Evidence
Every claim has an identity.
The viewer is a deterministic projection of committed evidence. Checksums, verified remote identities, and account boundaries remain inspectable.
Validation chain
Phase 4 does not replace these canonical records. It verifies and presents them.
- Phase 1 run
- fc174741528435dd
- Deterministic local analysis
- Phase 2 migration checksum
- 7fafa8d61cd4ed3da97eb3c6b6ff37e22fede427115b06686b981e9151b0bfb6
- urn:li:document:mcpatch.migration.27f639a515e0c8e5
- Phase 3 Core patchset
- 0e8026633eb9ec30e098
- urn:li:document:mcpatch.patchset.27f639a515e0c8e5.0e8026633eb9ec30e098
- Known live patchset
- 3d427f20f1b196848050
- urn:li:document:mcpatch.patchset.27f639a515e0c8e5.3d427f20f1b196848050
- Holdout live patchset
- 1774f922aa82c29123f6
- urn:li:document:mcpatch.patchset.cfbc270b8dc92084.1774f922aa82c29123f6
- Aggregate live validation
- 072a2030b8ddaa70da05
- urn:li:document:mcpatch.phase3.live.072a2030b8ddaa70da05
Verified draft pull requests
5 exact evaluated trees were published to isolated synthetic repositories and read back. All remain drafts.
| Scenario | Repository | Remote tree | State | Link |
|---|---|---|---|---|
| Known | aman-khan-27/mcpatch-phase3-live-agent-skills | c3e425a9677f2f6a7ed5eead493f8651bda7551c | Draft | PR #1 |
| Known | aman-khan-27/mcpatch-phase3-live-fraud-triage-agent | 19dff1620f5786467df1d80bc18d264cbdf55dce | Draft | PR #1 |
| Known | aman-khan-27/mcpatch-phase3-live-revenue-analyst-agent | e3d68550892a9225bf6a31ed22d44108b83dceb4 | Draft | PR #1 |
| Holdout | aman-khan-27/mcpatch-phase3-live-job-insights-skill-holdout | 68300fd8290b36bf50475f68fb2ed1b946cff903 | Draft | PR #1 |
| Holdout | aman-khan-27/mcpatch-phase3-live-operations-dashboard-agent-holdout | 3bee655476f9a07ae90a283ea7bf12126879725e | Draft | PR #1 |
Account boundary
The official project and isolated validation estate are deliberately separate.
aman2712
Owns the canonical MCPatch source repository. Phase 4 performs no write through this account.
aman-khan-27
Owns only the isolated validation repositories and draft PRs. It has no role in owning or modifying the official source.
Public verification route
The checksum-covered evidence index is the release artifact. The validated tag, judge route, and canonical source remain directly inspectable.
Trusted repository onboarding
Sanitized demonstrations show trusted metadata inspection without executing repository commands during replay. Validation and human-review state are shown separately.
| Repository | Runtime | Base | Path policy | Proposed checks | Validation | Review |
|---|---|---|---|---|---|---|
| github.acme/agent-skills customer-platform |
python stdlib |
ba1264302ea2c000f4fcf91d9a5260ad743b01da | Editable customer_insights.py Protected .git, tests |
python -m pytest | Validated | Approved |
| github.acme/job-insights-skill-holdout operations-platform |
python stdlib |
da3c0f5015e638a8ef34a2ef9e9a7a822892ef8b | Editable src/job_insights/adapters/status_client.py, src/job_insights/services/summary.py Protected .git, tests |
python -m pytest | Validated | Approved |
| github.acme/revenue-analyst-agent analytics-platform |
python stdlib |
bf777d5a9ad2a86d7975cc81c362c8e06869945d | Editable app.py Protected .git, tests |
python -m pytest | Validated | Approved |
Checksums and provenance
The manifest covers 28 payload files. Every listed byte matched before any JSON or Markdown evidence was parsed.
- Evidence manifest5c20490f6252db2ec8fa73f9eaaa69bb7144625bf2d44bdf06fcb74becafaad1Verified
- Aggregate evidence56f1725c871edb0031d778bc129755b2e658aea5adbe8de20bb9f71c0dbad679Verified
- Aggregate JSON payloaddd4977ee83279049c8f3e4280e848d2ca65598d0ce5d244023adce07d7c910a2Verified
- Aggregate rendered record9f46caa8667a6226469283f35b5553feb2e4c7deecc0ef99338b499ad59218d0Verified
- Aggregate DataHub receipt91c57bc07d645cd16a8b326593a2d1cb344a3fe5164ada367e25566144722911Verified
- Locked Codex runneree148fe402624e25323c85366689261b547320d990bc9d9c53e9b9cbb908595bVerified
Public replay has no write surface
No route can generate a patch, push a branch, create or ready a PR, write to DataHub, merge, or deploy. Raw prompts, transcripts, credentials, private mappings, runtime homes, and temporary paths are excluded.