Clearpath Assure
Formerly Witness
Know what your agents reported. Show how you reviewed it.
- Assigned task
- Research prospects and prepare email drafts
- Configured boundary
- Draft creation allowed. Sending prohibited.
Reported action
10:14:07
record_type: action_reported · action: send_email · tool: email
Finding
Action outside the configured boundary
Why it was flagged: the reported send_email action falls under “Sending prohibited.”
Human review · Recorded
Operator investigated and recorded a decision: escalate to the agent owner.
- Finding status: ReviewedSigning status: Sandbox, not signed
Synthetic data. Boundary wording and labels are illustrative. Assure evaluated the action after the agent reported it. Assure did not stop the email or intercept it. No email was sent by this example.
Small teams operating agents
Investigate reported exceptions and keep a record of the decisions your team made.
Developers and agencies
Give clients a scoped, reviewable account of the agents and workflows you oversee.
Client and governance reviews
Bring activity, boundaries, findings and review history together—and make evidence gaps visible.
Why teams choose Assure
Boundaries with a review history
Tie reported activity to versioned operating boundaries and human review, so your team can trace the expectations and decisions behind a finding.
Approval for the exact request
For explicitly integrated actions, require human MFA approval with expiry and single-use protection. Changed or already-used requests are rejected.
Portable integrity proofs
New production proofs bind record content and workspace identity. Check them offline using independently trusted public keys, rather than relying only on a dashboard.
Learn from findings before changing rules
Reuse findings as regression cases and simulate proposed rules before activation. Review the likely findings without executing an action.
A consistent client-scoped package
Bring the same review scope into manual PDF, requirements matrix CSV, evidence manifest JSON and record-proof ZIP exports.
Evidence support with visible gaps
Use selected NIST evidence mappings alongside missing evidence and remaining customer responsibilities, so a review can distinguish support from unfinished work.
From connected activity to a reviewable report.
Connect
Submit activity from your agents and workflows through the API or OTLP import.
Define boundaries
Record versioned operating boundaries to compare with reported activity.
Approve
Use exact-request human MFA approval where the separate gate is explicitly integrated.
Verify
Check record-specific integrity proofs offline with an independently trusted key.
Test
Reuse findings to simulate proposed rules before activation—not to execute actions.
Report
Manually download a consistent client-scoped package for review, with gaps visible.
Production signing is live
Evidence clients can inspect. Integrity they can check.
01
Signed production records
Accepted production reports flow through an automatic worker to real KMS-backed signing through Clearpath Trust Ledger.
02
Explicit evidence status
Signed, pending and unsigned records remain distinct. Sandbox history is unsigned and never converted into signed evidence.
03
Applicable record proofs
Use individual or batch proofs as applicable to the record. Not every record belongs to a Merkle batch.
04
Customer verification
New production proofs protect record content and workspace identity. The offline ECDSA P-384 verifier requires an independently trusted public key, obtainable from Clearpath through a trusted channel. It does not support post-quantum verification.
Bring a scoped evidence package to the review.
- PDF review report
- A scoped account of activity, findings, review history and limitations.
- Requirements matrix CSV
- Selected evidence support alongside remaining responsibilities and gaps.
- Evidence manifest JSON
- An inventory tying the package’s evidence and scope together.
- Record-proof ZIP + offline verifier
- Record proofs for integrity checks using independently trusted public keys.
Selected evidence for NIST-informed reviews.
NIST SP 800-53 Rev. 5
Selected support: AU-3 audit-record content from submitted activity, and AU-9(3) integrity evidence from signed records and applicable proofs. Your team still owns audit coverage, access protections and the wider control implementation.
Read at NIST NIST SP 800-53 Rev. 5 (opens in a new tab)NIST AI RMF
MEASURE 2.4: reported production behavior supports monitoring evidence. MANAGE 4.1: findings and human review history support broader response work. Your team remains responsible for monitoring coverage, response plans, remediation and effectiveness.
Read at NIST NIST AI RMF (opens in a new tab)AI Agent Standards Initiative
An emerging reference for agent standards. It is not a completed Assure certification or a claim that every emerging requirement is covered.
Read at NIST AI Agent Standards Initiative (opens in a new tab)
Connect your agents and applications.
Start free. Move to production when you’re ready.
Free sandbox
Unsigned and nonbillable. Up to 30-day expiry per key; 100 events/day, 1,000 total, 2 active keys. Sandbox history is never converted to signed evidence.
Production oversight
Starter includes 50,000 accepted production events/calendar month · 5,000/day. Exact retries deduplicated. Over-limit events rejected; no overage charges.
Review current plans on the Assure product site. Cancel through Usage & Billing → Manage billing at paid-period end.
Questions
Does Assure stop an agent from acting?
Reporting only observes submitted activity and compares it with recorded boundaries. It does not intercept actions. A separately and explicitly integrated approval gate requires a human MFA approval for the exact request, uses a single-use approval with expiry, and rejects changed or already-used requests. Actions that do not integrate the gate remain uncontrolled.
What does Starter include, and what happens at a limit?
Starter provides 50,000 accepted production events per calendar month and 5,000 per day. Exact retries are deduplicated. Over-limit events are rejected; there are no overage charges. Current subscription pricing is available on the Assure product site.
How do I cancel?
In the product, open Usage & Billing → Manage billing. Cancellation takes effect at the end of the paid period. Read the service terms for the governing agreement.
What can I try for free?
Sandbox is unsigned and nonbillable, with up to 30-day expiry per key, 100 events per day, 1,000 total and 2 active keys. Sandbox history is not converted into signed production evidence.
What can a client verify offline?
New production proofs protect record content and workspace identity. Assure’s offline verifier supports classical ECDSA P-384 and requires an independently trusted public key, obtainable from Clearpath through a trusted channel. Existing legacy individual proofs can validate a signature without independently verifying all record content or identity. Use each record’s specific verification status. The offline verifier does not support post-quantum verification.
Do signatures prove the agent’s report is true?
No. Signatures support record integrity, not truth, correctness or completeness. Assure cannot account for activity that was never submitted. Pending and unsigned records must not be treated as signed evidence.
Are reports emailed automatically?
No. Reports are manually downloaded. The hosted email action is simulation only—not live email delivery or automatic report emails. iPilot and guided tours provide guidance only; they cannot approve requests or change controls.
Do heartbeats prove an agent is inactive?
No. Optional heartbeats show reporter check-in, not a guarantee about agent activity or inactivity. Your team must investigate missing reporting and validate its coverage.
Does this establish NIST compliance or regulated-data eligibility?
No. Assure supplies selected evidence support, not NIST certification, endorsement, comprehensive compliance or an ATO. Your team owns the remaining controls, evidence gaps and review decisions. This launch does not expand eligibility for sensitive, CUI or regulated data.
