Diligence
Legal scenarios for signed receipts.
This matrix explains the software boundary in five common buyer-review scenarios. AgentGuard records technical receipts. Customers operate their agents and choose their review process.
| Scenario | Likely named party | Legal theory | AgentGuard role | Mitigation |
|---|---|---|---|---|
| A. Agent sends incorrect customer communication | Customer operating the agent | Misstatement, contract, consumer protection | When signing is configured, the receipt records model, policy result, projected cost, and a triggered cap when one exists. It does not sign the selected governance posture. | Use capability tiers, reviewer cascade for high-impact messages, and application-level blocked-send policies |
| B. Receipt presented in regulator review | Customer presenting the record | Record weight and evidentiary challenge | Verifier checks signed-record integrity, chain linkage, and sequence only | Export the vendor due-diligence file and preserve raw local logs under the organization's retention process |
| C. Foreign-origin model used after opt-in | Customer account owner | Vendor diligence and procurement review | The hosted consent receipt records selected model-family and outcome labels. The current SDK validates the receipt ID but does not bind those labels to the current call. | Compliance posture blocks. Standard posture requires a receipt ID accepted by the hosted consent endpoint. Velocity posture does not require one. |
| D. Regulated workflow uses unsupported provider route | Customer configuring route | BAA, retention, residency, or vendor-review gap | The signed provenance block preserves registry-derived and integrator-configured hosting, jurisdiction, BAA, and retention fields. It does not prove the underlying provider facts. | Review the actual route, configuration, current provider terms, and applicable contract outside AgentGuard |
| E. Signing-key compromise alleged | Key custodian and affected operator | Authenticity challenge | Verification cannot distinguish the legitimate custodian from an attacker who holds the private key. Retained chains can still reveal internal gaps or broken links. | Rotate keys, pin public keys, preserve independently retained chain-head checkpoints, and document the compromise boundary |