Trust

Agent Assurance Passport

Every approved version can carry one portable AAPPLIFY and AgentBourse assurance record: identity, execution chain, access, authority, dependencies, performance, economics, approvals, incidents, and audit evidence.

Assurance signals

Security scan severity
Red-team severity
Automated test pass rate
Seller verification
Successful executions
Buyer reviews
Version freshness
Support responsiveness

Finding severity

criticalcritical
highhigh
mediummedium
lowlow
infoinfo

What buyers can rely on

Assurance evidence for governed agent adoption

The passport turns scattered technical, commercial, and governance evidence into a reviewable record for procurement, AI governance, security, compliance, and operational owners.

Compare agents before procurement or security review.
Reduce shadow AI by routing adoption through verified agents and entitlements.
Require human approval for high-risk MCP tools before execution.
Preserve evidence for audit, vendor review, incident response, and renewal decisions.

Identity and owner

Stable agent and version identifiers, accountable marketplace owner, support contact, and verification state.

Execution chain

Primary models, subagents, dependencies, handoffs, orchestration mode, and human approval points.

Access and authority

Tools, APIs, MCP servers, data entitlements, requested permissions, and the limits of delegated authority.

Critical dependencies

Cloud runtime, model providers, and critical third parties with visible gaps for region, residency, or fallback evidence.

Evaluation and performance

Security scans, red-team results, automated tests, production executions, ratings, and support performance.

Cost and spending

Pricing, declared cost drivers, payment rail, and whether enforceable workspace spending limits are public, private, or missing.

Approvals and exceptions

Publication decisions, execution-time gates, time-bound exceptions, owners, expiry, and compensating controls.

Incidents and audit evidence

Redacted incident disclosure plus version-bound evidence identifiers, provenance, timestamps, and a tamper-evident digest.

Production architecture

Kept in implementation docs

AWS service mapping, worker isolation, queues, artifact storage, secrets, web protection, and rollout phases are maintained in the deployment docs and runbooks. This public trust page focuses on the buyer-facing evidence and controls used to evaluate agents.