Run
Supply an AgentFence policy and representative tool calls, locally or in CI.
Authorization evidence for AI agents
VeriCordon creates reproducible evidence for agent, MCP, and tool authorization decisions — locally and in CI.
No hosted control plane required.
Raw audit JSONL is not uploaded by default.
01 / Evidence check
02 / The gap stays visible
The supplied audit events lacked action and policy binding. The report recorded that gap as partial.
Inspect the decision. Preserve the evidence. Trust the artifact, not a dashboard.
01 / The evidence gap
AI agents increasingly perform actions with real consequences. When something is allowed, denied, or unexpectedly succeeds, an opaque decision isn’t enough.
Raw audit logs, scattered traces, and vendor dashboards leave engineers reconstructing the context. You need a record of what actually happened.
02 / How it works
Supply an AgentFence policy and representative tool calls, locally or in CI.
Collect the available authorization evidence for the boundary and calls actually evaluated.
Review a versioned JSON evidence report and deterministic Markdown report, ready to preserve in CI.
03 / Deliberate by design
Keep sensitive authorization evidence in your environment.
Generate evidence as part of development and security workflows.
Missing binding evidence stays partial or not_evaluated — never silently converted into success.
Machine-readable JSON and human-readable reports make behavior reviewable by systems and engineers.
Distinct evidence states. Uncertainty stays visible.
OBSERVEDPARTIALNOT_EVALUATEDFAILED04 / The artifact is the output
{
"id": "exact_action_policy_binding",
"status": "partial"
}Missing binding evidence stays visible.
Evidence that survives a failed gate
Real check excerpt from the documented missing-evidence run. The status applies only to the supplied evidence. View the repository guide
05 / In your workflow
Attach authorization evidence to CI before shipping agent changes.
Inspect evidence for MCP tool calls evaluated at the configured boundary.
Give reviewers a deterministic artifact instead of asking them to reconstruct decisions from raw logs.
Preserve reports alongside CI results so changes to authorization evidence can be reviewed.
Your boundary. Your evidence.
VeriCordon is designed around local and CI execution.
Raw sensitive audit material does not need to be uploaded to a VeriCordon SaaS service just to understand an authorization decision.
A deliberate product decision.
Not a temporary limitation.
Built for the work ahead
VeriCordon is most useful once agents move beyond chat and begin calling APIs, MCP tools, infrastructure, repositories, internal systems, or business workflows.
Early access
Try the open-source evidence bundle in AgentFence on GitHub.
Need richer evidence workflows, policy regression capabilities, or organizational features? Tell us what authorization evidence your team needs.
Scope, clearly stated
Authorization evidence.
Not a security guarantee.
Generate evidence you can review, preserve, and reproduce.