# BitEvo Public Product Manifest BitEvo audits the action layer of AI-agent systems: what a workflow is allowed to change, what evidence must exist before it acts, how the external effect is confirmed, and how uncertainty is contained or recovered from. ## BitEvo Doctrine - Authority Budget: consequential capability expands a permission surface that must be earned and bounded. - Evidence Before Effect: critical effects depend on evidence available at decision time; post-hoc logs do not retroactively authorize. - False Green: apparent health/success while required evidence, object binding or external confirmation has diverged. ## Decision-grade artifacts - Authority Ledger: action, target object/environment, authority owner, approvals, allowed/prohibited transitions, replay rights and recovery ownership. - Evidence Contract: evidence required at decision time, provenance, freshness, object/environment binding, approval evidence, version context, external confirmation and missing-evidence behavior. - Finding Record: trigger, authority involved, observed evidence, external effect, recovery behavior, reproduction, consequence and uncertainty. - Decision Memo: owner question, bounded decision, supporting evidence, residual uncertainty, control change, resulting authority and retest criterion. ## Authority Mapper v2 - /mapper is a local browser mini-product for one action-capable workflow. - Supported action classes: CRM/record write, outbound message, deployment/config change and custom external effect. - It generates a draft Authority Ledger, Evidence Contract, action-specific failure scenarios, unresolved decision gates and a planning posture. - SAMPLE-001/002/003 presets prefill synthetic structure but deliberately set decision gates to UNKNOWN; presets are not evidence. - Mapper JSON can be exported and later imported locally. Import expects authority_ledger and evidence_contract structures. - A generated mapper draft can be handed to /workspace through browser sessionStorage for local checkpointing and before/after comparison. - The same generated mapper draft can be handed to /audit-intake through browser sessionStorage so technical scope fields can be prefilled without placing workflow content in a URL or transmitting it to a server. - Audit Intake intentionally leaves company/contact, access approval, secret confirmation, data boundary and testing authorization unset after mapper handoff. - If one or more decision gates are NO/UNKNOWN, the deterministic planning posture is CONSTRAIN pending resolution. If all gates are explicit, the planning posture is READY TO SCOPE TEST / RETEST. That label means description-level readiness to prepare written scope and Rules of Engagement; it does not authorize execution or establish implementation behavior. - Mapper does not produce a numerical trust score, authorize testing or certify implementation behavior. ## Decision Workspace - /workspace is a browser-local workspace for multiple saved Authority Mapper checkpoints. - Checkpoints are stored in localStorage on the current device; incoming Mapper handoffs use sessionStorage. The page does not upload these artifacts. - An incoming Mapper handoff remains pending in sessionStorage until the user explicitly saves the checkpoint or clears the incoming handoff; initial page load does not consume it. - Before/after comparison is classified as RETEST_CANDIDATE, SCOPE_DRIFT or CROSS_WORKFLOW. - RETEST_CANDIDATE requires the same normalized action class and the same normalized workflow identity. - SCOPE_DRIFT means workflow identity remains the same but the critical action and/or target binding changed. CROSS_WORKFLOW means action class or workflow identity differs. - The workspace also compares unresolved-gate counts, exact gate transitions, Authority Ledger field changes and Evidence Contract field changes. - Authority Budget comparison is non-numerical: exact authority-surface changes are shown, but the system does not infer semantic expansion or contraction from prose. - Deterministic defaults are identity-aware: unresolved gates -> CONSTRAIN; clean RETEST_CANDIDATE with zero unresolved gates -> RETEST; SCOPE_DRIFT with zero unresolved gates -> REPAIR; CROSS_WORKFLOW with zero unresolved gates -> CONSTRAIN. - The owner may choose EXPAND / CONSTRAIN / REPAIR / RETEST and supplies rationale plus an exact retest criterion. - RETEST and EXPAND are flagged as EVIDENCE CONFLICT when unresolved gates remain or when the comparison class is not RETEST_CANDIDATE. - Decision Memo local JSON uses schema bitevo.decision-memo.local.v2 and records comparison_class, same_action_class, same_workflow_identity, critical_action_drift, target_binding_drift and conflict_reasons. - RETEST_CANDIDATE is structural eligibility only. It does not authorize testing, certify implementation behavior or establish runtime correctness. - Decision Memo output can be copied or exported locally as TXT/JSON and always states testing authorization is not granted. - Fewer unresolved gates is not presented as a trust/safety score and is not treated as proof of implementation behavior. ## BitEvo Build - /build is the public index of shipped decision tools, source projects and research surfaces. - Build keeps source state, successful build evidence, public route availability and private runtime evidence as separate evidence classes. - The page is a curated public artifact index, not a live operations dashboard and not evidence of private runtime health. - Current build-breaking gate classes are: public claim boundary; public quality/metadata/accessibility/link/funnel/sitemap/deployment-policy contracts; public performance/dependency policy; homepage trust provenance; static asset budgets; contextual dogfood proof contract; and Workspace decision contract. - Passing machine gates does not certify design quality, business value, security or runtime correctness. - Public build principles: bound the object, separate source from runtime, expose the decision path, and publish only claims supported by the strongest available evidence. - Public working loop: Hypothesis -> Artifact -> Evidence -> Decision -> Retest -> Publish. ## Synthetic proof matrix - /proof compares three synthetic worked action classes using the same Authority / Evidence / Effect / Recovery method. - SAMPLE-001 /sample-audit: CRM write. Worked finding class: False Green / external-effect confirmation gap. Worked owner decision: CONSTRAIN. - SAMPLE-002 /sample-message: outbound message. Worked finding class: recipient + approval binding gap. Worked owner decision: CONSTRAIN. - SAMPLE-003 /sample-deployment: staging deployment/config change. Worked finding class: environment + baseline/version binding gap. Worked owner decision: REPAIR. - Machine-readable packs: /sample-audit.json, /sample-message.json, /sample-deployment.json. - All samples explicitly set customer_evidence=false, executed_audit=false and certification=false. - Provenance remains visible: SYNTHETIC, ASSUMPTION, EXPECTED GATE and NOT TESTED are not observations. ## Internal dogfood self-audit - /dogfood-self-audit is an INTERNAL SELF-AUDIT proof surface based on BitEvo dogfooding the authority/evidence method against its own agent/control workflows. - customer_case=false; independent_certification=false; production_wide_security_claim=false. - Public redacted failure classes: declared local-only authority crossing into synced storage; a no-effect receipt contradicting observed actions; and an early repair that still trusted caller-controlled effect semantics. - Scoped qualification receipt: 46 requests, 45 denied, one bounded READ_LOCAL control allowed, denied-handler dispatch count 0, external-handler dispatch count 0, uncaught exceptions 0, 46 terminal ledger rows. - Internal adversarial/evidence batch: 5,400 authority requests; 24/25 mutation kills (96% in that batch); 10,000 synthetic event ledgers; 1,000 corrupted summaries with 100% detection in that batch; 12,000 authority state-space scenarios; 105 attack patterns. - Claim ceiling: internal dogfood and bounded qualification only. This is not customer evidence, certification, universal no-bypass, provider-wide enforcement, production-wide security or proof that unknown defects do not exist. - Control proven does not mean control adopted everywhere; fleet-wide/live adoption remains a separate engineering program. ## Cross-case invariants - Authority is bound to the exact action and target object/environment, not generic tool access. - Required evidence must still be valid at execution time. - External confirmation must bind to the same recipient/object/environment affected by the action. - Ambiguity reduces authority and blocks blind retry/replay. - Retest replays the original decision criterion after repair. ## Local diagnostic - /diagnostic is a seven-gate local browser diagnostic for one workflow. - It returns unresolved decision gates rather than a numerical trust/safety score. - Seven YES gates mean the description layer has no unresolved gates and can support written scope preparation; this is not a safety pass or testing authorization. - The diagnostic does not authorize testing. Written Rules of Engagement remain required before test execution. - The diagnostic does not transmit data and does not certify a workflow. ## Core audit model - Audit object: one concrete action-capable workflow, not an abstract model score. - Intent: what external change is being proposed, to which object, and for what reason. - Authority: what may act, on which object/environment, under whose approval, and which transitions are prohibited. - Evidence: what must be present, fresh and attributable at decision time. - Effect: whether the intended external change is independently confirmed. - Recovery: how retries, interruption, stale state, partial effects and ambiguity are contained. - Owner decision: expand authority, constrain it, repair the workflow, or retest. ## Primary service Agent Authority & Evidence Audit - Fixed price: USD 4,900 - Duration: 5 working days after complete evidence/access + written scope - Scope: 1 staging/test workflow - Integrations: up to 3 tools / APIs / MCP servers - Failure plan: 10-20 agreed scenarios - Deliverables: 1. Executive report 2. Authority / effect map 3. Test inventory and scenario results 4. Reproducible evidence pack 5. Finding cards with impact, evidence, limitations, and confidence 6. Prioritized repair backlog 7. One retest 8. Evidence manifest / hashes where applicable ## Commercial decision ladder - Free / 20 minutes: decide whether the workflow is worth auditing and identify the critical action, authority owner and staging boundary. - USD 1,500 Entry Audit: determine whether one primary failure hypothesis on one critical action chain is reproducible and decision-relevant. - USD 4,900 Primary Audit: decide whether one workflow has enough evidence, effect confirmation and recovery control for its current or proposed authority. - Homepage Primary Audit timing uses the same qualified five-working-day window after complete evidence/access + written scope; its public Phase A-D sequence describes method, not a guaranteed day-by-day allocation. - Public Homepage, Pricing/Consulting and Agent Authority Audit scope-preparation CTAs, including the Primary Audit path, prepare a local scope brief only; they do not book or submit an engagement and do not authorize testing. - Hardening: quoted separately only after verified findings identify the real control gap. ## Boundaries This is a bounded engineering audit. It is not certification, a universal AI safety score, legal advice, production penetration testing by default, or a profit promise. Written scope and Rules of Engagement are required before testing. Do not submit API keys, passwords, tokens, private keys, wallet seeds, production credentials, or customer secrets through public forms. ## Canonical public routes - / - /doctrine - /artifacts - /proof - /dogfood-self-audit - /mapper - /workspace - /build - /sample-audit - /sample-message - /sample-deployment - /diagnostic - /agent-authority-audit - /audit-intake - /pricing - /consulting - /continuityos - /guides - /universe ## Reviewed public research notes - /guides/ai-agent-reliability-audit - /guides/security-sandboxing - /guides/fleet-coordinator-drift-monitoring - /guides/d3-tool-io-bridge-contract Historical guide routes are not part of the reviewed public research set and may be redirected to /guides. This manifest intentionally contains no runtime telemetry, internal checkpoints, infrastructure identifiers, private operational state, credentials, or control endpoints.