Integrations
OntoGuard Decision Authorization in the AgenTrust Marketplace
OntoGuard makes the semantic authorization decision. TRACE receives execution evidence only after the authorized action is independently evidenced. Listed as a Community Integration — not AgenTrust Verified.
What integrates
OntoGuard evaluates the exact proposed action and returns ALLOW, BLOCK, or ESCALATE with signed authorization material. The adapter does not contain OntoGuard’s authorization engine.
What TRACE receives
A TRACE record is emitted only when an ALLOW is bound to independently signed execution evidence for that exact action. BLOCK, ESCALATE, or ALLOW without a valid execution receipt emit no TRACE record. TRACE is not OntoGuard’s native audit format. AgenTrust does not perform OntoGuard’s semantic decision.
What was independently reproduced
Before merge, an AgenTrust maintainer reproduced the adapter tests and live harness against agenttrust-trace 0.10.0:
- 27 / 27 adapter tests passed
- Historical controlled proof passed
- Live executor path passed
Authorized case — $250,000
The frozen authorized action was executed: PENDING → RELEASED, commit_count=1, ALLOW_EXECUTION_PROVEN, TRACE emitted.
Material-change case — $260,000
The amount was mutated after authorization. Execution was refused. State remained PENDING. commit_count=0. No TRACE emitted. A changed action is a new action.
What this does not claim
Related: ALLOW vs BLOCK vs ESCALATE · Proof Explorer · Headless Runtime.