What holds up, and
what we refuse to invent.
The full accounting. Unmeasured is UNAVAILABLE, never zero. The two largest entries are structural rather than statistical: nothing is ingested agentlessly at the front of the loop, and execution has exactly one effector at the back. See the loop, link by link ↗
MEASURED
Decision latency
111–640 µs p50
p99 in milliseconds, machine-load dependent. Produced by caveat-bench on recorded sessions.
Comment and Control replay
7 of 7 refused
CVSS 9.4 attack class: 7 of 7 exfiltration steps refused, 5 of 5 legitimate review steps allowed. demo_comment_and_control.sh.
Credential broker
0 of 9 leaked
0 of 9 leak vectors succeeded under the broker vs 6 of 8 without it; 4 of 4 legitimate API calls forwarded. Measured on macOS (demo_credential_broker.sh).
Code quality gate
0 issues
cargo clippy -D warnings clean, golangci-lint 0 issues, demos pass against real binaries.
NOT MEASURED / NOT CONNECTED
ADR-Bench / AgentDojo
Not measured. The replay harness and ASR/utility calculation exist; no corpus has been run, so no detection or prevention rate is claimed.
Prompts per session
Not at target. 36.66 mean / 25 p50 on a frozen transcript set, against a target of ≤ 2. The active engineering priority.
Agentless ingestion
Not connected, and it is the front of the loop. The connector framework is real — registry, SDK, credential sealing, sync-run recording, tenant isolation — but no upstream API client is written, so nothing is read from an identity provider, a drive or a SaaS application today. Without a credential a connector reports NOT CONNECTED; with one it reports UNAVAILABLE and makes no upstream call. The only live enterprise ingestion is GitHub, by webhook. Every engine downstream is as populated as this link allows, which is why the rollout simulator answers insufficient_data rather than safe_to_deploy on an empty graph.
Remediation effectors
One, and it is the back of the loop. The lifecycle is real and stricter than the category’s: a model may propose, a model subject can never approve, execution is separate, and closure is re-observed against the revocation log, checked for a newer record that re-authorized the session, and recorded as claimed or unverifiable rather than ever overstated as verified. But execution revokes a session and nothing else. Marking a data finding for re-observation is not revoking a share; marking an entitlement recommendation applied is not changing an entitlement. There is no revoke-share, disable-account or kill-token effector, because there is no connector to act through. We close one action with proof where the category closes many without.
Outreach and workflow
Not built. No Slack, Teams, email or ticketing sender exists in the control plane; Slack appears as a connector kind and nothing more. An owner-guided one-step fix has no transport today.
Time to risk reduction
Not computed. The metric has no implementation anywhere in the codebase, so no surface renders one. A number with nothing behind it is not a number.
Kernel sensor
Linux only today (Aya / eBPF / BPF-LSM), and it is the only collector delivering a kernel view. The macOS Endpoint Security crate exists but cannot start without the Apple-granted entitlement, TCC approval and root; without them it prints endpoint security UNAVAILABLE rather than claiming an observation. The Windows ETW crate reads the KernelProcess session and parses each record header; full exec and file-open extraction waits on a Windows host verifying the provider schemas. Three-platform sensor coverage does not ship.
Credential broker on Linux
Untested. Measured only on macOS; /proc/<pid>/environ handling exists in code.
Sandbox conclave
Not demonstrated end-to-end; the command exists and reports UNAVAILABLE without Docker.
SOC 2 Type II / ISO 42001
A blueprint, not an audit. The observation window is 3–6 months and cannot be accelerated.