Agent Governance · Post-Quantum Identity · Independent Evidence

The audit trail your agents don't have — and can't fake.

IDC reports that most enterprises cannot verify what their AI agents actually do — 60% of security leaders lack basic agent containment, and 35% cannot shut down a rogue agent. The record of what happened often does not exist at all.

P31's Loom is that record — live, hash-chained, PQC-signed, and independently verifiable on Cloudflare Workers.

The gap is the market

IDC, September 2026: 'The Audit Trail That Doesn't Exist.' Governance spend is the answer — agent observability & governance is a $1.68B (2026) → $8.62B (2031) market at 38.69% CAGR.

60%

of security leaders lack basic agent containment controls.

35%

cannot shut down a rogue agent once deployed.

$1.68B → $8.62B

agent observability & governance, 2026 → 2031 (38.69% CAGR).

Verify it yourself — ninety seconds

Three commands. No account. The chain recomputes from genesis and returns the current head.

# 1 · The Loom chain — recomputes and verifies
curl -s https://b30e37b5.loom-8z0.pages.dev/api/loom-public/verify | python3 -m json.tool

# 2 · The MCP tool registry
curl -s https://mcp-registry.trimtab-signal.workers.dev/servers | python3 -m json.tool

# 3 · A flagship live
open https://p31ca.org/apps/loom

Expected from #1: {"valid": true, "checked": 16, "brokenAt": null} — a live request against a deployed endpoint, not a screenshot.

Three proofs, all live

Every capability resolves to a running service or a published standard.

Pre-execution enforcement

guardAgentEvent runs before commit — refusals are recorded, not reconstructed. A denied action never reaches the log as if it happened.

Hash-chained evidence

RFC 8785 canonicalization + SHA-256. The chain is independently verifiable at a public endpoint — no vendor lock-in on the evidence.

Post-quantum identity

ML-DSA-65 (FIPS 204) capability tokens, 15-minute expiry, fail-closed verification. In a market where 87% plan PQC but only 7% deploy, this is live.

How it works, in one diagram

The Loom pipeline — the same architecture documented in the enterprise package, rendered live.

flowchart TB
    classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
    classDef gate fill:#f59e0b,stroke:#b45309,color:#000000
    classDef store fill:#64748b,stroke:#334155,color:#ffffff
    subgraph Gate["Pre-execution gate"]
        G1{"In scope?"}:::gate
        G2["Refusal sidecar"]:::gate
    end
    subgraph Chain["The Loom"]
        L1["SHA-256 chain
RFC 8785"]:::core L2["ML-DSA-65 sig
NIST L3"]:::core L3["WIMSE DSSE envelope"]:::core L4["Merkle anchor"]:::core end subgraph Store["Storage"] D1["D1 primary"]:::store R2["R2 backup"]:::store end A["Agent action"]:::core --> G1 G1 -->|yes| L1 G1 -->|no| G2 L1 --> L2 --> L3 --> L4 L4 --> D1 D1 --> R2 D1 --> V["Public verify"]:::core
flowchart LR
    classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
    classDef store fill:#64748b,stroke:#334155,color:#ffffff
    classDef external fill:#f59e0b,stroke:#b45309,color:#000000
    A["Agent proposes"]:::external --> G["Pre-execution gate"]:::core
    G --> B["did:key capability
scope-bound"]:::core B --> C["Device-key wrap
AES-GCM"]:::store B --> D["Public DID"]:::core C --> E["PIN re-wrap
PBKDF2"]:::store
timeline
    title P31 audit standards alignment
    2020 : RFC 8785 JSON Canonicalization
    2026-02 : NIST AI Agent Standards Initiative launches
    2026-04 : draft-dembowski agentledger -00
    2026-06 : RFC 9943 SCITT published
    2026-09-08 : draft-wei-aic-jwt -01
    2026-09-15 : draft-sharif-agent-audit-trail -04
    2026-09-20 : draft-gilda-wimse-agent-audit-record -00
    2026-09-23 : P31 v2.0 aligned against all of the above
flowchart TB
    classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
    classDef gap fill:#f59e0b,stroke:#b45309,color:#000000
    subgraph Real["Verified working"]
        A["Tamper-evident hash chain"]:::core
        B["Refusal sidecar"]:::core
        C["WIMSE signed envelopes"]:::core
        D["Merkle batch anchoring"]:::core
    end
    subgraph Gaps["Honest gaps"]
        E["ML-DSA-65 tested, not in production"]:::gap
        F["EU AI Act retention not audited"]:::gap
        G["ISO 42001 not pursued"]:::gap
    end
    A --> E
    B --> E
    C --> F
    D --> G

How it differs

The governance market shows policy and traces. P31's differentiator is an independently verifiable audit record — not a policy dashboard.

Platform What it does P31 difference
Credo AI Policy packs, audit-evidence workflows, risk views. Policy-first. P31 is evidence-first — the chain proves what happened.
Zenity Agent inventory, posture/risk view, runtime controls. Shows posture. P31 proves what actually occurred, verifiable by anyone.
Langfuse / LangSmith Traces + evals, LLM observability. Trace. P31 hash-chains — tamper-evident, not just replayable.
KiloClaw for Organizations Shadow-AI dashboard, SSO/SCIM, scoped access. Manages access. P31 proves the human approval gate and the record.

The line: independently verifiable audit record vs. policy dashboard.

Standards alignment

Verified drafts and staged regulatory deadlines. The architecture is compliant before the standards.

EU AI Act Art. 12
Dec 2, 2027 / Aug 2, 2028
Compliant before the staged high-risk logging deadline (Digital Omnibus, in force Jul 27, 2026).
AI Kill Switch Act
Forensic records
Preserved, tamper-evident records — the refusal sidecar is the evidence layer.
IETF WIMSE audit record
draft-gilda-wimse-agent-audit-record-00
Decision + observed effect, checkable via a canonicalization contract — the Loom records both.
MCP Enterprise-Managed Auth
Okta XAA
P31 MCP servers are aligned for the Anthropic Connectors Directory path.

The honest gaps

We would rather you find these here than during procurement. Disclosed, quantified, and scoped.

For how the audit chain maps to EU AI Act Article 12 and IETF audit drafts — including the honest scope of each — see Compliance.

Cloudflare Access gate
The Loom API verifies Access JWTs, but the audience value is a placeholder in the current deployment — the gate is OFF. Do not treat it as access-controlled today. Configuration step, not a design flaw.
Forge POST endpoint
The workspace Forge proxy forwards without an Access identity check. Lower severity — it renders documents from user input, it does not read family data. Same fix shape as the Loom's.
Custom-domain verify
The public verify endpoint is live on the Pages URL. The custom domain returns a redirect behind domain-level Access — use the Pages URL today; an exemption is a routing change.

Where it plugs in

The distribution paths are open — the governance slot is empty.

Google Agent Gateway

The network-level enforcement point for all agent traffic. The governance slot (hash-chained audit) is empty among current partners.

Anthropic MCP Connectors

Enterprise-managed authorization is GA (Aug 24, 2026), built on Okta XAA. PQC capability tokens complement XAA.

Cloudflare Agent Cloud

P31 runs on the same infrastructure — Workers, Durable Objects, D1. A native governance sidecar.

Available for a governance integration pilot.

Walk the chain, the tokens, or the relay with our engineers. 10–20 hour pilot this month.

[email protected] →