Agent Governance · Post-Quantum Identity · Independent Evidence
The audit trail your agents don't have — and can't fake.
IDC reports that most enterprises cannot verify what their AI agents actually do — 60% of security leaders lack basic agent containment, and 35% cannot shut down a rogue agent. The record of what happened often does not exist at all.
P31's Loom is that record — live, hash-chained, PQC-signed, and independently verifiable on Cloudflare Workers.
The gap is the market
IDC, September 2026: 'The Audit Trail That Doesn't Exist.' Governance spend is the answer — agent observability & governance is a $1.68B (2026) → $8.62B (2031) market at 38.69% CAGR.
of security leaders lack basic agent containment controls.
cannot shut down a rogue agent once deployed.
agent observability & governance, 2026 → 2031 (38.69% CAGR).
Verify it yourself — ninety seconds
Three commands. No account. The chain recomputes from genesis and returns the current head.
# 1 · The Loom chain — recomputes and verifies
curl -s https://b30e37b5.loom-8z0.pages.dev/api/loom-public/verify | python3 -m json.tool
# 2 · The MCP tool registry
curl -s https://mcp-registry.trimtab-signal.workers.dev/servers | python3 -m json.tool
# 3 · A flagship live
open https://p31ca.org/apps/loom
Expected from #1: {"valid": true, "checked": 16, "brokenAt": null} — a live request against a deployed endpoint, not a screenshot.
Three proofs, all live
Every capability resolves to a running service or a published standard.
Pre-execution enforcement
guardAgentEvent runs before commit — refusals are recorded, not reconstructed. A denied action never reaches the log as if it happened.
Hash-chained evidence
RFC 8785 canonicalization + SHA-256. The chain is independently verifiable at a public endpoint — no vendor lock-in on the evidence.
Post-quantum identity
ML-DSA-65 (FIPS 204) capability tokens, 15-minute expiry, fail-closed verification. In a market where 87% plan PQC but only 7% deploy, this is live.
How it works, in one diagram
The Loom pipeline — the same architecture documented in the enterprise package, rendered live.
flowchart TB
classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
classDef gate fill:#f59e0b,stroke:#b45309,color:#000000
classDef store fill:#64748b,stroke:#334155,color:#ffffff
subgraph Gate["Pre-execution gate"]
G1{"In scope?"}:::gate
G2["Refusal sidecar"]:::gate
end
subgraph Chain["The Loom"]
L1["SHA-256 chain
RFC 8785"]:::core
L2["ML-DSA-65 sig
NIST L3"]:::core
L3["WIMSE DSSE envelope"]:::core
L4["Merkle anchor"]:::core
end
subgraph Store["Storage"]
D1["D1 primary"]:::store
R2["R2 backup"]:::store
end
A["Agent action"]:::core --> G1
G1 -->|yes| L1
G1 -->|no| G2
L1 --> L2 --> L3 --> L4
L4 --> D1
D1 --> R2
D1 --> V["Public verify"]:::core
flowchart LR
classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
classDef store fill:#64748b,stroke:#334155,color:#ffffff
classDef external fill:#f59e0b,stroke:#b45309,color:#000000
A["Agent proposes"]:::external --> G["Pre-execution gate"]:::core
G --> B["did:key capability
scope-bound"]:::core
B --> C["Device-key wrap
AES-GCM"]:::store
B --> D["Public DID"]:::core
C --> E["PIN re-wrap
PBKDF2"]:::store
timeline
title P31 audit standards alignment
2020 : RFC 8785 JSON Canonicalization
2026-02 : NIST AI Agent Standards Initiative launches
2026-04 : draft-dembowski agentledger -00
2026-06 : RFC 9943 SCITT published
2026-09-08 : draft-wei-aic-jwt -01
2026-09-15 : draft-sharif-agent-audit-trail -04
2026-09-20 : draft-gilda-wimse-agent-audit-record -00
2026-09-23 : P31 v2.0 aligned against all of the above
flowchart TB
classDef core fill:#2563eb,stroke:#1e40af,color:#ffffff
classDef gap fill:#f59e0b,stroke:#b45309,color:#000000
subgraph Real["Verified working"]
A["Tamper-evident hash chain"]:::core
B["Refusal sidecar"]:::core
C["WIMSE signed envelopes"]:::core
D["Merkle batch anchoring"]:::core
end
subgraph Gaps["Honest gaps"]
E["ML-DSA-65 tested, not in production"]:::gap
F["EU AI Act retention not audited"]:::gap
G["ISO 42001 not pursued"]:::gap
end
A --> E
B --> E
C --> F
D --> G
How it differs
The governance market shows policy and traces. P31's differentiator is an independently verifiable audit record — not a policy dashboard.
| Platform | What it does | P31 difference |
|---|---|---|
| Credo AI | Policy packs, audit-evidence workflows, risk views. | Policy-first. P31 is evidence-first — the chain proves what happened. |
| Zenity | Agent inventory, posture/risk view, runtime controls. | Shows posture. P31 proves what actually occurred, verifiable by anyone. |
| Langfuse / LangSmith | Traces + evals, LLM observability. | Trace. P31 hash-chains — tamper-evident, not just replayable. |
| KiloClaw for Organizations | Shadow-AI dashboard, SSO/SCIM, scoped access. | Manages access. P31 proves the human approval gate and the record. |
The line: independently verifiable audit record vs. policy dashboard.
Standards alignment
Verified drafts and staged regulatory deadlines. The architecture is compliant before the standards.
The honest gaps
We would rather you find these here than during procurement. Disclosed, quantified, and scoped.
For how the audit chain maps to EU AI Act Article 12 and IETF audit drafts — including the honest scope of each — see Compliance.
Where it plugs in
The distribution paths are open — the governance slot is empty.
The network-level enforcement point for all agent traffic. The governance slot (hash-chained audit) is empty among current partners.
Enterprise-managed authorization is GA (Aug 24, 2026), built on Okta XAA. PQC capability tokens complement XAA.
P31 runs on the same infrastructure — Workers, Durable Objects, D1. A native governance sidecar.
Available for a governance integration pilot.
Walk the chain, the tokens, or the relay with our engineers. 10–20 hour pilot this month.
[email protected] →