Skip to content

docs(ocsf): review + supporting sample bundle for ocsf-schema#1724 trust-base inventory - #436

Merged
Levaj2000 merged 2 commits into
mainfrom
claude/review-dave-paypal-work-uokt9k
Aug 11, 2026
Merged

docs(ocsf): review + supporting sample bundle for ocsf-schema#1724 trust-base inventory#436
Levaj2000 merged 2 commits into
mainfrom
claude/review-dave-paypal-work-uokt9k

Conversation

@Levaj2000

Copy link
Copy Markdown
Owner

What

Support package for ocsf/ocsf-schema#1724@rabbidave's (Dave, PayPal) proposal for a Discovery-category agent trust-base inventory class that applies the record_integrity profile per emission. His chain-of-custody mechanism is the #1661 shape we landed in OCSF 1.9 and run in production, so this backs the proposal with that experience.

Three artifacts:

  • docs/ocsf-1724-trust-base-review.md — review: assessment of the declared+executed one-event design, the admission-control emission timing, and his two maintainer questions (Discovery is right, with the config_state/device_config_state_change split as precedent for a Change activity; new class over extending device-shaped inventory classes), plus five suggestions for the eventual class PR.
  • docs/ocsf-1724-draft-issue-comment.md — paste-ready response for the issue, carrying the practitioner notes that transfer from production (metadata.uid per emission, genesis omits prev_event, fingerprint-sibling honesty, the #1709 signature-bytes gap) and the offer to co-draft the 1.10 class PR.
  • docs/cosai-ws4-ocsf-mapping/trust-base-inventory-sample/ — worked data: 3 chained events for the reference bundle's demo agent, stdlib-only recomputable end to end (build_sample.py --verify: fingerprints, chain linkage, named digest preimages). Demonstrates a benign declared/executed divergence (MCP tools/list refresh vs enforced allowlist) and the Sleeper-Agents one (registry-declared adapter digest ≠ loaded-bytes digest, emitted before the adapter's first inference).

Why

The issue's design and our production evidence are mutually reinforcing: he needs proof record_integrity works per-emission on a second class; we've been accumulating exactly the "what the agent was" gaps (issues draft 1/2/5) his class would home.

Verification

python3 docs/cosai-ws4-ocsf-mapping/trust-base-inventory-sample/build_sample.py --verify
# ✓ 3 events: fingerprints recompute, chain links, content digests resolve
#   to named preimages, event-3 declared≠loaded divergence present

Docs only — no product impact.

🤖 Generated with Claude Code

https://claude.ai/code/session_012phLbmYc3Tgp3Bn39EfFML


Generated by Claude Code

…ust-base inventory

Dave's (PayPal, @rabbidave) #1724 proposes a Discovery-class agent
trust-base inventory chained with record_integrity per emission — built on
the #1661 shape we run in production. Back it with: a review against our
production experience and his maintainer questions, a paste-ready issue
response, and a worked 3-event sample (stdlib-only recomputable: named
digest preimages, chain verifier, benign + malignant declared/executed
divergences, admission-control timing).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012phLbmYc3Tgp3Bn39EfFML
@vercel

vercel Bot commented Aug 11, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
ai-identity-landing Ready Ready Preview Aug 11, 2026 1:52pm
dashboard Ready Ready Preview Aug 11, 2026 1:52pm

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012phLbmYc3Tgp3Bn39EfFML
@Levaj2000
Levaj2000 marked this pull request as ready for review August 11, 2026 13:57
@Levaj2000
Levaj2000 merged commit ffcbb12 into main Aug 11, 2026
7 checks passed
@Levaj2000
Levaj2000 deleted the claude/review-dave-paypal-work-uokt9k branch August 11, 2026 14:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants