Diligence

Legal scenarios for signed receipts.

This matrix explains the software boundary in five common buyer-review scenarios. AgentGuard records technical receipts. Customers operate their agents and choose their review process.

ScenarioLikely named partyLegal theoryAgentGuard roleMitigation
A. Agent sends incorrect customer communicationCustomer operating the agentMisstatement, contract, consumer protectionReceipt shows model, cap, posture, and policy decision at time of callUse capability tiers, reviewer cascade for high-impact messages, and blocked-send policies
B. Receipt presented in regulator reviewCustomer presenting the recordRecord weight and evidentiary challengeVerifier checks hash chain and signature onlyExport vendor due-diligence file and preserve raw local logs
C. Foreign-origin model used after opt-inCustomer account ownerVendor diligence and procurement reviewConsent receipt records opt-in, models, outcomes, and signerCompliance posture blocks by default. Standard posture requires signed consent
D. Regulated workflow uses unsupported provider routeCustomer configuring routeBAA, retention, residency, or vendor-review gapProvenance block records hosting, jurisdiction, BAA field, and retention fieldUse Bedrock, Azure OpenAI, Vertex, or enterprise direct routes where contracts support the workflow
E. Signing-key compromise allegedKey custodian and affected operatorAuthenticity challengePublic key and chain hash enable independent detection of forged or missing linksRotate keys, pin JWKS, store chain checkpoints, and verify receipt ranges