Architectural brief
Decision records in a deployment review
Agree on the evidence before integrating a gateway. This review contract separates what a retained AGA bundle can establish from what must be tested in its deployment.
Jack Brennan, Founder · Originally published May 1, 2026 · Revised October 3, 2026
Revision history and scope
This is a revised web brief, previously titled Frontier Deployments and AGA: An Architectural Complement. The September 28 revision distinguished the published components from proposed architecture. The October 3 revision removes unnamed-vendor statistics, an unsupported model ranking, historical configuration examples and claims that AGA resolves limitations of behavioral evaluation. Original publication dates and this URL are retained. Historical downloadable papers and filed submissions are separate records and are unchanged.
No lab partnership, customer deployment, independent security review or measured integration benefit is established by this brief.
One question the artifact can answer.
Which tool decisions are recorded in this export, which policy reference do their signed fields commit to, and does the supplied bundle verify against the expected signing key?
The current reviewer case supplies a policy, request fixture, signed bundle and retained manifest. Its verification and deliberate failure controls can be reproduced locally. It is a synthetic evaluation of that artifact contract, not proof of a deployed customer control.
Define what the recipient will retain.
- Artifact and interpretation
- Keep the original bundle bytes, verifier version and result. Identify which fields are signed, which are unchecked metadata and how the parser treats the file. The published verifiers have documented byte-level differences.
- Expected key and issuer
- Establish the expected key through a separately trusted channel and document who controls it. Copying a key from the same bundle establishes no independent identity. Plan key rotation and retention of the old verification material.
- Policy and coverage
- Retain the policy that corresponds to the signed reference. Specify which request paths are recorded, which are refused without receipts and which bypass the collector. A consistent chain of supplied receipts does not prove complete capture.
- Time and history
- Specify how the recipient obtains freshness or independent witnessing if required. A genuine older bundle can still verify. The signing key holder may sign a different history; the artifact alone does not rule that out.
Qualify the deployment separately.
Call path
Observe the protected tool.
Use an independently observed synthetic integration to determine whether denied requests reach the tool and whether alternate routes bypass the control. A signed denial is not that observation.
Key custody
Test the actual identities.
Check which OS identities can read the signing key, change policy and reach tool credentials. A separate process is not sufficient if the agent can read or modify its state.
Continuity
Exercise failure and recovery.
Qualify disconnects, concurrent exports, restarts, key rotation and retention against the agreed workflow. Document what the recipient can conclude when evidence is absent.
Use model evaluations and operational monitoring for model behavior. Signed records do not detect evaluation awareness, measure unobserved activity or determine whether the policy itself is adequate. The published decision-record path does not establish the proposed continuous measurement or synthetic-response architecture.
Use an explicit acceptance decision.
Proceed only if the intended recipient can reproduce the check, interpret its limits and identify a review decision the retained artifact helps them make. Compare an existing signed export or protected-log workflow first. Additional routing and key-management work must be justified by that requirement.
No comparative overhead benchmark or independent usefulness result is claimed here. A historical artifact-measurement benchmark does not establish per-call gateway overhead. Measure the actual integration and report its workload, latency distribution, failure behavior and retained evidence.