Skip to content

Instrumented Agent

Instrumentation can make additional claim-relevant distinctions possible.

Consider a claim concerning unauthorized consequential action.

An opaque service may expose evidence that an action occurred while providing little evidence about:

  • who or what initiated the action
  • the authorization state
  • the execution pathway
  • whether relevant evidence could have been altered
  • whether consequential-action channels were fully observed

An instrumented agent can expose additional runtime evidence concerning origin, authorization, and execution pathway.

An assurability-oriented architecture can additionally expose or preserve evidence concerning integrity, coverage, and independent corroboration.

Example Result

In the formal example, each stronger architecture preserves the relevant capabilities of the preceding architecture and adds at least one additional capability.

For the modeled assurance context:

text S_R ≻q S_A ≻q S_O

This is strict comparative dominance for that claim and context.

It does not establish that any architecture satisfies the claim. A more assurable architecture may instead provide stronger evidence that the claim is false.

The architecture comparison uses an abstract claim and an explicitly defined capability model. The following resolution-bound example uses a separate claim and observation model.

The two constructions demonstrate different aspects of the theory. No theorem in this example establishes that strict capability-profile dominance implies improved claim resolution.

Claim-Resolution Bound

The same example also considers two admissible possible worlds:

text World 1: no unauthorized consequential action occurred World 2: an unauthorized consequential action occurred

The worlds differ on a fact relevant to the claim.

If the evaluator receives the same observation in both worlds, that observation cannot determine which world holds and therefore cannot resolve the claim.

Source of Truth

The Lean source is authoritative: