provenance
No emission-time hash of CLI output to agent + config.
audit
a5a-0016
agent
junie · jetbrains ide
operator
JetBrains
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0016 junie jetbrains ide

identity
Junie is JetBrains' agentic line inside IntelliJ and sibling IDEs. JetBrains s.r.o., Prague; chain resolves.
config
Per-project AI assistant settings; no attested fingerprint of the running agent.
monitoring
IDE logs are local or JetBrains-account. Not outsider-replayable.
approval
The IDE can prompt before applying patches. Fired gates are not public.
provenance
Patches apply as ordinary editor edits. No emission binding.
audit
a5a-0017
agent
amp · dev agent
operator
Amp (Sourcegraph spin-out)
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0017 amp dev agent

identity
Amp spun out of Sourcegraph (Cody consumer line closed 2025). Operator resolves to the Amp company; parent history is public.
config
Terminal/IDE agent config is per-user. No published fingerprint.
monitoring
No public replayable ledger.
approval
Documented human-in-the-loop is product policy, not an inspectable firing.
provenance
No hash-bound outputs.
audit
a5a-0018
agent
factory droid · autonomous swe
operator
Factory
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0018 factory droid autonomous swe

identity
Factory AI, US entity, public product (droid-team agents). Chain resolves.
config
Org- and repo-level droid config is customer-side.
monitoring
Session views are for the paying operator. Not replayable from outside.
approval
Human review of droid PRs is recommended. Not platform-enforced in a way an outsider can inspect across customers.
provenance
No public emission-time binding.
audit
a5a-0019
agent
replit agent · browser ide
operator
Replit
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0019 replit agent browser ide

identity
Replit, Inc.; replit.com; named leadership. Chain resolves.
config
Repl, model and tool settings are per-repl. No attested fingerprint.
monitoring
Agent traces exist inside the Replit account. Not outsider-replayable.
approval
Deploy/publish can require a click in-product. Not observable from outside.
provenance
Generated apps are not hash-bound to agent + config at emission.
audit
a5a-0020
agent
v0 · ui generate
operator
Vercel
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0020 v0 ui generate

identity
v0 → Vercel Inc.; vercel.com; public entity. Chain resolves.
config
Generation settings and connected repos are per-user. No fingerprint.
monitoring
Generation history is account-visible. No public ledger of tool calls.
approval
Deploy to Vercel is a separate user action, but that is the platform deploy gate, not an attested agent gate with an inspectable firing log.
provenance
UI code is not hash-bound to the generating agent at emission.
audit
a5a-0021
agent
bolt · browser app-build
operator
StackBlitz
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0021 bolt browser app-build

identity
Bolt.new → StackBlitz, Inc. Public product and company. Chain resolves.
config
WebContainer and model choices are session-local. No attested fingerprint.
monitoring
No outsider-replayable tool ledger.
approval
Publish/deploy is a user click in-product. Not a public fired-gate record.
provenance
No emission-time hash binding.
audit
a5a-0022
agent
lovable · text-to-app
operator
Lovable
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0022 lovable text-to-app

identity
Lovable (Sweden); lovable.dev; public company and product. Chain resolves.
config
Project instructions and integrations are per-app. No fingerprint.
monitoring
Build history is customer-visible. Not replayable from outside.
approval
Shipping the app is a user action. No public record that a dangerous tool call waited.
provenance
Generated apps are not bound to agent + config by hash.
audit
a5a-0023
agent
cline · vscode harness
operator
Cline
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0023 cline vscode harness

Subject is the Cline product as shipped by Cline. Bring-your-own-key installs have a different operator (whoever holds the key) and would need their own label.

identity
Cline ships as an open-source VS Code harness with a named company behind the product. Chain resolves for the vendor; third-party installs would not.
config
The repo is public; that is source, not an attested running version plus model.
monitoring
Transcripts stay in the user's editor. No public ledger.
approval
Auto-approve vs confirm-every-tool is a user setting. Policy without a public firing is untested from outside.
provenance
Edits are ordinary workspace diffs. No emission binding.
audit
a5a-0024
agent
aider · dev cli
operator
named maintainer (Paul Gauthier)
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0024 aider dev cli

identity
Aider is an open-source CLI with a named author and public repo. Accountability is reputational, like ClueBot — the chain resolves to a responsible human, not a notarised entity of scale.
config
Local flags and model settings; nothing attests which commit a given user ran.
monitoring
Local chat history only. No public ledger.
approval
Git commit/diff review is the user's. No platform-enforced gate an outsider can inspect.
provenance
Commits are the user's. No agent-bound hash at emission.
audit
a5a-0025
agent
goose · dev agent
operator
Block
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0025 goose dev agent

identity
Goose is Block's (Square) open-source agent. Operator resolves to Block, Inc.
config
Recipes, recipes.yaml and local extensions are per-deploy. No attested fingerprint.
monitoring
Local session logs. Not outsider-replayable.
approval
Desktop permission prompts exist. Fired gates are not public.
provenance
No emission-time binding of outputs to agent + config.
audit
a5a-0026
agent
coderabbit · pr review
operator
CodeRabbit
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0026 coderabbit pr review

identity
CodeRabbit, Inc.; GitHub App publicly listed. Chain resolves.
config
Per-repo yaml and dashboard settings; no fingerprint of the running reviewer.
monitoring
Review comments on public PRs are enumerable — the final note, not the run. Not a ledger of tool calls.
approval
The bot reviews; humans merge. That is the right shape of (a), but whether merge protection is on is per-repo, so at product scope (a) is conditional.
provenance
Comments are platform-attributed. No hash binding to a config fingerprint.
audit
a5a-0027
agent
vscode agent mode · dev ide
operator
Microsoft
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0027 vscode agent mode dev ide

identity
VS Code agent mode → Microsoft. Distinct from GitHub Copilot coding agent (a5a-0002). Chain resolves.
config
Workspace and Copilot Chat settings are local. No attested fingerprint.
monitoring
No public replayable ledger of agent tool calls.
approval
Confirmation for terminal/tools exists in-product. Not inspectable from outside.
provenance
Edits apply in the workspace under the user. No emission binding.
audit
a5a-0028
agent
tabnine · dev assistant
operator
Tabnine
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0028 tabnine dev assistant

identity
Tabnine; public company and trust centre; self-host option documented. Chain resolves.
config
Self-host vs SaaS is the point of the product — and that is why there is no single public fingerprint.
monitoring
Enterprise logs stay in the customer's deployment. Not outsider-replayable.
approval
Policy controls exist for enterprise admins. Fired gates are not public.
provenance
Completions are not hash-bound at emission.
audit
a5a-0029
agent
continue · ide harness
operator
Continue.dev
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0029 continue ide harness

identity
Continue.dev; open-source IDE extension with a named company. Chain resolves for the vendor product.
config
config.yaml is local and often public in a repo, but the runtime model is whatever key the user attached. Public source ≠ attested running version.
monitoring
Local session only.
approval
User-level allowlists. Not a public fired gate.
provenance
No emission-time binding.
audit
a5a-0030
agent
microsoft 365 copilot · workplace
operator
Microsoft
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0030 microsoft 365 copilot workplace

identity
Microsoft 365 Copilot → Microsoft. Chain resolves. The tenant operator is each customer — this label covers the platform, not each tenant's agent.
config
Grounding, plugins and DLP are tenant-configured.
monitoring
Purview / audit logs are tenant-visible. Not replayable from outside.
approval
Admin policies can require confirmation or block connectors. Wiring is per-tenant, so (a) is conditional at platform scope.
provenance
Generated mail, docs and chat are not hash-bound to agent + config.
audit
a5a-0031
agent
copilot studio · custom agents
operator
Microsoft
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0031 copilot studio custom agents

identity
Copilot Studio → Microsoft. Chain resolves. Each published agent has a different tenant operator.
config
Topics, tools and channels are author-defined. The platform cannot be fingerprinted as one agent.
monitoring
Transcripts in the maker portal. Not outsider-replayable.
approval
Authentication and human-handoff are optional maker settings.
provenance
No emission-time hash of agent replies.
audit
a5a-0032
agent
servicenow ai agents · itsm
operator
ServiceNow
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0032 servicenow ai agents itsm

identity
ServiceNow, Inc.; public company. Chain resolves. Tenant operators are the customers running Now Assist / AI agents.
config
Now Assist skills and tool access are instance-configured.
monitoring
Instance logs. Not public.
approval
Change and approval workflows exist in the platform; whether an AI agent is wired through them is per-instance.
provenance
Tickets and actions are not hash-bound to the agent run.
audit
a5a-0033
agent
intercom fin · support
operator
Intercom
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0033 intercom fin support

identity
Fin → Intercom; public entity. AIUC-1 appears on Intercom's marketing. That is an organisational/product cert, not a deployment fingerprint, and it does not move any a5a claim.
config
Fin's knowledge, actions and escalation are per-workspace.
monitoring
Inbox transcripts are workspace-visible. Not outsider-replayable.
approval
Escalation to a human is configurable. Whether it fired on a given answer is not public.
provenance
Customer replies are not hash-bound at emission.
audit
a5a-0034
agent
zendesk ai agents · support
operator
Zendesk
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0034 zendesk ai agents support

identity
Zendesk, Inc. Chain resolves. Each customer's AI agent is a different deployment.
config
Procedures, tools and brand voice are admin-configured.
monitoring
Ticket audits are tenant-visible.
approval
Handoff rules exist; firing is not publicly inspectable.
provenance
No emission-time binding of agent replies.
audit
a5a-0035
agent
sierra · customer agent
operator
Sierra
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0035 sierra customer agent

identity
Sierra AI; sierra.ai; named founders; US entity. Chain resolves.
config
Customer-specific Agent OS configs. No public fingerprint.
monitoring
Enterprise traces stay with the customer. Not public.
approval
Escalation is a selling point and a per-customer wiring. Not inspectable from outside.
provenance
No public hash binding of conversations.
audit
a5a-0036
agent
harvey · legal
operator
Harvey
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0036 harvey legal

identity
Harvey AI, Inc.; legal-AI assistant. Chain resolves.
config
Matter, vault and model settings are customer-side and usually under NDA.
monitoring
Firm-visible audit trails, if any, are not public. Outside-in stops at the NDA.
approval
Attorney review is professional duty, not a platform gate an outsider can see fire.
provenance
Work product is not hash-bound to the agent run.
audit
a5a-0037
agent
glean assistant · workplace search
operator
Glean
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0037 glean assistant workplace search

identity
Glean Technologies; public company/product. Chain resolves.
config
Connectors, permissions and agents are tenant-configured.
monitoring
Admin logs are tenant-visible. Not public.
approval
Write actions (drafts, tickets) depend on which tools the tenant enabled.
provenance
Answers are not hash-bound at emission.
audit
a5a-0038
agent
notion agent · workspace
operator
Notion
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0038 notion agent workspace

identity
Notion Labs; notion.so. Chain resolves.
config
Custom agents, connected apps and page access are workspace-configured.
monitoring
No public ledger of agent edits across a workspace.
approval
Page permissions are the control; they are not a per-action agent gate with a public firing.
provenance
Page edits are attributed to a user/integration, not hash-bound to agent + config.
audit
a5a-0039
agent
hubspot breeze · crm
operator
HubSpot
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0039 hubspot breeze crm

identity
Breeze → HubSpot, Inc. Chain resolves.
config
Breeze agents, CRM properties and send-from identities are portal-configured.
monitoring
Portal audit logs. Not public.
approval
Sending email or updating records can require a user; that wiring is per-portal.
provenance
CRM writes are not hash-bound to the agent run.
audit
a5a-0040
agent
uipath agents · automation
operator
UiPath
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0040 uipath agents automation

identity
UiPath, Inc.; public company. AIUC-1 appears in UiPath materials — organisational cert, not a per-agent fingerprint. Does not move these claims.
config
Orchestrator processes, robots and agent tools are customer-tenant.
monitoring
Orchestrator logs are tenant-visible. Not public.
approval
Human-in-the-loop activities exist in the product. Whether they are used is per-process.
provenance
Job output is not hash-bound to agent + config at emission.
audit
a5a-0041
agent
sap joule · erp copilot
operator
SAP
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0041 sap joule erp copilot

identity
Joule → SAP SE. Chain resolves. Each customer's Joule is a different deployment.
config
Grounding, business roles and Joule skills are tenant-configured.
monitoring
BTP / audit logs are customer-visible.
approval
Business-user authorizations are the gate; not a public agent-firing record.
provenance
No emission-time hash of Joule outputs.
audit
a5a-0042
agent
claude.ai · consumer
operator
Anthropic
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
YES — assessor is an Anthropic model. Weight accordingly.
verify
(no registry — v1 rule)

a5a-0042 claude.ai consumer

identity
claude.ai → Anthropic PBC. Entity, domain, leadership public. Same ceiling as a5a-0003: related party got no extra claims.
config
Projects, tools, connectors and memory are per-account. No attested fingerprint of a given chat.
monitoring
Chat transcripts are user-visible. No public replayable ledger.
approval
Connectors and computer-use confirmations exist in-product. Fired gates are not public.
provenance
Replies are not hash-bound at emission. (The related-party line did not buy a pass.)
audit
a5a-0043
agent
gemini · consumer
operator
Google
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no (adverse: assessor's developer competes with operator)
verify
(no registry — v1 rule)

a5a-0043 gemini consumer

identity
Gemini app / gemini.google.com → Google LLC. Chain resolves.
config
Apps, extensions and Workspace grounding are per-account.
monitoring
No public ledger of tool calls.
approval
Some extensions ask; firings are not public.
provenance
Replies are not hash-bound at emission.
audit
a5a-0044
agent
grok · consumer
operator
xAI
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no (adverse: assessor's developer competes with operator)
verify
(no registry — v1 rule)

a5a-0044 grok consumer

identity
Grok → xAI; x.com / grok.x.ai. Legal entity and named principal public. Chain resolves.
config
Grok vs Grok with tools/search is account- and surface-dependent (X vs grok.com vs Tesla). No single fingerprint.
monitoring
No public tool-call ledger.
approval
Autonomous posting on X, where enabled, is the opposite of a mandatory gate. (a) fails at that surface. Other surfaces are unobservable.
provenance
Posts and replies are not hash-bound to agent + config.
audit
a5a-0045
agent
perplexity · answer engine
operator
Perplexity
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0045 perplexity answer engine

identity
Perplexity AI, Inc. Chain resolves.
config
Model, focus, attachments and connectors are per-thread. No fingerprint.
monitoring
Cited sources are visible; that is a bibliography, not a tool-call ledger.
approval
Search is the product; there is no public mandatory gate before a lookup.
provenance
Answers cite URLs; they are not hash-bound to agent + config.
audit
a5a-0046
agent
meta ai · consumer
operator
Meta
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0046 meta ai consumer

identity
Meta AI → Meta Platforms, Inc. Chain resolves.
config
WhatsApp, Instagram, Facebook and meta.ai are different surfaces with different tools.
monitoring
No public ledger.
approval
Messaging surfaces do not expose a fired human gate to outsiders.
provenance
No emission-time binding.
audit
a5a-0047
agent
microsoft copilot · consumer
operator
Microsoft
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0047 microsoft copilot consumer

identity
Copilot (copilot.microsoft.com / Bing) → Microsoft. Distinct from M365 Copilot (a5a-0030) and GitHub Copilot (a5a-0002). Chain resolves.
config
Consumer vs work account, plugins and voice are per-user.
monitoring
No public tool ledger.
approval
Some actions ask; not publicly inspectable.
provenance
Replies are not hash-bound.
audit
a5a-0048
agent
le chat · consumer
operator
Mistral
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0048 le chat consumer

identity
Le Chat → Mistral AI; French entity; chat.mistral.ai. Chain resolves.
config
Model, agents and tools are per-account. No fingerprint.
monitoring
No public ledger.
approval
Tool use is in-product. Fired gates not public.
provenance
No emission-time hash.
audit
a5a-0049
agent
deepseek · consumer
operator
DeepSeek
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0049 deepseek consumer

identity
DeepSeek → Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; chat.deepseek.com. Chinese operating entity is named and the domain is controlled. Chain resolves at entity level.
config
Chat vs coder vs reasoner modes; no attested fingerprint.
monitoring
No public ledger.
approval
No documented mandatory gate visible from outside.
provenance
No emission-time binding.
audit
a5a-0050
agent
elevenlabs agents · voice
operator
ElevenLabs
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0050 elevenlabs agents voice

identity
ElevenLabs; conversational/voice agents. Chain resolves. AIUC-1 appears in their materials — org cert, not a per-agent fingerprint.
config
Voice, tools, workflow and phone numbers are per-agent in the console.
monitoring
Call recordings/transcripts are workspace-visible. Not public.
approval
Tool calls (calendar, CRM) are author-configured. No public firing log.
provenance
Audio is the product and is not hash-bound to agent + config at emission in a way a stranger can recompute.
audit
a5a-0051
agent
comet · browser agent
operator
Perplexity
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0051 comet browser agent

identity
Comet is Perplexity's agentic browser. Operator resolves to Perplexity AI, Inc. Distinct from the answer engine (a5a-0045).
config
Browser permissions and site access are user-local. No attested fingerprint.
monitoring
No public ledger of page actions.
approval
Browser permission prompts exist. Fired gates are not public.
provenance
Page actions and generated text are not hash-bound.
audit
a5a-0052
agent
renovate[bot] · dep updates
operator
Mend
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0052 renovate[bot] dep updates

identity
renovate[bot] → GitHub App → Mend (formerly WhiteSource / Renovate). Entity-level chain resolves.
config
renovate.json is often public, and behaviour is diffable against it. Hosted runtime is not attested — same miss as Dependabot (a5a-0009).
monitoring
Every action lands as a public PR, commit and branch. Replay: pick a renovate[bot] PR, read the manifest diff, check the registry. Same caveats as Dependabot: the ledger is the target repo, admins can force-push, internals stay closed.
approval
Automerge is optional per-repo. A gate the deployer can silently remove is (a)-conditional at product scope.
provenance
Commits attributed and hash-chained; no config fingerprint in the binding.
audit
a5a-0053
agent
mergify[bot] · merge queue
operator
Mergify
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0053 mergify[bot] merge queue

identity
mergify[bot] → Mergify SAS (France). GitHub App publicly listed. Chain resolves.
config
.mergify.yml is often public. Hosted merge-queue runtime is not attested.
monitoring
Queue comments and merges on public repos are visible — the decision, not the engine. Not a tool-call ledger.
approval
The product's job is to merge when rules match, which can be zero extra humans. (a) is the yaml, and yaml can drop the human. Conditional at product scope.
provenance
Merges attributed to the bot; no config fingerprint in the binding.
audit
a5a-0054
agent
imgbot · image optimize
operator
Imgbot
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0054 imgbot image optimize

identity
Imgbot GitHub App; imgbot.net; named operator. Chain resolves.
config
Per-repo settings exist; hosted compressor is closed. No fingerprint.
monitoring
Every run that matters is a public PR with before/after image diffs. Replay the PR. Same ledger-is-the-repo caveat as Dependabot.
approval
Human merge by default unless the repo automerges. Conditional at product scope.
provenance
PR commits attributed; no config fingerprint.
audit
a5a-0055
agent
codecov[bot] · coverage
operator
Codecov (Sentry)
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0055 codecov[bot] coverage

identity
codecov[bot] → Codecov, now part of Sentry. GitHub App listed. Chain resolves.
config
codecov.yml may be public; the coverage worker is hosted and unattested.
monitoring
Status checks and PR comments are public. They are a result, not a replayable run of the agent.
approval
The bot comments; it does not merge. Merge protection is per-repo.
provenance
Coverage numbers are not hash-bound to a config fingerprint an outsider can recompute from the comment alone.
audit
a5a-0056
agent
sonarcloud[bot] · code quality
operator
SonarSource
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0056 sonarcloud[bot] code quality

identity
SonarCloud → SonarSource S.A. GitHub App listed. Chain resolves.
config
Quality profiles are org-configured. Hosted analyzer unattested.
monitoring
PR decorations are public results, not a replayable analyzer ledger.
approval
Quality-gate can block merge if the repo requires the check. That wiring is per-repo, so (a) is conditional at product scope.
provenance
Findings are not hash-bound to analyzer version + config in the GitHub comment.
audit
a5a-0057
agent
snyk[bot] · vuln prs
operator
Snyk
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0057 snyk[bot] vuln prs

identity
snyk[bot] → Snyk Ltd. GitHub App listed. Chain resolves.
config
Org policies and .snyk files may be public; the scanner runtime is not.
monitoring
PRs and issues on public repos are visible. Result, not a replayable scan ledger.
approval
Opening a fix PR is not merging it. Merge remains per-repo.
provenance
No config fingerprint in the commit binding.
audit
a5a-0058
agent
prow / tide · k8s ci merge
operator
Kubernetes (CNCF)
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval verified
  • provenance not assessed

3 claims verified. 2 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0058 prow / tide k8s ci merge

Subject scoped to Prow/Tide as operated on kubernetes/kubernetes and sibling kubernetes org repos. Other Prow installs have a different operator.

identity
Prow/Tide on kubernetes org repos → Kubernetes project under CNCF / Linux Foundation, with named SIG contributors and public governance. Chain resolves for this scoped deployment.
config
config.yaml and plugins.yaml are public. The running Prow images and tide SHA are not hash-attested as the live set.
monitoring
prow.k8s.io plus GitHub comments (lgtm, tide, test results) form a public, replayable job log. Pick a PR, open the Prow job, read the log while retained. Logs are not cryptographically append-only and they expire — same class of caveat as Dependabot.
approval
(a) OWNERS + /lgtm + /approve + required tests, documented. (b) Fired gates are public: labels, reviewer identities, Tide merge commits. Human review is the authorized OWNERS reviewer, not a silent automerge.
provenance
Merge commits are hash-chained. Missing: config fingerprint of the Tide instance that merged.
audit
a5a-0059
agent
ofborg · nixpkgs eval
operator
NixOS
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring not assessed
  • approval not assessed
  • provenance not assessed

1 claim verified. 4 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0059 ofborg nixpkgs eval

identity
ofborg → NixOS community / NixOS Foundation, named maintainers, public GitHub app/bot on nixpkgs. Chain resolves.
config
ofborg source is public. Which revision runs in the build farm is not attested.
monitoring
GitHub comments report eval results — the outcome, not the builder VM. Not a ledger of the run.
approval
ofborg does not merge nixpkgs. Human committers merge. That is the right shape, but it is the project's merge policy, not a gate ofborg itself enforces.
provenance
Comments attributed; no config fingerprint.
audit
a5a-0060
agent
bors · merge bot
operator
rust-lang
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval verified
  • provenance not assessed

3 claims verified. 2 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0060 bors merge bot

Subject scoped to bors as used on rust-lang/rust. Other bors-ng installs have a different operator.

identity
bors on rust-lang/rust → rust-lang org / Rust Foundation, named infrastructure team, public bot account. Chain resolves for this scoped deployment.
config
bors.toml / homu config is public. Hosted homu revision is not attested.
monitoring
Every try/merge is a public comment plus a rollup PR. Replay: pick a rust-lang/rust PR, read the bors comments and the merge commit. The ledger is the repo.
approval
(a) r+ from an authorized reviewer is required; bors will not merge without it. (b) Fired r+ comments are public, reviewer identities resolvable. Structural enforcement, same class as Copilot's copilot/ branch + human merge.
provenance
Merge commits hash-chained and bot-attributed; no config fingerprint of homu.
audit
a5a-0061
agent
automoderator · reddit mod
operator
Reddit
assessed
2026-09-05 · mock, not issued
  • identity verified
  • config not assessed
  • monitoring verified
  • approval not assessed
  • provenance not assessed

2 claims verified. 3 not assessed. Details below.

related-party
no
verify
(no registry — v1 rule)

a5a-0061 automoderator reddit mod

Subject is Reddit's platform AutoModerator, not a volunteer Python bot a subreddit might also name AutoModerator.

identity
AutoModerator → Reddit, Inc. Platform bot, named in Reddit docs. Chain resolves.
config
Each subreddit's automod yaml is often public. The platform runtime is not attested, and yaml is per-subreddit — a fingerprint-vs-live check still fails.
monitoring
Actions land as public comments, removals and mod-log entries on the subreddit. Replay a removal: permalink, before/after, timestamp. Caveat: mods can remove the evidence; not cryptographically append-only. Same class as ClueBot (a5a-0010).
approval
Autonomous by design, like ClueBot. Compensating controls (mod-log, human mods, un-remove) exist. Under label-v0, no per-action human gate → not assessed.
provenance
Comments attributed and timestamped; no hash binding to a config fingerprint.

closed status list · no aggregate

  • verified — evidence held
  • expired — evidence held, validity lapsed
  • revoked — withdrawn by ledger event
  • not assessed — no evidence held

The list is closed. There is no fifth status and no aggregate of these four. Documented is not verified, and partial passes do not round up.

  • identity

    who is behind this agent?

    what kills it: anonymous or shared credentials; an operator that cannot be resolved

  • config

    is what is running what they said?

    what kills it: silent drift; granted permissions wider than the job needs

  • monitoring

    does anyone watch it run?

    what kills it: gaps, editable logs, monitoring switched on for audit day

  • approval

    does a human hold the dangerous lever?

    what kills it: an irreversible action with no approval; rubber-stamp approvals

  • provenance

    did this output really come from this agent?

    what kills it: a hash minted after the fact; emission outside the monitored window

  • Not a certificate. a5a issues no badge and no pass mark.
  • Not a score. The claims are atomic and are never rolled into a number, a tier, or a set of stars.
  • Not a statement that an agent is safe. The label records what was checked and what was not.
  • Not a ranking. Outside-in assessments share a low ceiling by method; a low count reflects what public evidence can reach, not the quality of the agent.
  • Not a registry. Verification pointers resolve once obvio.id exists; until then a label is only as good as the party that wrote it, which is why the related-party line is mandatory.

a5a, SQRL and Obversio are commonly owned. Disclosed on every label, every time.

Have an agent in production?

One named agent, one run, one pack a second-line reader can check.