{
  "claimBoundary": "CapitalGuard Enforced Mode 0.7 controls host-file access, host commands, outbound network access, MCP calls, and agent handoffs originating inside a verified OCI session by removing ambient host authority and routing authenticated, task-bound broker operations through a manifest-bound, full-hash Workspace Integrity check before authority release, host-derived Context Provenance, Sensitive Egress Gate, owner-signed Data Boundary Firewall, transformed-request reauthorization, Runtime Sequence Firewall, Agent Action Gateway, and Agent Change Gate. File writes are blocked without a manifest-bound Agent Change policy; configured writes become signed candidates outside the repository and require exact, expiring, one-use reviewer approval before a separate apply operation. Operations outside that broker, writes after an integrity check, explicitly ignored workspace paths, arbitrary semantic intent, unlabeled confidential prose, code correctness, application-semantic preservation after masking, host or OCI compromise, stolen authority keys, and hardware attestation remain outside its authority; rollback detection depends on retained broker, workspace, and change-state anchors.",
  "digestAlgorithm": "SHA-256",
  "files": [
    {
      "bytes": 6532,
      "path": "agent-change-receipt.schema.json",
      "sha256": "7b2419c47e6896de3e98798f8e723c611745ff9963828dbebb01703d488d7b9e"
    },
    {
      "bytes": 1294,
      "path": "broker-request.schema.json",
      "sha256": "cd4347f8fe41990af8421fa75e60cbfa41789c033bb485c61642cf746dca7169"
    },
    {
      "bytes": 1794,
      "path": "broker-response.schema.json",
      "sha256": "f94b5262ee8a6fbbe8be814538c757d9297aaacec0ccb40952138fde9dbb9894"
    },
    {
      "bytes": 3819,
      "path": "broker-state.schema.json",
      "sha256": "f7444d5762bf6d09e1fc61ba8da3203480e93f390e15ec31be62316e48d21a15"
    },
    {
      "bytes": 6273,
      "path": "data-boundary-receipt.schema.json",
      "sha256": "95ec08c44091c9adafa8331beff4f7270736a6e24370eae32023cec87268f9fe"
    },
    {
      "bytes": 5084,
      "path": "enforced-mode-session.schema.json",
      "sha256": "8bf996240b9d55877cc475ba25cfe118bead5d208172b7e10b30590858ff8baf"
    },
    {
      "bytes": 3057,
      "path": "methodology.json",
      "sha256": "b8f155d7581f33a0b8b32b4edb0793613a0af38e6539fb57a2bda8c30d0d6a66"
    },
    {
      "bytes": 4163,
      "path": "sensitive-egress-receipt.schema.json",
      "sha256": "292af9aa776ad496e84d550b09e50dd6b3323b8a98d0cfb1c5ab3525184e8fa2"
    },
    {
      "bytes": 7562,
      "path": "support-matrix.json",
      "sha256": "e930067d53ff1e465d1c8b1626b3a3f995fdf9fab510462ede1fe25659f924ea"
    },
    {
      "bytes": 2881,
      "path": "test-vectors.json",
      "sha256": "177848c6d5d993e0a0a734bc2f6744943e2e41643996edbd565d0ec55155f01d"
    },
    {
      "bytes": 4339,
      "path": "threat-model.json",
      "sha256": "94e7cad06257cb993623e1574202100fc5c3f4a013589c4683419ae3ecbd1bbc"
    },
    {
      "bytes": 2225,
      "path": "trust-chain-receipt.schema.json",
      "sha256": "7d6ae172fa44bc5283909edc5fdc913738f19c9d8424fd1dbb445f6ff360a1f4"
    },
    {
      "bytes": 3974,
      "path": "workspace-integrity-receipt.schema.json",
      "sha256": "f78649bcbabdf0f98532756276b8362c28312fdb198b8d8ad900fc117c73e1a5"
    }
  ],
  "id": "CG-ENFORCED-MODE-0.7.0-RELEASE",
  "licensedArtifacts": [
    {
      "bytes": 577184,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-runtime-enclave.mjs",
      "id": "runtime-enclave",
      "sha256": "78e0c06115ba5de81c7279eaf7622b0746c2b73974c27ada9b208c5129ccd91f"
    },
    {
      "bytes": 12015,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-enforced-mode.mjs",
      "id": "enforced-mode-cli",
      "sha256": "4a442fd631a6853802ee80c98ccffe3d28e9439813975dfcddd811ca6d120b32"
    },
    {
      "bytes": 7303,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-enclave-mcp.mjs",
      "id": "enclave-mcp",
      "sha256": "b26f13ae6d00906c300698cab51fa2a4fe4d84f654912568849373764e176a0a"
    },
    {
      "bytes": 7308,
      "distribution": "licensed_delivery_only",
      "filename": "capitalguard-enforced-mode-guide.md",
      "id": "enforced-mode-guide",
      "sha256": "94a345f90003fa43283f0d5846d5a7a4f6c600e75ebc1c22f6cc6a686fe7ca51"
    }
  ],
  "publishedAt": "2026-07-19T05:40:00.000Z",
  "releaseDigestSha256": "8b8fea5732f68fa228d423f9bc17d7b09ace8d401d26535693839024f2417b2f",
  "status": "stable",
  "trustChainClaimBoundary": "CapitalGuard Runtime Trust Chain 0.3 binds a host-normalized, task-scoped Enforced Mode broker operation to signed model-output provenance, derives context trust without accepting caller trust, blocks high-confidence credentials, applies an optional owner-signed Data Boundary Firewall, re-authorizes and re-inspects any transformed payload, applies Runtime Sequence Firewall state, and invokes the Agent Action Gateway through that exact chain. It controls only operations routed through the authenticated broker and cannot understand semantic intent, classify arbitrary unlabeled prose, observe bypassed operations, preserve application semantics after masking, resist a compromised host or authority key, or provide hardware attestation; rollback detection depends on separately retained broker anchors.",
  "version": "0.7.0"
}
