Skip to main content

Evidence Provenance Rollout

Purpose

This page begins the same evaluation process across all registered external frameworks.

It applies the External Framework Evaluation Standard to every framework in the registry and records the first-pass evidence posture for each page.

The machine-readable rollout matrix is:

docs/external-frameworks/evidence-provenance-rollout.json

Evaluation Classes

F1 Framework Claim
F2 Framework Implementation
O1 Direct Observation
O2 Parameterized Observation
R1 Reproduced Result
S1 StegVerse Analysis
S2 Transition Mapping
I1 Interoperability Result
V1 Validation Artifact
H1 Hypothesis

First-Pass Rollout Matrix

FrameworkSource StatusObserved BehaviorStegVerse AnalysisStandingNext Action
GLMsourcednot startedprovisional crosswalksourced provisionalAdd Evidence Provenance and classify claims as F1/S1/S2.
EVIDEsourcednot startedprovisional crosswalksourced provisionalAdd Evidence Provenance and classify reconstructability claims.
DecisionAssureartifact package requiredartifact dependentpartial trace crosswalkfail-closed pending artifactSeparate artifact-package claims from StegVerse trace analysis.
MindForgeartifact package requiredartifact dependentpartial review-evidence crosswalkfail-closed pending artifactSeparate historical review evidence from execution authority.
Morrison Runtimesourced with parameterized boundary case partialO2 partialsemantic-equivalence boundary casebounded partial observationAttach raw audit payload, timestamp, runtime configuration, and source hash.
CARE Runtimeofficial source requirednot startedintake onlysource-blocked fail-closedIdentify official source before any compatibility claim.
AARsourcednot startedprovisional crosswalksourced provisionalAdd source/analysis split.
ASROsourcedcommitment candidate material present or pendinggovernance-state attestation crosswalksourced provisionalClassify ASRO commitment candidate artifacts as V1/I1 where present.
MITRE ATLASsourcednot applicable for runtime resultthreat-context crosswalksourced provisionalMap threat knowledgebase evidence without runtime claims.
OWASP Top 10 for LLM Applicationssourcednot applicable for runtime resultrisk-category crosswalksourced provisionalMap risk categories without certification claims.
Agent Governance Playbooksourcednot startedagent-continuation crosswalksourced provisionalClassify release/source evidence and continuation-governance analysis.
Emergency Stop Conventionsourcednot startedemergency-stop fail-closed crosswalksourced provisionalMap emergency-stop semantics to fail-closed boundary classes.
NIST AI RMFsourcednot applicable for runtime resultrisk-management crosswalksourced provisionalSeparate NIST source claims from StegVerse analysis.
ISO/IEC 42001sourcednot applicable for runtime resultAI management-system crosswalksourced provisionalClassify standard-source claims and StegVerse controls separately.
EU AI Actsourcednot applicable for runtime resultlegal-obligation crosswalksourced provisionalSeparate legal-source summary from StegVerse governance analysis.
Policy Cardssourcednot startedruntime policy artifact crosswalksourced provisionalBuild policy-card Commitment Candidate fixture.
Runtime Governance for AI Agentssourcednot startedruntime path-governance crosswalksourced provisionalCompare path-governance claims to semantic-equivalence boundary testing.
Admissible Existence Seed Cyclefirst framework cycle completeseed-cycle artifacts presentcanonical seed-cycle mirrorcycle complete, non-authorizingPreserve as mirror record; do not treat publication as standing.

Rollout Rule

Each framework page should be refactored to include the same Evidence Provenance structure before stronger interoperability claims are made.

Official Framework Sources
Official Implementation Sources
Observed Behavior
Reproduced Behavior
StegVerse Analysis
Interoperability Assessment
Standing

Boundary

This rollout is not certification.
This rollout is not endorsement.
This rollout does not grant execution authority.
This rollout does not convert source availability into validation.
This rollout does not generalize observed behavior beyond captured evidence.

Next Safe Build Target

Refactor pages in batches:

Batch 1: GLM, EVIDE, Morrison Runtime
Batch 2: DecisionAssure, MindForge, ASRO
Batch 3: MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, EU AI Act
Batch 4: Policy Cards, Runtime Governance for AI Agents, Agent Governance Playbook, Emergency Stop Convention, CARE Runtime, AAR
Batch 5: Admissible Existence Seed Cycle