Integrations

OntoGuard Decision Authorization in the AgenTrust Marketplace

OntoGuard makes the semantic authorization decision. TRACE receives execution evidence only after the authorized action is independently evidenced. Listed as a Community Integration — not AgenTrust Verified.

What integrates

OntoGuard evaluates the exact proposed action and returns ALLOW, BLOCK, or ESCALATE with signed authorization material. The adapter does not contain OntoGuard’s authorization engine.

What TRACE receives

A TRACE record is emitted only when an ALLOW is bound to independently signed execution evidence for that exact action. BLOCK, ESCALATE, or ALLOW without a valid execution receipt emit no TRACE record. TRACE is not OntoGuard’s native audit format. AgenTrust does not perform OntoGuard’s semantic decision.

What was independently reproduced

Before merge, an AgenTrust maintainer reproduced the adapter tests and live harness against agenttrust-trace 0.10.0:

  • 27 / 27 adapter tests passed
  • Historical controlled proof passed
  • Live executor path passed

Authorized case — $250,000

The frozen authorized action was executed: PENDING → RELEASED, commit_count=1, ALLOW_EXECUTION_PROVEN, TRACE emitted.

Material-change case — $260,000

The amount was mutated after authorization. Execution was refused. State remained PENDING. commit_count=0. No TRACE emitted. A changed action is a new action.

What this does not claim

No hardware attestation. No production-wide non-bypassability. No customer-production L5. No AgenTrust Verified status. No OPAQUE partnership. Community Marketplace listings are technical integrations, not certification or commercial approval.

AgenTrust Marketplace Integration source Merged PR #201