GGuardState
THE CONTROL PLANE FOR AGENTIC FINANCEGUARDSTATE CLOUD
Share Evaluation

Share operating evidence without sharing authority.

GuardState evaluation artifacts are workspace-scoped, viewer-bound, permission-limited, expiring, revocable, and integrity-checked. Production sharing stays unavailable until durable revocation and customer evidence persistence are commissioned.

BOUND

Tenant and evaluation scope

Every token binds organization, workspace, evaluation, viewer reference, permission, nonce, issue time, and expiry.

REVOCABLE

Durable production revocation

Ephemeral revocation is allowed for tests only. Production verification fails closed unless a durable revocation store is present.

REDACTED

No credential fields

Safe artifacts reject secrets, passwords, tokens, API keys, private keys, seed phrases, cookies, and authorization fields.

Current public state: implementation foundation verified in source and tests; hosted customer-data sharing is NOT COMMISSIONED on this public deployment.
Eligible report content

Evidence, not credentials.

Architecture, Agent Passport, AIBOM, Mandate, Authority Envelope, Blast Radius, Verified Control Coverage, evaluations, replay, reconciliation, Conflict Provenance, Control Effectiveness, evidence gaps, and commissioning plan.

Authority limit

A share token never authorizes finance.

VIEW_REPORT and DOWNLOAD_EVIDENCE_PACK are the only sharing permissions. Neither creates, confirms, modifies, cancels, or executes a financial action.