Skip to main content

Platform truth table — what actually enforces, where

Every derived cell is produced from package metadata or exported code. PREVENTS means the action physically cannot proceed on that path. REPORTS means the result is visible while merge or deploy can still proceed. INSTRUCTS means durable guidance the agent reads; it is not enforcement. MANAGED_REACH means an org setting reaches every managed machine and locks the hook layer; a shell path around it is not seen, so it stops nothing alone. The fourth column names the switch in either direction — the one that turns reporting into prevention, or prevention into reporting.

Shipped packages (derived): sdk 3.14.3, prove 0.1.13, conformance 0.8.11, release-acceptance 1.0.5, guard 17.3.6, cli 8.7.4, gate v0.11.4, python-sdk 3.8.2, receipt-verifier v1.1.0. Server-derived change-set platforms (derived from src/scm/platforms.js): github, gitlab, bitbucket.

Conformance (derived): END_TO_END COVERED (7/7).

See What each path does — and does not.

Atomic-stack packages (checkout vs published)

Package npm/PyPI/git name Checkout Published Drift
clicoderifts8.7.48.7.4no
guard@coderifts/agent-guard17.3.617.3.6no
sdk@coderifts/sdk3.14.33.14.3no
pythoncoderifts-sdk3.8.23.8.2no
gatecoderifts/contract-gate0.11.40.11.4no
conformance@coderifts/conformance0.8.110.8.11no
prove@coderifts/prove0.1.130.1.13no

Conformance assurance profiles

Profile Status runnable / present
DECISION_LOGICCOVERED15 / 15
RECEIPT_CRYPTOCOVERED16 / 16
GUARDED_TOOL_TABLECOVERED6 / 6
CREDENTIAL_BOUNDARYCOVERED4 / 4
ATOMIC_COMMITCOVERED6 / 6
PROVIDER_ENFORCEDCOVERED7 / 7
END_TO_ENDCOVERED2 / 2
Surface What it gates Default With opt-in / opt-out How to enable
Claude Code — PreToolUse hookContract-touching Write/Edit/MultiEdit at tool-call timePREVENTS (exit 2; fail-closed / enforce_indeterminate when governance cannot run)CODERIFTS_ADVISORY=1 restores soft-allow on “could not run” sitescoderifts agent-setup writes .claude/settings.json
Claude Code — MCP pluginpreflight/verify/details as toolsREPORTS (decision surface)—plugin install (3 canonical tools)
MCP — advanced tools (not default)agent_readiness_score — callable always, listed only on opt-inNOT LISTED by default (3 canonical only)listed when the request passes include_advanced_tools — a per-request flag on tools/list, not an environment variableoutside the wire digest: tools_sha256 is taken over the tools[] the anchored profile receives, and that profile sends no params
OpenAI / Codex — dispatcherEvery registered mutating tool call—PREVENTS (proof-bound return; BLOCK → raw function does not run)withCodeRiftsOpenAI + executeOpenAIToolCall loop
Anthropic / Gemini / LangGraph — dispatcherSame, framework-native faces—PREVENTSexecute*ToolCall wrappers
GitHub App — CodeRifts / issuerPR contract check posted by the GitHub AppREPORTS (phase-1 conclusion clamped to neutral; MERGEGATE_ENFORCE default false)PREVENTS when MERGEGATE_ENFORCE=true → conclusion may be failureApp install + MERGEGATE_ENFORCE
GitHub Action — CodeRifts / contract-gatecoderifts/contract-gate GitHub Action check (the reader; a different name from the App)REPORTS (posts a real check conclusion; merge is not blocked until the check is required)PREVENTS when configured as a required check (issuer-bound, not name-only)coderifts init --agents then require the check
Deploy gateDeploying an artifact whose receipt is stale/mismatched/unverifiedPREVENTS (fail-closed since CLI 4.3.0; verifies the signed receipt since 4.4.0; exit 1 on deny)CODERIFTS_DEPLOY_ADVISORY=1 (or CODERIFTS_ADVISORY=1) → advisory, exit 0coderifts deploy-gate in the deploy job
Publish gatenpm prepublishOnly / coderifts publish-gatePREVENTS (exit 1 on BLOCK/STOP or resolver error)—coderifts publish-gate in npm prepublishOnly
git pre-push hookPushing spec changes without authorizationPREVENTS (BLOCK/STOP → exit 1 when the hook is installed)—coderifts hook install
Rule files (6 platforms)Agent knows when/how to consult CodeRiftsINSTRUCTS—coderifts agent-setup
Claude Code — managed (org)Whether the org can put the CodeRifts hook and decision surface on every developer's machine and keep users from replacing the hook (managed-settings.json: hooks + allowManagedHooksOnly, permissions.deny, managedMcpServers)MANAGED_REACH (reaches the fleet, locks at hook level, does not see a bypass)—a managed settings source (file measured 2026-09-27, Claude Code 2.1.283) — docs/managed-mcp-protocol.md
MCP server (hosted)analyze = information only; authorize = receipt issuanceREPORTS + issues receipts(feeds every PREVENTS path above)app.coderifts.com/mcp

Boundary

Prevention holds inside the wired boundary — a host that bypasses the guarded table, uninstalls the hook, or merges on a repository without the required check is outside it, and the proofs say so rather than pretending otherwise.

Derived vs prose

This page is generated from the frozen release-set (packages/release-acceptance/fixtures/CURRENT) plus the app repository (src/generated/release-manifest.json, rendered by scripts/generate-truth-table-html.js) and gated byte-for-byte in freeze-gate check 1. Package versions come from the frozen digest; enforcement rows, the platform list, the deploy-gate default, the merge check name and the MERGEGATE_ENFORCE default are derived from code. The two lines below are prose — product readings rather than constants, each carrying its own review date, and they are carried through rather than generated.

Frozen digest sha256:69d45710350d87e661262492fa10a55b242734f47b05845726d105dc3c429345. Derived enforcement rows from release manifest commit 502695e28a90b30d66923f6710ba13c6972b5beb (last --out of the manifest, not current HEAD).

What COVERED means, and where it stops

Every row above reads COVERED, and none of them carries the axis that says how. That axis exists in the tool and was missing here. Measured 2026-09-17 by running npx @coderifts/conformance --assurance <PROFILE> once per profile:

DECISION_LOGICLIVE15 vectors
RECEIPT_CRYPTORECORDED16 vectors
GUARDED_TOOL_TABLELIVE6 vectors
CREDENTIAL_BOUNDARYRECORDED4 vectors
ATOMIC_COMMITRECORDED6 vectors
PROVIDER_ENFORCEDRECORDED7 vectors
END_TO_ENDRECORDED2 vectors

COVERED means the vectors exist, run, and pair positive with negative — or, for a recorded profile, that the pinned artifact’s panels hold. It does not mean the shipped guard ran. Measured on the shipped package: lib/assurance-profiles.js requires neither @coderifts/agent-guard nor @coderifts/sdk, so no profile on this table executes the shipped guard. The subject that does (--subject agent-guard) runs on a different path, and the --subject flag is ignored when --assurance is given.

GUARDED_TOOL_TABLE is the sharpest case. Its six vectors are five conformance cases plus one adversarial test. Measured 2026-09-17, those five — AA-DOCS-ONLY-SKIP, AA-CONTRACT-CHANGE-PREFLIGHT, AA-RECEIPT-CARRY-VERIFY, AA-RECEIPT-WRONG-SCOPE-REPREFLIGHT, AA-AUTHORIZE-NEEDS-OPERATION — are exactly the five the shipped guard’s own subject does not answer. The reference subject answers 16 cases; the agent-guard subject answers 11, and the five it drops are this profile.

RECEIPT_CRYPTO verifies pinned token bytes produced by the receipt verifier, using a separate implementation on purpose — so a future verifier rewrite cannot silently agree with itself. It measures the format, deliberately not the shipped verifier’s own code path.

PROVIDER_ENFORCED needs its own sentence, because the name says enforced without saying by whom. The provider is GitHub. We do not operate a merge provider. The evidence is raw GitHub API dumps, and the profile’s own boundary says it does not prove that GitHub signed those payloads — they are API responses, not GitHub-signed objects.

ATOMIC_COMMIT and CREDENTIAL_BOUNDARY are the six and four panels of one pinned, signed prove transcript (run prove-fb5c23bd). A recorded panel holding is not the same as the shipped guard consuming a nonce — see what makes a grant single-use.

Conformance END_TO_END (7/7)

The generated table above is the enforcement map. The public assurance claim sits beside it: @coderifts/conformance@0.8.11 reports every profile COVERED, including END_TO_END (7/7), via TARGET_STATE_TRANSITION_PROVEN — a governed ref moved to the authorized commit under a signed grant, observed afterwards by a separate read-only process.

Boundary, exactly as the profile records it: proof_scope TRUSTED_EXECUTOR, provider_witness NOT_APPLICABLE, externally_witnessed false. Trusted-executor-integrity, not a provider merge (PATH B), not externally witnessed. CodeRifts did not witness or sign the provider state. The GitHub positive provider-loop is a separate claim: provider canary. Honesty table: What each proof proves. Derived profile rows: atomic-stack.json. Replay: VERIFY.md. Gate today vs roadmap (not available): claim table.