Skip to content

Domain and Lifecycle Reference

Durable entities

These are the tables the workspace actually stores.

Entity Purpose
Workspace Private local state root containing engagements and platform storage.
Engagement Scope metadata, participants, retention context, runs and findings for one body of work.
Target Locator, protocol adapter, authorization metadata, credential references and capabilities.
Surface Discovered agent, endpoint, tool, resource, prompt, schema, memory, session or credential flow.
Run One immutable execution attempt and its lineage.
Job A supervised process attached to a run.
Observation A captured or discovered fact.
Hypothesis An unvalidated structural attack path.
Validation A tested result.
Finding A triaged result with severity, disposition, remediation and retest history.
Artifact Immutable content-addressed object.

Connections, interception sessions, transform rules and shadow endpoints are deliberately not rows here. A connection is a file under the workspace, a session is a supervised process, and a transcript is a hash-chained file, so none of them can be quietly rewritten by a later database write.

Run and job state

RunStatus is pending, running, succeeded, failed, cancelled, lost. JobStatus adds starting and stopping around the same shape. Transitions are compare-and-set: a terminal run cannot silently return to running. lost is distinct from failed. It means the supervisor stopped being able to observe the process, which is not the same as the process reporting a result.

Evidence tiers

A finding claims one of five tiers. AIT determines the first two from the transcript and refuses to infer the top two. See Evidence for what earns each one.

Tier Claim
nothing_delivered No modified delivery was recorded.
mutation_delivered AIT altered the communication and delivered the change.
receiver_processed The receiver acted on the altered message.
behavior_changed The receiver's behavior differed because of the alteration.
external_effect_observed An independently observed side effect followed the delivery.

Higher tiers require every lower tier, and a tier cannot be skipped. Target text never substitutes for an observation: the receiving agent saying it did something is narration, not evidence.

Alongside the tier, a finding carries an attribution, derived by comparing the receiver's behaviour across arms: attributable when the arms differed, not_isolated when they did not, no_control when no control arm ran, and undetermined when the arms cannot be compared. A behavior_changed claim with no_control is a weaker statement than the tier alone suggests, and the ledger records that rather than hiding it.

A validation record of kind=behavior may not assert impact_validated. The API rejects one that tries, because behavior observed through the target is exactly the evidence that needs an independent oracle.

Artifact envelope

Platform artifacts share a versioned envelope: kind and schema version, stable ID, creation time, producer/build information, workspace/engagement/run/parent references, content digest, source references, provenance, redaction status and signature status.

Interception session artifacts

A completed interception session leaves:

  • the hash-chained transcript, recording the sender's original and the delivered message separately for every edited record;
  • the JSONL sidecar the transcript appends to during the session;
  • the evidence ledger, if one was built;
  • shadow observation files for any shadow endpoint that received traffic;
  • the cleanup receipt, naming every component stopped and how anything still paused at stop time was resolved.

Transcripts, session files, shadow observations and rule exports are written 0600. With credential masking removed so token forging, stripping, downgrade and relay can be tested, captured bytes include credentials in full: that is deliberate, and it is why the file mode matters.

Compatibility

Transcript verifiers support chain 1.0, 2.0 and 2.1.