# BitEvo Public Product Manifest BitEvo audits the action layer of AI-agent systems: what a workflow is allowed to change, what evidence must exist before it acts, how the external effect is confirmed, and how uncertainty is contained or recovered from. ## BitEvo Doctrine - Authority Budget: consequential capability expands a permission surface that must be earned and bounded. - Evidence Before Effect: critical effects depend on evidence available at decision time; post-hoc logs do not retroactively authorize. - False Green: apparent health/success while required evidence, object binding or external confirmation has diverged. ## Decision-grade artifacts - Authority Ledger: action, target object/environment, authority owner, approvals, allowed/prohibited transitions, replay rights and recovery ownership. - Evidence Contract: evidence required at decision time, provenance, freshness, object/environment binding, approval evidence, version context, external confirmation and missing-evidence behavior. - Finding Record: trigger, authority involved, observed evidence, external effect, recovery behavior, reproduction, consequence and uncertainty. - Decision Memo: owner question, bounded decision, supporting evidence, residual uncertainty, control change, resulting authority and retest criterion. ## Authority Mapper v2 - /mapper is a local browser mini-product for one action-capable workflow. - Supported action classes: CRM/record write, outbound message, deployment/config change and custom external effect. - It generates a draft Authority Ledger, Evidence Contract, action-specific failure scenarios, unresolved decision gates and an owner decision posture. - SAMPLE-001/002/003 presets prefill synthetic structure but deliberately set decision gates to UNKNOWN; presets are not evidence. - Mapper JSON can be exported and later imported locally. Import expects authority_ledger and evidence_contract structures. - A generated mapper draft can be handed to /workspace through browser sessionStorage for local checkpointing and before/after comparison. - The same generated mapper draft can be handed to /audit-intake through browser sessionStorage so technical scope fields can be prefilled without placing workflow content in a URL or transmitting it to a server. - Audit Intake intentionally leaves company/contact, access approval, secret confirmation, data boundary and testing authorization unset after mapper handoff. - If one or more decision gates are NO/UNKNOWN, the deterministic planning posture is CONSTRAIN pending resolution. If all gates are explicit, the posture is TEST / RETEST because description is not proof. - Mapper does not produce a numerical trust score, authorize testing or certify implementation behavior. ## Decision Workspace - /workspace is a browser-local workspace for multiple saved Authority Mapper checkpoints. - Checkpoints are stored in localStorage on the current device; incoming Mapper handoffs use sessionStorage. The page does not upload these artifacts. - The workspace compares before/after unresolved-gate counts, exact gate transitions, Authority Ledger field changes and Evidence Contract field changes. - Authority Budget comparison is non-numerical: exact authority-surface changes are shown, but the system does not infer semantic expansion or contraction from prose. - The owner explicitly chooses EXPAND / CONSTRAIN / REPAIR / RETEST and supplies rationale plus an exact retest criterion. - EXPAND selected while after-state gates remain NO/UNKNOWN is flagged as an evidence conflict; the workspace does not support or authorize expansion from that state. - Decision Memo output can be copied or exported locally as TXT/JSON and always states testing authorization is not granted. - Fewer unresolved gates is not presented as a trust/safety score and is not treated as proof of implementation behavior. ## Synthetic proof matrix - /proof compares three synthetic worked action classes using the same Authority / Evidence / Effect / Recovery method. - SAMPLE-001 /sample-audit: CRM write. Worked finding class: False Green / external-effect confirmation gap. Worked owner decision: CONSTRAIN. - SAMPLE-002 /sample-message: outbound message. Worked finding class: recipient + approval binding gap. Worked owner decision: CONSTRAIN. - SAMPLE-003 /sample-deployment: staging deployment/config change. Worked finding class: environment + baseline/version binding gap. Worked owner decision: REPAIR. - Machine-readable packs: /sample-audit.json, /sample-message.json, /sample-deployment.json. - All samples explicitly set customer_evidence=false, executed_audit=false and certification=false. - Provenance remains visible: SYNTHETIC, ASSUMPTION, EXPECTED GATE and NOT TESTED are not observations. ## Cross-case invariants - Authority is bound to the exact action and target object/environment, not generic tool access. - Required evidence must still be valid at execution time. - External confirmation must bind to the same recipient/object/environment affected by the action. - Ambiguity reduces authority and blocks blind retry/replay. - Retest replays the original decision criterion after repair. ## Local diagnostic - /diagnostic is a seven-gate local browser diagnostic for one workflow. - It returns unresolved decision gates rather than a numerical trust/safety score. - The diagnostic does not transmit data and does not certify a workflow. ## Core audit model - Audit object: one concrete action-capable workflow, not an abstract model score. - Intent: what external change is being proposed, to which object, and for what reason. - Authority: what may act, on which object/environment, under whose approval, and which transitions are prohibited. - Evidence: what must be present, fresh and attributable at decision time. - Effect: whether the intended external change is independently confirmed. - Recovery: how retries, interruption, stale state, partial effects and ambiguity are contained. - Owner decision: expand authority, constrain it, repair the workflow, or retest. ## Primary service Agent Authority & Evidence Audit - Fixed price: USD 4,900 - Duration: 5 working days - Scope: 1 staging/test workflow - Integrations: up to 3 tools / APIs / MCP servers - Failure plan: 10-20 agreed scenarios - Deliverables: Authority Ledger, Evidence Contract, reproducible Finding Records, Decision Memo/backlog and one retest ## Commercial decision ladder - Free / 20 minutes: decide whether the workflow is worth auditing and identify the critical action, authority owner and staging boundary. - USD 1,500 Entry Audit: determine whether one primary failure hypothesis on one critical action chain is reproducible and decision-relevant. - USD 4,900 Primary Audit: decide whether one workflow has enough evidence, effect confirmation and recovery control for its current or proposed authority. - Hardening: quoted separately only after verified findings identify the real control gap. ## Boundaries This is a bounded engineering audit. It is not certification, a universal AI safety score, legal advice, production penetration testing by default, or a profit promise. Written scope and Rules of Engagement are required before testing. Do not submit API keys, passwords, tokens, private keys, wallet seeds, production credentials, or customer secrets through public forms. ## Canonical public routes - / - /doctrine - /artifacts - /proof - /mapper - /workspace - /sample-audit - /sample-message - /sample-deployment - /diagnostic - /agent-authority-audit - /audit-intake - /pricing - /consulting - /continuityos - /guides - /universe ## Reviewed public research notes - /guides/ai-agent-reliability-audit - /guides/security-sandboxing - /guides/fleet-coordinator-drift-monitoring - /guides/d3-tool-io-bridge-contract Historical guide routes are not part of the reviewed public research set and may be redirected to /guides. This manifest intentionally contains no runtime telemetry, internal checkpoints, infrastructure identifiers, private operational state, credentials, or control endpoints.