{"_id":"@absuitecore/trust","_rev":"6-d241a14801766488a54d7999a443c0e2","name":"@absuitecore/trust","dist-tags":{"latest":"1.1.3"},"versions":{"1.0.0":{"name":"@absuitecore/trust","version":"1.0.0","keywords":["ai-governance","trust-score","agent-monitoring","hallucination","grounding","arbitration","ai-safety"],"license":"MIT","_id":"@absuitecore/trust@1.0.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"808db58a8eb386aa342ed2dfdc6aa52b58be070b","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.0.0.tgz","fileCount":19,"integrity":"sha512-RZUNoUcow77zfPv+AO3xjPGMTG5xtN0PjIwUqjsvhX6aWif5GqPVlAyJERE8dVbIQOq93jut9i1NzS6gZGgTYQ==","signatures":[{"sig":"MEYCIQCh3nq+4Dwf2k/mdtaxrL+6HlaaV2Lo9/SX+x2+JNSt8gIhAMWXDRo2evZ+8pcoD8YAIHpSWoDGcQvaeuwhbLIEtym2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":163662},"main":"dist/index.js","_from":"file:absuitecore-trust-1.0.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/6446f682296dac51bff4304db7ccd084/absuitecore-trust-1.0.0.tgz","_integrity":"sha512-RZUNoUcow77zfPv+AO3xjPGMTG5xtN0PjIwUqjsvhX6aWif5GqPVlAyJERE8dVbIQOq93jut9i1NzS6gZGgTYQ==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/trust"},"_npmVersion":"10.9.8","description":"Evidence-based trust for multi-agent systems: explainable scores, output grounding checks, agent-to-agent monitoring, correlation-aware arbitration and reciprocal contracts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0","@absuitecore/capkit":"1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.0.0_1785297891950_0.9731228296160819","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"@absuitecore/trust","version":"1.0.1","keywords":["ai-governance","trust-score","agent-monitoring","hallucination","grounding","arbitration","ai-safety"],"license":"MIT","_id":"@absuitecore/trust@1.0.1","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"cc8a01554c4ad5f77e537b2b5ca156e4e4136685","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.0.1.tgz","fileCount":19,"integrity":"sha512-Dy+rdvpLjeNcydCPPC2iIv5Bp82lW/TMkAlpI7NABIAayq2mipXpflmlKa4cnsORidWEeLSj94SYnXq+wn6/PQ==","signatures":[{"sig":"MEUCICIPT8aPcRG5FFjpnvXmlRNn+qDuBWFfcOaffYY17q6aAiEAvkD3XADhUXtP33vX1fRqOZ3ItM1VoV1ZeBU0mEMslxE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.0.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":163663},"main":"dist/index.js","_from":"file:absuitecore-trust-1.0.1.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/35d2ae69df36cf08d27db5e343d1eb9b/absuitecore-trust-1.0.1.tgz","_integrity":"sha512-Dy+rdvpLjeNcydCPPC2iIv5Bp82lW/TMkAlpI7NABIAayq2mipXpflmlKa4cnsORidWEeLSj94SYnXq+wn6/PQ==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/trust"},"_npmVersion":"10.9.8","description":"Evidence-based trust for multi-agent systems: explainable scores, output grounding checks, agent-to-agent monitoring, correlation-aware arbitration and reciprocal contracts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0","@absuitecore/capkit":"^1.0.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.0.1_1785316095265_0.2759341415998049","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"@absuitecore/trust","version":"1.1.0","keywords":["ai-governance","trust-score","agent-monitoring","hallucination","grounding","arbitration","ai-safety"],"license":"MIT","_id":"@absuitecore/trust@1.1.0","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"09a672d3be94025a62556688c8de79888bbb3b77","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.1.0.tgz","fileCount":19,"integrity":"sha512-9tAOicEzPIt+SBe3zIlfk/gnM5qGzk9kwoItm5fGNsfdlB+hohwg/q9fuHRVd3GTayF6H1gUE6TmycsDDpTITA==","signatures":[{"sig":"MEUCIAc1mhiuz5VZnf8hLdA8iQCJmlO47wQVmydmxo8xlMCkAiEAlNd7VgRYtaXknZ8LUfnREVaLA/19Z9g3WhCh1Y1Un+c=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":164375},"main":"dist/index.js","_from":"file:absuitecore-trust-1.1.0.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/f083d826136df6671f4bfa7d8848a4cb/absuitecore-trust-1.1.0.tgz","_integrity":"sha512-9tAOicEzPIt+SBe3zIlfk/gnM5qGzk9kwoItm5fGNsfdlB+hohwg/q9fuHRVd3GTayF6H1gUE6TmycsDDpTITA==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/trust"},"_npmVersion":"10.9.8","description":"Evidence-based trust for multi-agent systems: explainable scores, output grounding checks, agent-to-agent monitoring, correlation-aware arbitration and reciprocal contracts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0","@absuitecore/capkit":"^1.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.1.0_1785317364146_0.17169817825540568","host":"s3://npm-registry-packages-npm-production"}},"1.1.1":{"name":"@absuitecore/trust","version":"1.1.1","keywords":["evidence-validation","grounding","provenance","ai-governance","agent-monitoring","arbitration","ai-safety","ai-agents","audit"],"license":"MIT","_id":"@absuitecore/trust@1.1.1","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"0d5a2e8fca034e2a840a4aae395552ff6d3e1282","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.1.1.tgz","fileCount":19,"integrity":"sha512-d1y+Sz8Pgd4D1M5hAsddkjylD9cMA4oU0pZOoJ7pLAcxW+dU2JQO6ZW4vIfhZC9ax+gMPm+wAu9dHj5+tyjfcg==","signatures":[{"sig":"MEUCIQDKeupFKjCdG+QG6V8Wbq61eW2c0lWb2SE4tBSkU9ssaQIgFLbSErBVoT19vyx+BKrWkOGybP/bO8PAdDyqxS+z/PU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":164470},"main":"dist/index.js","_from":"file:absuitecore-trust-1.1.1.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/b298a795f5f1fe7f6ca6a44eca4b7c8e/absuitecore-trust-1.1.1.tgz","_integrity":"sha512-d1y+Sz8Pgd4D1M5hAsddkjylD9cMA4oU0pZOoJ7pLAcxW+dU2JQO6ZW4vIfhZC9ax+gMPm+wAu9dHj5+tyjfcg==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/trust"},"_npmVersion":"10.9.8","description":"Evidence validation for AI systems: claims checked against their sources and reported SUPPORTED, UNVERIFIED or CONTRADICTED — never a probability. Plus agent-chain monitoring, correlation-aware arbitration and reciprocal contracts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0","@absuitecore/capkit":"^1.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.1.1_1785320184199_0.8676522275912979","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@absuitecore/trust","version":"1.1.2","keywords":["evidence-validation","grounding","provenance","ai-governance","agent-monitoring","arbitration","ai-safety","ai-agents","audit"],"license":"MIT","_id":"@absuitecore/trust@1.1.2","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"dist":{"shasum":"482b86e8471e525574e0b7a46d4ce514ad999d1e","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.1.2.tgz","fileCount":19,"integrity":"sha512-GeSr8c+wQCoTyFMW8QOqyIMB2EtAWU9T4bi0fErDhdRMi66KFpjkHBz8ZCSgNhJZQ0JvL2x0vCihiybYLQ5O3A==","signatures":[{"sig":"MEYCIQCCWWEBq3J3HtYodd1Xd/Jcce195mT79MzEY0WwIsNE8AIhALuwXRn/QN4aOfPrR9++WbRJYOQMBFfY8Fc7esGBQcfz","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":166416},"main":"dist/index.js","_from":"file:absuitecore-trust-1.1.2.tgz","types":"dist/index.d.ts","engines":{"node":">=22.5.0"},"scripts":{"dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust","build":"tsc -p tsconfig.json","start":"node dist/server.js"},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"_resolved":"/tmp/97cb7ce6b65b38a74a0c886c1dba7a50/absuitecore-trust-1.1.2.tgz","_integrity":"sha512-GeSr8c+wQCoTyFMW8QOqyIMB2EtAWU9T4bi0fErDhdRMi66KFpjkHBz8ZCSgNhJZQ0JvL2x0vCihiybYLQ5O3A==","repository":{"url":"git+https://github.com/iamGodofall/ABSuite-core.git","type":"git","directory":"packages/trust"},"_npmVersion":"10.9.8","description":"Evidence validation for AI systems: claims checked against their sources and reported SUPPORTED, UNVERIFIED or CONTRADICTED — never a probability. Plus agent-chain monitoring, correlation-aware arbitration and reciprocal contracts.","directories":{},"_nodeVersion":"22.23.1","dependencies":{"express":"^4.18.0","@absuitecore/capkit":"^1.2.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","typescript":"^5.0.0","@types/node":"^22.0.0","@types/express":"^4.17.21"},"_npmOperationalInternal":{"tmp":"tmp/trust_1.1.2_1785669575241_0.20058261416726264","host":"s3://npm-registry-packages-npm-production"}},"1.1.3":{"name":"@absuitecore/trust","version":"1.1.3","description":"Evidence validation for AI systems: claims checked against their sources and reported SUPPORTED, UNVERIFIED or CONTRADICTED — never a probability. Plus agent-chain monitoring, correlation-aware arbitration and reciprocal contracts.","license":"MIT","main":"dist/index.js","types":"dist/index.d.ts","keywords":["evidence-validation","grounding","provenance","ai-governance","agent-monitoring","arbitration","ai-safety","ai-agents","audit"],"dependencies":{"express":"^4.18.0","@absuitecore/capkit":"^1.3.1"},"devDependencies":{"@types/express":"^4.17.21","@types/node":"^22.0.0","tsx":"^4.21.0","typescript":"^5.0.0"},"engines":{"node":">=22.5.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/iamGodofall/ABSuite-core.git","directory":"packages/trust"},"homepage":"https://github.com/iamGodofall/ABSuite-core#readme","bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"scripts":{"build":"tsc -p tsconfig.json","start":"node dist/server.js","dev":"tsx src/server.ts","test":"jest -c ../../jest.config.js --rootDir ../.. --testPathPatterns packages/trust"},"_id":"@absuitecore/trust@1.1.3","_integrity":"sha512-WT2Po0bdb+r4OMsQ20y4jGTVAQIOIvHDXUBDEM0mxyBHFNoR1Y4C7s0ESfPj3HSVW00Y1q2PRu5zRUvdnB5+Pw==","_resolved":"/tmp/a72ca6598a8f3282dc618557fb0a33c7/absuitecore-trust-1.1.3.tgz","_from":"file:absuitecore-trust-1.1.3.tgz","_nodeVersion":"22.23.1","_npmVersion":"10.9.8","dist":{"integrity":"sha512-WT2Po0bdb+r4OMsQ20y4jGTVAQIOIvHDXUBDEM0mxyBHFNoR1Y4C7s0ESfPj3HSVW00Y1q2PRu5zRUvdnB5+Pw==","shasum":"6fa5595352ec8a44b804bafcbec3ff61ae1a789e","tarball":"https://registry.npmjs.org/@absuitecore/trust/-/trust-1.1.3.tgz","fileCount":19,"unpackedSize":166464,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@absuitecore%2ftrust@1.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIF22R7mkHvCz3PxrtlQKdDb7s3c/pSP0N26ox2v8rNsTAiEA8fPFr96+38o9+sR2NzBUzUzrwAaXWuXHO+0+jz2ZW+E="}]},"_npmUser":{"name":"themba-mpehle","email":"landinwest@gmail.com"},"directories":{},"maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/trust_1.1.3_1785684246241_0.8585542204610348"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-29T04:04:51.850Z","modified":"2026-08-02T15:24:06.734Z","1.0.0":"2026-07-29T04:04:52.103Z","1.0.1":"2026-07-29T09:08:15.417Z","1.1.0":"2026-07-29T09:29:24.296Z","1.1.1":"2026-07-29T10:16:24.348Z","1.1.2":"2026-08-02T11:19:35.378Z","1.1.3":"2026-08-02T15:24:06.404Z"},"bugs":{"url":"https://github.com/iamGodofall/ABSuite-core/issues"},"license":"MIT","homepage":"https://github.com/iamGodofall/ABSuite-core#readme","keywords":["evidence-validation","grounding","provenance","ai-governance","agent-monitoring","arbitration","ai-safety","ai-agents","audit"],"repository":{"type":"git","url":"git+https://github.com/iamGodofall/ABSuite-core.git","directory":"packages/trust"},"description":"Evidence validation for AI systems: claims checked against their sources and reported SUPPORTED, UNVERIFIED or CONTRADICTED — never a probability. Plus agent-chain monitoring, correlation-aware arbitration and reciprocal contracts.","maintainers":[{"name":"themba-mpehle","email":"landinwest@gmail.com"}],"readme":"# @absuitecore/trust\n\nEvidence-based trust for multi-agent systems.\n\nEvery judgement this package makes is a pure function of recorded events, each\npointing at a verifiable artefact — an execution trace, an audit entry, a\nsigned attestation. That is the whole design constraint, and everything below\nfollows from it: a score you can interrogate, contest, and reproduce months\nlater is evidence. One you cannot is a black-box rating that quietly ruins\nsomeone's day.\n\n```bash\nnpm install @absuitecore/trust\n```\n\nRequires Node 22.5+ (uses `node:sqlite`). Service runs on `:8085`.\n\n---\n\n## What it does\n\n| Capability | What it actually gives you |\n|---|---|\n| **Trust events** | An append-only evidence store with a working appeals process. |\n| **Scoring** | Explainable, time-decaying, confidence-bounded scores — advisory by default. |\n| **Output verification** | Grounding and contradiction signals against supplied sources. |\n| **Chain monitoring** | Structural facts about agent-to-agent chains: cycles, runaways, stalls, observer disagreement. |\n| **Arbitration** | Dispute resolution that discounts correlated agreement and escalates rather than guessing. |\n| **Reciprocal contracts** | Obligations that run both ways, so an operator's failures stop being charged to the agent. |\n\n---\n\n## Four things this package deliberately refuses to do\n\nThese are the design decisions, not caveats bolted on afterwards. Each one\nexists because the obvious alternative causes a specific, predictable harm.\n\n### 1. It does not detect hallucinations\n\nDeciding whether an arbitrary statement is true is open-domain fact-checking.\nNobody can do it, and a product claiming to is a classifier with a confident\nvoice — the fastest possible route to a customer getting sued after trusting it.\n\nWhat `verifyOutput` answers instead is a closed-domain question that *does* have\na real answer: **does this output assert things its own sources do not support?**\n\n```ts\nimport { verifyOutput, renderReport } from '@absuitecore/trust';\n\nconst report = verifyOutput(\n  'The CEO approved this.',\n  ['The Q3 report shows revenue of $4.2M, up 23% year over year.']\n);\n\nconsole.log(renderReport(report));\n// Claim:    The CEO approved this\n// Evidence: none\n//           missing: 0/2 content words in sources\n// Status:   UNVERIFIED\n```\n\nFour statuses and deliberately no fifth. There is no `LIKELY_FALSE` and no\nprobability:\n\n| Status | Means |\n|---|---|\n| `SUPPORTED` | Every checkable element traces to a source. Not \"true\". |\n| `UNVERIFIED` | Evidence is absent. **Not** a claim of falsehood — it may be correct and merely unsourced. |\n| `CONTRADICTED` | The output disagrees with itself. The only status asserting a defect. |\n| `NOT_CHECKED` | No sources supplied; nothing could be assessed. |\n\nThree signals, in descending order of reliability:\n\n1. **Verbatim anchors** — figures, quotes, DOIs, URLs present in the output and\n   absent from the sources. Fabricated numbers and invented citations are the\n   highest-cost failure and are exactly detectable, no judgement required.\n   Magnitude suffixes count: `$4.2M` and `$4.2B` are different claims.\n2. **Lexical grounding** — how much of a claim's vocabulary appears in the\n   sources. Weak on its own, so it is reported as coverage with the matched\n   terms attached, and never becomes a permanent mark against a subject.\n3. **Self-contradiction** — two claims in one output with opposite polarity\n   about the same subject, or two values for the same quantity. Needs no\n   external truth at all, and is always a defect.\n\nEvery report carries a disclaimer stating what was and was not checked. A clean\nreport means every claim traces to a source — **not** that the output is true.\n\n### 2. It does not gate access by default\n\n`gating` is false unless an operator explicitly turns it on. Scores inform\nhumans; they do not silently deny anyone. Even with gating enabled, a subject\nwith confidence below 0.5 is **allowed**, because refusing someone on four data\npoints is not a decision anyone can defend.\n\n```ts\nscorer.check('agent:invoicing', 'agent', 70);\n// { allowed: true, advisory: true,\n//   reason: 'Advisory only. Score 62/70 (moderate); gating is disabled...' }\n```\n\n### 3. It does not score people — it counts what they did\n\nABSuite will not tell you John has a trust score of 42. `evidenceRecord()`\nreports facts:\n\n```ts\nscorer.evidence('person:j.smith', 'human');\n// { eventsRecorded: 1042, policyViolations: 2,\n//   manualOverrides: 1, auditFindings: 0,\n//   note: 'These are recorded facts, not an assessment...' }\n```\n\nThe object has no `score` field and cannot be given one. It needs no flag and\nhas no off switch, because counting what happened is not the same act as rating\na person.\n\nProducing an actual *score* for a human throws unless\n`ABSUITE_TRUST_SCORE_HUMANS=true`. That is an employee-monitoring capability with\nreal obligations attached — GDPR Art. 22 among them — and a deployment should\nacquire it deliberately, not as a side effect of installing a package.\n\n### 4. It does not treat agreement as corroboration\n\nModel errors are *correlated*. Five deployments of one base model fail on the\nsame inputs in the same direction, so a 5-0 \"consensus\" among them is one\nopinion counted five times wearing the costume of overwhelming agreement.\n\n```ts\narbitrate({\n  question: 'Approve the refund?',\n  positions: [\n    { agentId: 'a1', answer: 'yes', family: 'openai:gpt-4' },\n    { agentId: 'a2', answer: 'yes', family: 'openai:gpt-4' },\n    { agentId: 'a3', answer: 'yes', family: 'openai:gpt-4' },\n    { agentId: 'a4', answer: 'yes', family: 'openai:gpt-4' },\n    { agentId: 'a5', answer: 'yes', family: 'openai:gpt-4' },\n    { agentId: 'b1', answer: 'no',  family: 'anthropic:claude' },\n    { agentId: 'c1', answer: 'no',  family: 'google:gemini' },\n  ],\n  /* ... */\n});\n// outcome: 'no_consensus'  — a naive 5-2 vote says \"yes\" decisively\n```\n\nThe arbitrator also:\n\n- **weights by recorded behaviour, not by confidence** — self-reported certainty\n  is uncorrelated with accuracy and trivially gamed, so its influence is capped\n  and it can never decide an outcome on its own;\n- **requires the leader to have more independent support than the runner-up**,\n  so weight alone never settles a dispute;\n- **always escalates an irreversible dispute**, whatever the tally. Deleting\n  production data on a majority vote among language models is not shippable.\n\nEscalations come with a brief written for the person who has to decide, ending\nwith `No action has been taken. This decision is yours.`\n\n---\n\n## Reciprocal contracts\n\nEvery governance product in this space constrains the agent. That is necessary\nand insufficient — a large share of real incidents are the agent behaving\nexactly as instructed on inputs that were wrong. Stale credentials. A tool that\nsilently changed shape. In each case the agent is blamed for a failure it could\nnot have avoided, and the actual defect goes unrecorded.\n\n```ts\nconst trust = new ReciprocalTrust(storage, events);\nconst contract = trust.establish('agent:invoicing', 'acme-corp');\n\ntrust.recordBreach(contract.id, 'valid_credentials', 'API key expired three days ago');\n\ntrust.health(contract.id);\n// { faultAttribution: 'operator',\n//   recommendation: '...The agent is largely failing because of its\n//                    environment; fixing the environment will do more than\n//                    constraining the agent further.' }\n```\n\nFive obligations each way. An operator breach is recorded against the operator\nand **never** charged to the agent's score — attributing a fault to the\ncomponent that cannot fix it is both unfair and diagnostically useless.\n\n---\n\n## Appeals\n\nA score nobody can challenge is a blacklist.\n\n```ts\nconst appeal = events.appeal(eventId, 'agent-owner@acme', 'Caused by an expired operator credential');\nevents.decideAppeal(appeal.id, 'reviewer@acme', true, 'Upheld — operator fault');\n```\n\nUpholding an appeal neutralises the original event and records a *repairing*\nevent, so a wrongly penalised subject ends up no worse off than before. The\noriginal is never deleted: the record of what happened, mistake included, has\nto survive.\n\n---\n\n## Chain monitoring\n\nRecords structural facts about who invoked whom — facts that are true\nregardless of anyone's judgement, which is why they can be trusted without\ntrusting any agent involved.\n\n```ts\nmonitor.summarise('chain_abc');\n// anomalies: [{ kind: 'cycle', severity: 'critical',\n//               detail: 'Agents call each other in a loop: a -> b -> c -> a...' }]\n```\n\nDetects cycles, excessive depth, runaway fan-out, stalls, and **observer\ndisagreement**. Disagreement is surfaced, never resolved by majority — two\nobservers splitting on the same evidence is exactly where a human should look,\nand quietly picking the more numerous side throws away the only signal that\nmattered.\n\n---\n\n## HTTP API\n\nSee [`docs/API.md`](https://github.com/iamGodofall/ABSuite-core/blob/main/docs/API.md) for the generated reference. Every route\nis guarded by the same `capabilityGuard` the rest of the suite uses — a service\nthat grades other services is the last one you want reachable without a token.\n\nScopes: `trust:read`, `trust:write`, `trust:verify`, `trust:arbitrate`,\n`trust:appeal`, `trust:manage`.\n\n## Environment\n\n| Variable | Default | Purpose |\n|---|---|---|\n| `TRUST_PORT` | `8085` | Listen port |\n| `ABSUITE_DB_PATH` | in-memory | SQLite file, shared with the rest of the suite |\n| `CAPKIT_HMAC_SECRET` | — | Required; verifies capability tokens |\n| `CAPKIT_ADMIN_KEY` | — | Bootstrap credential |\n| `ABSUITE_TRUST_SCORE_HUMANS` | `false` | Permit scoring human subjects |\n\n---\n\n## Part of ABSuite\n\n**The black box for AI systems** — record what happened, prove it happened,\npreserve the evidence.\n\n| | |\n|---|---|\n| Source | <https://github.com/iamGodofall/ABSuite-core> |\n| Verify a trace in your browser | <https://iamgodofall.github.io/ABSuite-core/verify.html> |\n| Getting started | [GETTING-STARTED.md](https://github.com/iamGodofall/ABSuite-core/blob/main/GETTING-STARTED.md) |\n| Reporting a vulnerability | [SECURITY.md](https://github.com/iamGodofall/ABSuite-core/blob/main/SECURITY.md) — never a public issue |\n| What this project refuses to build | [PRINCIPLES.md](https://github.com/iamGodofall/ABSuite-core/blob/main/PRINCIPLES.md) |\n\nPublished from CI with a signed Sigstore provenance attestation — check it with\n`npm audit signatures` rather than taking our word for it.\n\nMIT licensed.\n","readmeFilename":"README.md"}