Skip to content

Clearpath Assure

Formerly Witness

Know what your agents reported. Show how you reviewed it.

Practical AI-agent oversight for small teams, developers and agencies. Compare submitted activity with boundaries, investigate findings, and give clients reviewable evidence of human oversight.
A standalone service. No other Clearpath purchase required. Open Assure
Illustrative example
Assigned task
Research prospects and prepare email drafts
Configured boundary
Draft creation allowed. Sending prohibited.
  1. Reported action

    10:14:07

    record_type: action_reported · action: send_email · tool: email

  2. Finding

    Action outside the configured boundary

    Why it was flagged: the reported send_email action falls under “Sending prohibited.”

  3. Human review · Recorded

    Operator investigated and recorded a decision: escalate to the agent owner.

  4. Finding status: ReviewedSigning status: Sandbox, not signed

Synthetic data. Boundary wording and labels are illustrative. Assure evaluated the action after the agent reported it. Assure did not stop the email or intercept it. No email was sent by this example.

  • Small teams operating agents

    Investigate reported exceptions and keep a record of the decisions your team made.

  • Developers and agencies

    Give clients a scoped, reviewable account of the agents and workflows you oversee.

  • Client and governance reviews

    Bring activity, boundaries, findings and review history together—and make evidence gaps visible.

Why teams choose Assure

Keep expectations, decisions and evidence connected—from a reported exception to a client review.
  • Boundaries with a review history

    Tie reported activity to versioned operating boundaries and human review, so your team can trace the expectations and decisions behind a finding.

  • Approval for the exact request

    For explicitly integrated actions, require human MFA approval with expiry and single-use protection. Changed or already-used requests are rejected.

  • Portable integrity proofs

    New production proofs bind record content and workspace identity. Check them offline using independently trusted public keys, rather than relying only on a dashboard.

  • Learn from findings before changing rules

    Reuse findings as regression cases and simulate proposed rules before activation. Review the likely findings without executing an action.

  • A consistent client-scoped package

    Bring the same review scope into manual PDF, requirements matrix CSV, evidence manifest JSON and record-proof ZIP exports.

  • Evidence support with visible gaps

    Use selected NIST evidence mappings alongside missing evidence and remaining customer responsibilities, so a review can distinguish support from unfinished work.

Coverage depends on what your agents and applications submit. Optional heartbeats show reporter check-in—not guaranteed agent inactivity. Your team remains responsible for instrumentation, permissions and unreported activity.

From connected activity to a reviewable report.

  1. Connect

    Submit activity from your agents and workflows through the API or OTLP import.

  2. Define boundaries

    Record versioned operating boundaries to compare with reported activity.

  3. Approve

    Use exact-request human MFA approval where the separate gate is explicitly integrated.

  4. Verify

    Check record-specific integrity proofs offline with an independently trusted key.

  5. Test

    Reuse findings to simulate proposed rules before activation—not to execute actions.

  6. Report

    Manually download a consistent client-scoped package for review, with gaps visible.

Reporting observes submitted activity; it does not stop actions. Approval applies only where the gate is explicitly integrated; actions outside it remain uncontrolled. Testing simulates rules, not live actions.

Production signing is live

Evidence clients can inspect. Integrity they can check.

Production records are signed through Clearpath Trust Ledger. A signature makes changes detectable; it does not prove that a report is true, that an AI result is correct, or that every action was reported.
Do not treat pending or unsigned records as signed. Sandbox records remain unsigned and are never converted.
  1. 01

    Signed production records

    Accepted production reports flow through an automatic worker to real KMS-backed signing through Clearpath Trust Ledger.

  2. 02

    Explicit evidence status

    Signed, pending and unsigned records remain distinct. Sandbox history is unsigned and never converted into signed evidence.

  3. 03

    Applicable record proofs

    Use individual or batch proofs as applicable to the record. Not every record belongs to a Merkle batch.

  4. 04

    Customer verification

    New production proofs protect record content and workspace identity. The offline ECDSA P-384 verifier requires an independently trusted public key, obtainable from Clearpath through a trusted channel. It does not support post-quantum verification.

Bring a scoped evidence package to the review.

Manually download the PDF, requirements matrix, manifest and record-proof ZIP from one consistent package. Show what is supported—and what remains your team’s responsibility.
PDF review report
A scoped account of activity, findings, review history and limitations.
Requirements matrix CSV
Selected evidence support alongside remaining responsibilities and gaps.
Evidence manifest JSON
An inventory tying the package’s evidence and scope together.
Record-proof ZIP + offline verifier
Record proofs for integrity checks using independently trusted public keys.
Check each record’s verification status: new production proofs protect record content and workspace identity. Existing legacy individual proofs can validate a signature without independently verifying all record content or identity. The offline ECDSA P-384 verifier requires an independently trusted public key, obtainable from Clearpath through a trusted channel; it does not support post-quantum verification.
Reports are manual downloads, not automatically emailed. The hosted email action is simulation only. iPilot and guided tours guide users; they cannot approve requests or change controls.

Selected evidence for NIST-informed reviews.

Use concrete evidence support in a broader governance process, not as a substitute for implementing controls.
  • NIST SP 800-53 Rev. 5

    Selected support: AU-3 audit-record content from submitted activity, and AU-9(3) integrity evidence from signed records and applicable proofs. Your team still owns audit coverage, access protections and the wider control implementation.

    Read at NIST NIST SP 800-53 Rev. 5 (opens in a new tab)
  • NIST AI RMF

    MEASURE 2.4: reported production behavior supports monitoring evidence. MANAGE 4.1: findings and human review history support broader response work. Your team remains responsible for monitoring coverage, response plans, remediation and effectiveness.

    Read at NIST NIST AI RMF (opens in a new tab)
  • AI Agent Standards Initiative

    An emerging reference for agent standards. It is not a completed Assure certification or a claim that every emerging requirement is covered.

    Read at NIST AI Agent Standards Initiative (opens in a new tab)
Not NIST certified or endorsed. Not comprehensive compliance or an authorization to operate (ATO). Customers must assess missing evidence, reporting coverage, their own controls and response work. No expansion of eligibility for sensitive, CUI or regulated data is implied.

Connect your agents and applications.

Submit activity through the documented API or OTLP import. Start with unsigned sandbox reporting, then use production access for signed records. Assure does not automatically discover agents or provide universal native connectors.

Start free. Move to production when you’re ready.

Free sandbox

Unsigned and nonbillable. Up to 30-day expiry per key; 100 events/day, 1,000 total, 2 active keys. Sandbox history is never converted to signed evidence.

Production oversight

Starter includes 50,000 accepted production events/calendar month · 5,000/day. Exact retries deduplicated. Over-limit events rejected; no overage charges.

Review current plans on the Assure product site. Cancel through Usage & Billing → Manage billing at paid-period end.

Questions

Does Assure stop an agent from acting?

Reporting only observes submitted activity and compares it with recorded boundaries. It does not intercept actions. A separately and explicitly integrated approval gate requires a human MFA approval for the exact request, uses a single-use approval with expiry, and rejects changed or already-used requests. Actions that do not integrate the gate remain uncontrolled.

What does Starter include, and what happens at a limit?

Starter provides 50,000 accepted production events per calendar month and 5,000 per day. Exact retries are deduplicated. Over-limit events are rejected; there are no overage charges. Current subscription pricing is available on the Assure product site.

How do I cancel?

In the product, open Usage & Billing → Manage billing. Cancellation takes effect at the end of the paid period. Read the service terms for the governing agreement.

What can I try for free?

Sandbox is unsigned and nonbillable, with up to 30-day expiry per key, 100 events per day, 1,000 total and 2 active keys. Sandbox history is not converted into signed production evidence.

What can a client verify offline?

New production proofs protect record content and workspace identity. Assure’s offline verifier supports classical ECDSA P-384 and requires an independently trusted public key, obtainable from Clearpath through a trusted channel. Existing legacy individual proofs can validate a signature without independently verifying all record content or identity. Use each record’s specific verification status. The offline verifier does not support post-quantum verification.

Do signatures prove the agent’s report is true?

No. Signatures support record integrity, not truth, correctness or completeness. Assure cannot account for activity that was never submitted. Pending and unsigned records must not be treated as signed evidence.

Are reports emailed automatically?

No. Reports are manually downloaded. The hosted email action is simulation only—not live email delivery or automatic report emails. iPilot and guided tours provide guidance only; they cannot approve requests or change controls.

Do heartbeats prove an agent is inactive?

No. Optional heartbeats show reporter check-in, not a guarantee about agent activity or inactivity. Your team must investigate missing reporting and validate its coverage.

Does this establish NIST compliance or regulated-data eligibility?

No. Assure supplies selected evidence support, not NIST certification, endorsement, comprehensive compliance or an ATO. Your team owns the remaining controls, evidence gaps and review decisions. This launch does not expand eligibility for sensitive, CUI or regulated data.