An old fact can remain in the history
A project first approves staging-blue, then switches to staging-green. The old record can explain a past decision. Whether it may support a new output depends on the current state. Finding the record does not answer that question.
The GPM paper studies persistent state semantics and a source-bound release contract. This demo makes one case observable: whether an explicit claim passes through the same tool after its source is revoked. An owner supplies the change; the system does not discover an external project change by itself.
The valid replacement still passes
A tool that refuses every request would also stop old A. The positive control matters: both clients also request current B and receive its structured released claim. The normal path remains available in this run.
Claude Code uses a scoped CLI-to-MCP bridge; Codex uses native MCP. The stale requests share a query and claim-set hash. Post-revocation receipts refer to the same policy version and ledger head. The transport changes while the observed release boundary stays consistent.
The boundary ends at this tool response
The tool checks explicit claims and decides whether to return released_claims. A host can still repeat a value from its prompt, use another tool, or act after a later state change. A real action needs another check at its execution boundary.
This research adapter is separate from the publicly distributed Agent Client. This page provides recorded results and the paper. The executable demo package is not distributed here; a video and JSON receipts do not replace independent reproduction.
Where ACS relates to this demo
This comparison uses ACS v0.1.0 at commit 27799c2. It identifies related behavior and gaps. No ACS conformance is claimed.
| Scope | Observed here | Missing evidence |
|---|---|---|
| Core | Structured release or abstain decisions | ACS handshake, signatures, replay protection and host decision honoring |
| Provenance / Trace | Source IDs, decisions and timestamps | Required field-level provenance objects and event exports |
| Inspect / Crypto / Audit | Record hashes can be inspected | The inventory, signature and audit-chain implementations required by those profiles |