Data origin labels. Fixture: synthetic or pinned data, no live system. Controlled run: PromptKing ran it against a system it controls. Demo organization: PromptKing's own demo account. Design only: written down, not run.
Also featured on the homepage: the Aug 8 denied action, the Sep 19 rewritten log, the Sep 21 green report, and the Sep 22 reproduction.
Six AI agents, one policy engine
Demo organization · controlled run
Jul 15, 2026 (five runs and the superseded watsonx receipt) · Jul 18, 2026 (watsonx receipt to cite)
Receipts: governed-run-v1
Shows. Agents running on Claude, GPT-5.6, Gemini, Grok and Llama each completed one low-budget research task and were allowed. An agent running on IBM watsonx declared a $500 high-risk operation, was stopped at a human-approval step (recorded verdict APPROVAL_REQUIRED) and halted. The first watsonx receipt (Jul 15) stored the wrong verdict, 'allowed'; it is marked superseded by the Jul 18 receipt.
Does not establish. That the six agents ran the same task: the sixth declared a different, deliberately high-cost operation. The vendors did not take part, and no audit, certification or endorsement is implied. Costs are agent-reported.
An approval, then a continuation under a second runtime
Demo organization · one controlled run
Aug 5–6, 2026
Receipts: governed-run-v1; obligation artifacts v1 and v2
Shows. A parent receipt (Aug 5, 22:54 UTC) names a Claude task runner. An approval request opened at 23:22 UTC names that receipt and a plan to continue on a watsonx leg; it was approved at 23:31 UTC. A receipt from the watsonx continuation agent was issued on Aug 6 at 15:14 UTC. Each artifact's hash recomputes in public, and the approval is bound to the parent receipt.
Does not establish. That the continuation is publicly bound to the approval or to the parent. The continuation receipt carries no reference to either, and PromptKing's own chain check labels the lineage legacy_unbound. The parent receipt records no policy verdict (no_policy_context) and no cost, so the reason for the approval request is not visible in it. One controlled run, not volume.
Ten strangers, five seconds each
External readers · our own record
Aug 29, 2026
Article only; test records not reviewed here
Shows. We showed our published record to ten strangers for five seconds each. Some read the overall verdict as covering a line marked 'Authority: not established'. We logged it as a defect and changed the page the same day.
Does not establish. A statistical result. The article does not give how readers were recruited or the exact script, and we have not reviewed the test records for this page.
ServiceNow fixtures
Fixture
Aug 15 – Oct 3, 2026
Work-record assessor, profile PK-WR-HOME-0-v1
Shows. The work-record assessor was run on synthetic incident and change fixtures. A read-only reader was provisioned on a ServiceNow developer instance.
Does not establish. Customer, production or enterprise ServiceNow data. The developer-instance reader's API authority is unverified, and the ServiceNow lane is not closed.
Source. Internal record. Not public today.
Salesforce Agentforce scenario fixtures
Fixture
Sep – Oct 2026
Work-record assessor, profile PK-WR-HOME-0-v1
Shows. Ten synthetic case-refund scenarios were run through the assessor to test how it reports a missing refund read, a differing amount, a removed approval and a late declaration. A supplier-onboarding scenario is at design stage.
Does not establish. A live Salesforce read. These are hand-authored fixture replays with no customer data, and no Salesforce relationship or endorsement is implied.
Source. Internal record. Not public today.
Computer-use run
Controlled run
Sep 2026
One bounded run
Shows. One bounded computer-use run by a founder-dispatched external AI runner on the founder's own Google Drive, recorded as a work record built around the agent's declared intent.
Does not establish. That the screen state was verified, or that the agent is safe. Nothing beyond that single run. The record shows what was declared and observed, not that intent was independently checked.
Source. Internal record. Not public today.
GitHub Copilot cloud agent on a throwaway repository
Controlled run · throwaway repository
Sep 2026
Capture format under test
Shows. A GitHub Copilot cloud agent was given tasks on a throwaway repository, and captures of the sessions were hash-manifested for the record format.
Does not establish. Independent confirmation. Each capture comes from one session, is unsigned, and has no independent witness; authority and event ordering are not established. Not a customer repository.
Source. Internal record. Not public today.
Transparency-log packs
Fixture
Sep – Oct 2026
Three synthetic packs
Shows. Three synthetic packs showed how a log's commitment can bound claims about the event fields it covers.
Does not establish. That any vendor's real log was checked. The verifier and inspection screen are not built, and a log is bounded evidence, not proof of the outcome.
Source. Internal record. Not public today.
Independent recompute plan
Design only
Designed Sep 20 · rehearsal Sep 29, 2026
Plan plus builder-run rehearsal
Shows. A plan for someone who did not build the system to recompute a record offline. A builder-run rehearsal on a fixture reproduced the result, flagged a one-byte edit, and reported 'could not check' when evidence was missing.
Does not establish. That anyone outside PromptKing has recomputed a record under this plan. No such run is documented as of Oct 4, 2026.
Source. Internal record. Not public today.