Proof artifact

If this decision is challenged later, can you prove what happened?

A Governed Event Receipt is the record StreamKernel preserves for one governed execution: what ran, which policy version decided, which route was selected, which model or transform context was active, what provenance was stamped, and which audit-chain reference connects the event to the wider run. It is written while the decision executes, not reconstructed afterwards.

Samples

Two governed executions, two receipts.

Both samples use synthetic data and the field names emitted by the corresponding pipeline in the StreamKernel runtime. They are collateral for inspection, not a certification, accreditation, or production customer reference.

Financial services

Credit / fraud / AML decision event

A declined credit decision routed to AML case review because a sanctions screening hit combined with an elevated fraud device signal. The receipt records which policy version decided, which domain evidence contributed, what the transform chain ran, and where the event went.

{
  "artifact_type": "Governed Event Receipt",
  "final_decision": "DECLINE",
  "decision_route": "aml_case_review",
  "case_priority": "P1",
  "policy_version": "financial-credit-fraud-aml-v1",
  "policy_sha256": "sha256:3ab41c9d...",
  "enforcement_model": "inline_fail_closed",
  "transform_chain": [
    "DJL_EMBEDDING",
    "EMBEDDING_TO_WIREEVENT",
    "CREDIT_FRAUD_AML_DECISION"
  ],
  "aml.sanctions.hit": true,
  "event_hash": "sha256:6d2a91fb..."
}

Healthcare

PHI-aware governed AI pipeline

A clinical event allowed with redaction. The receipt records which PHI fields were detected, that redaction was applied, that raw text was not retained, and the digest of the source text so the decision stays reconstructable without storing the sensitive payload.

{
  "artifact_type": "Governed Event Receipt",
  "policy_decision": "ALLOW_WITH_REDACTION",
  "route": "audit_review",
  "transform_chain": [
    "STRING_TO_WIREEVENT",
    "DJL_EMBEDDING",
    "PHI_GUARDRAIL"
  ],
  "redaction_applied": true,
  "raw_text_retained": false,
  "event_hash": "sha256:225b4188..."
}

What it answers

The questions a receipt has to survive.

A governed decision is only defensible if someone can answer these six questions months later without reconstructing the path from logs, traces, warehouse tables, and vendor consoles.

Which policy decided, and which version of it?

Policy version and policy SHA-256 are recorded on the receipt, alongside the decision, route, case priority, and reason codes.

Which model ran, and was it the approved one?

Model name, version, runtime, execution mode, and model reference digest are recorded. In-process execution means the model identity is known at the moment of the decision, not inferred afterwards.

Did sensitive data reach somewhere it should not have?

The receipt records detected sensitive fields, redaction posture, whether raw text was retained, and a digest of the source text rather than the payload itself.

Was the control actually enforced, or only logged?

The enforcement model and fail-closed posture are on the receipt. StreamKernel is explicit about authorization granularity: a cached admission gate is recorded as a cached admission gate, not as per-event authorization.

Where did the event go afterwards?

Downstream disposition records the destination, whether delivery occurred, and whether the event was routed to a dead-letter path.

Can the sequence be verified?

The audit chain records the hash algorithm, canonicalization rule, previous event hash, and current event hash. The chain is per-runtime-instance; correlating a multi-hop path across instances requires stitching on run and event identifiers.

Receipt contents

Readable by buyers, auditors, and engineers.

The receipt is deliberately concrete. It gives reviewers a one-event artifact before they need to reconstruct the path from logs, metrics, Kafka headers, workflow cases, or audit JSONL.

Receipt

Schema version, receipt id, creation time, artifact type, data class, and a plain claim boundary so the artifact never implies certification or regulatory approval.

Event

Pipeline id, run id, event id, event type, source, sink, topic, timestamp, and sequence context for the execution being inspected.

Decision

Final decision, route, case priority, decision basis, reason codes, thresholds, policy version, and policy SHA-256.

Model and transform

Model name, version, runtime, execution mode, and model reference digest, plus the transform chain that actually ran on the event.

Authorization

Enforcement model, fail-closed posture, authorization granularity, and the pipeline identity used. A cached admission gate is recorded as a cached admission gate, not as per-event authorization.

Payload evidence

Source-text digest, redaction posture, retention posture, and resolved field aliases, so sensitive payloads do not have to be stored to keep the decision reconstructable.

Provenance

The streamkernel.provenance.* headers and use-case headers emitted with the governed event, scoped to what this runtime instance observed and executed.

Audit chain

Hash algorithm, canonicalization rule, previous event hash, current event hash, chain scope, and audit path.

Disposition and attachments

Downstream destination, delivery and DLQ status, plus links back to the use case, demo steps, evidence checklist, pipeline profile, and benchmark matrix that make the receipt replayable.

Claim boundary

Proof-backed without overclaiming.

StreamKernel's external claim boundary is intentionally explicit: what is proven in the current build, what belongs in a scoped pilot, and what is not claimed yet.

Proven today

  • Inline fail-closed authorization gates on the event-execution path.
  • Embedded MCP control plane with 22 registered tools: 16 read-only tools and 6 guarded mutations in the current codebase.
  • Per-event provenance headers for pipeline, run, transform, config, model, and policy context where configured.
  • Tamper-evident MCP audit hash chains when hash chaining is enabled.
  • CostProof-style routing, budget caps, circuit-breaker behavior, and spend audit records in the frontier-agentic benchmark lane.
  • Air-gap, on-prem, and embedded deployment posture by design with no required SaaS control plane.
  • Reproducible in-house benchmark rows with matrix files, pipeline configs, logs, metrics snapshots, and metadata.

Scoped pilot work

  • Integration into a customer's event topology, policy source, identity boundary, and downstream systems.
  • Customer-specific MCP allowlists, authorization policy, audit retention, and case-system integration.
  • Customer-specific evidence schemas, audit exports, and sink-side verification.
  • Multi-node tuning and customer-volume validation against real event shapes and real sinks.
  • Enclave-specific packaging, deployment hardening, and operational runbooks.

Not claimed yet

  • Certification, accreditation, FedRAMP authorization, SCIF approval, or NIPRNet authorization without the customer's formal assessment process.
  • Fully autonomous multi-agent handoff governance at production scale.
  • Prebuilt regulatory policy-pack libraries for EU AI Act, NIST, ISO, or agency-specific control mappings out of the box.
  • Cryptographic human-attestation binding in the hot path; AuthorityProof remains a separate sidecar proof lane.
  • Production enterprise references at scale; StreamKernel is early-stage and pre-revenue.

Governance note: technical evidence is not a substitute for the customer's formal compliance, accreditation, security, or authorization process.

Commercial path

Start with one event lane and one receipt.

A focused evaluation should prove which policy, model, route, cost posture, action, and sink contract applied before the event moved on.