Platform truth table — what actually enforces, where
Every derived cell is produced from package metadata or exported code. PREVENTS means the action physically cannot proceed on that path. REPORTS means the result is visible while merge or deploy can still proceed. INSTRUCTS means durable guidance the agent reads; it is not enforcement. MANAGED_REACH means an org setting reaches every managed machine and locks the hook layer; a shell path around it is not seen, so it stops nothing alone. The fourth column names the switch in either direction — the one that turns reporting into prevention, or prevention into reporting.
Shipped packages (derived): sdk 3.14.3, prove 0.1.13, conformance 0.8.11, release-acceptance 1.0.5, guard 17.3.6, cli 8.7.4, gate v0.11.4, python-sdk 3.8.2, receipt-verifier v1.1.0. Server-derived change-set platforms (derived from src/scm/platforms.js): github, gitlab, bitbucket.
Conformance (derived): END_TO_END COVERED (7/7).
See What each path does — and does not.
Atomic-stack packages (checkout vs published)
| Package | npm/PyPI/git name | Checkout | Published | Drift |
|---|---|---|---|---|
| cli | coderifts | 8.7.4 | 8.7.4 | no |
| guard | @coderifts/agent-guard | 17.3.6 | 17.3.6 | no |
| sdk | @coderifts/sdk | 3.14.3 | 3.14.3 | no |
| python | coderifts-sdk | 3.8.2 | 3.8.2 | no |
| gate | coderifts/contract-gate | 0.11.4 | 0.11.4 | no |
| conformance | @coderifts/conformance | 0.8.11 | 0.8.11 | no |
| prove | @coderifts/prove | 0.1.13 | 0.1.13 | no |
Conformance assurance profiles
| Profile | Status | runnable / present |
|---|---|---|
DECISION_LOGIC | COVERED | 15 / 15 |
RECEIPT_CRYPTO | COVERED | 16 / 16 |
GUARDED_TOOL_TABLE | COVERED | 6 / 6 |
CREDENTIAL_BOUNDARY | COVERED | 4 / 4 |
ATOMIC_COMMIT | COVERED | 6 / 6 |
PROVIDER_ENFORCED | COVERED | 7 / 7 |
END_TO_END | COVERED | 2 / 2 |
| Surface | What it gates | Default | With opt-in / opt-out | How to enable |
|---|---|---|---|---|
| Claude Code — PreToolUse hook | Contract-touching Write/Edit/MultiEdit at tool-call time | PREVENTS (exit 2; fail-closed / enforce_indeterminate when governance cannot run) | CODERIFTS_ADVISORY=1 restores soft-allow on “could not run” sites | coderifts agent-setup writes .claude/settings.json |
| Claude Code — MCP plugin | preflight/verify/details as tools | REPORTS (decision surface) | — | plugin install (3 canonical tools) |
| MCP — advanced tools (not default) | agent_readiness_score — callable always, listed only on opt-in | NOT LISTED by default (3 canonical only) | listed when the request passes include_advanced_tools — a per-request flag on tools/list, not an environment variable | outside the wire digest: tools_sha256 is taken over the tools[] the anchored profile receives, and that profile sends no params |
| OpenAI / Codex — dispatcher | Every registered mutating tool call | — | PREVENTS (proof-bound return; BLOCK → raw function does not run) | withCodeRiftsOpenAI + executeOpenAIToolCall loop |
| Anthropic / Gemini / LangGraph — dispatcher | Same, framework-native faces | — | PREVENTS | execute*ToolCall wrappers |
GitHub App — CodeRifts / issuer | PR contract check posted by the GitHub App | REPORTS (phase-1 conclusion clamped to neutral; MERGEGATE_ENFORCE default false) | PREVENTS when MERGEGATE_ENFORCE=true → conclusion may be failure | App install + MERGEGATE_ENFORCE |
GitHub Action — CodeRifts / contract-gate | coderifts/contract-gate GitHub Action check (the reader; a different name from the App) | REPORTS (posts a real check conclusion; merge is not blocked until the check is required) | PREVENTS when configured as a required check (issuer-bound, not name-only) | coderifts init --agents then require the check |
| Deploy gate | Deploying an artifact whose receipt is stale/mismatched/unverified | PREVENTS (fail-closed since CLI 4.3.0; verifies the signed receipt since 4.4.0; exit 1 on deny) | CODERIFTS_DEPLOY_ADVISORY=1 (or CODERIFTS_ADVISORY=1) → advisory, exit 0 | coderifts deploy-gate in the deploy job |
| Publish gate | npm prepublishOnly / coderifts publish-gate | PREVENTS (exit 1 on BLOCK/STOP or resolver error) | — | coderifts publish-gate in npm prepublishOnly |
| git pre-push hook | Pushing spec changes without authorization | PREVENTS (BLOCK/STOP → exit 1 when the hook is installed) | — | coderifts hook install |
| Rule files (6 platforms) | Agent knows when/how to consult CodeRifts | INSTRUCTS | — | coderifts agent-setup |
| Claude Code — managed (org) | Whether the org can put the CodeRifts hook and decision surface on every developer's machine and keep users from replacing the hook (managed-settings.json: hooks + allowManagedHooksOnly, permissions.deny, managedMcpServers) | MANAGED_REACH (reaches the fleet, locks at hook level, does not see a bypass) | — | a managed settings source (file measured 2026-09-27, Claude Code 2.1.283) — docs/managed-mcp-protocol.md |
| MCP server (hosted) | analyze = information only; authorize = receipt issuance | REPORTS + issues receipts | (feeds every PREVENTS path above) | app.coderifts.com/mcp |
Boundary
Prevention holds inside the wired boundary — a host that bypasses the guarded table, uninstalls the hook, or merges on a repository without the required check is outside it, and the proofs say so rather than pretending otherwise.
Derived vs prose
This page is generated from the frozen release-set (packages/release-acceptance/fixtures/CURRENT) plus the app repository (src/generated/release-manifest.json, rendered by scripts/generate-truth-table-html.js) and gated byte-for-byte in freeze-gate check 1. Package versions come from the frozen digest; enforcement rows, the platform list, the deploy-gate default, the merge check name and the MERGEGATE_ENFORCE default are derived from code. The two lines below are prose — product readings rather than constants, each carrying its own review date, and they are carried through rather than generated.
- Prose (review 2026-08-25): the Boundary statement above. (product honesty line, not a code constant)
- Prose (review 2026-08-25): MCP analyze is informational (not permission); authorize may mint a receipt. The three canonical tools do not themselves prevent a call. (protocol meaning; the schemas encode it but the “does not prevent by itself” sentence is a product reading)
Frozen digest sha256:69d45710350d87e661262492fa10a55b242734f47b05845726d105dc3c429345. Derived enforcement rows from release manifest commit 502695e28a90b30d66923f6710ba13c6972b5beb (last --out of the manifest, not current HEAD).
What COVERED means, and where it stops
Every row above reads COVERED, and none of them
carries the axis that says how. That axis exists in the tool and was missing here.
Measured 2026-09-17 by running npx @coderifts/conformance --assurance <PROFILE>
once per profile:
DECISION_LOGIC | LIVE | 15 vectors |
RECEIPT_CRYPTO | RECORDED | 16 vectors |
GUARDED_TOOL_TABLE | LIVE | 6 vectors |
CREDENTIAL_BOUNDARY | RECORDED | 4 vectors |
ATOMIC_COMMIT | RECORDED | 6 vectors |
PROVIDER_ENFORCED | RECORDED | 7 vectors |
END_TO_END | RECORDED | 2 vectors |
COVERED means the vectors exist, run, and pair positive with negative — or, for a
recorded profile, that the pinned artifact’s panels hold. It does not mean the shipped
guard ran. Measured on the shipped package: lib/assurance-profiles.js
requires neither @coderifts/agent-guard nor @coderifts/sdk,
so no profile on this table executes the shipped guard. The subject that does
(--subject agent-guard) runs on a different path, and the
--subject flag is ignored when --assurance is given.
GUARDED_TOOL_TABLE is the sharpest case. Its six
vectors are five conformance cases plus one adversarial test. Measured 2026-09-17, those five —
AA-DOCS-ONLY-SKIP, AA-CONTRACT-CHANGE-PREFLIGHT,
AA-RECEIPT-CARRY-VERIFY, AA-RECEIPT-WRONG-SCOPE-REPREFLIGHT,
AA-AUTHORIZE-NEEDS-OPERATION — are exactly the five
the shipped guard’s own subject does not answer. The reference subject answers 16 cases; the
agent-guard subject answers 11, and the five it drops are this profile.
RECEIPT_CRYPTO verifies pinned token bytes produced by
the receipt verifier, using a separate implementation on purpose — so a future verifier rewrite cannot
silently agree with itself. It measures the format, deliberately not the shipped verifier’s own code path.
PROVIDER_ENFORCED needs its own sentence, because the
name says enforced without saying by whom. The provider is GitHub. We do not operate a
merge provider. The evidence is raw GitHub API dumps, and the profile’s own boundary says it does not prove
that GitHub signed those payloads — they are API responses, not GitHub-signed objects.
ATOMIC_COMMIT and CREDENTIAL_BOUNDARY
are the six and four panels of one pinned, signed prove transcript (run prove-fb5c23bd).
A recorded panel holding is not the same as the shipped guard consuming a nonce — see
what makes a grant single-use.
Conformance END_TO_END (7/7)
The generated table above is the enforcement map. The public assurance claim sits beside it: @coderifts/conformance@0.8.11 reports every profile COVERED, including END_TO_END (7/7), via TARGET_STATE_TRANSITION_PROVEN — a governed ref moved to the authorized commit under a signed grant, observed afterwards by a separate read-only process.
Boundary, exactly as the profile records it: proof_scope TRUSTED_EXECUTOR, provider_witness NOT_APPLICABLE, externally_witnessed false. Trusted-executor-integrity, not a provider merge (PATH B), not externally witnessed. CodeRifts did not witness or sign the provider state. The GitHub positive provider-loop is a separate claim: provider canary. Honesty table: What each proof proves. Derived profile rows: atomic-stack.json. Replay: VERIFY.md. Gate today vs roadmap (not available): claim table.