Deployment Decision Gate

“Should I ship this version — and is the clean score even trustworthy?”

The unified scorecard yields a number; certification yields a badge; posture-drift grades a trend. None of them is the deploy decision a CI gate can block on. AgentSmack's deployment gate folds the unified ProductionScorecard together with the trust-qualifying meta-lenses — test-validity coverage-confidence, false-positive specificity, blast-radius magnitude, and the compound-exposure kill-chain verdict — into ONE auditable allow / allow_with_conditions / block / inconclusive verdict with enumerated, defensible reasons. The killer property nothing else enforces: a clean production score does NOT launder a deploy approval when the run was vacuous (the harness never exercised the agent) or when AgentSmack itself overblocks (the scanner cries wolf) — those are forced to inconclusive, never allow. Block is sticky-maximal: no allow qualifier can override a production hard blocker, a catastrophic blast radius, or a critically-exposed kill chain. Honest-empty: a passing scorecard with no meta-lenses yields a clean allow with no fabricated qualifier. It is a PURE decision aggregator over already-computed reports (no new surface, no new dimension, no DB). Fill a sample run below to watch the verdict swing with no live infra.

Fill with a sample run to watch the deploy verdict swing — a clean score from a vacuous run is forced to inconclusive, never an allow.

The gate emits a binary allow / block DECISION over a SUBSET of the trust lenses. Want a single graded, explainable 0–100 trust NUMBER over the full trust-lens set — including the coverage blind-spots, finding corroboration, and forecast calibration this gate does not consume? Compose the Report Trust Index — the meta-meta lens a CISO reads before believing any verdict.

The gate said block / allow_with_conditions / inconclusive and you intend to ship anyway? Record a formal, time-boxed exception with the Residual-Risk Acceptance Record — who accepted which enumerated residual risk, why, and until when, content-addressed and digest-verifiable. A confirmed compromise / forged evidence / tampered scorecard can never be waived.

The scorecard the gate trusts — is it self-consistent?

The gate reads the scorecard's overall / band / blockedDimensions verbatim. SC.1 re-derives them from the scorecard's OWN claimed dimensions — a hand-edited clean-looking scorecard whose arithmetic does not add up is tampered and the gate forces the decision to inconclusive. Audit a scorecard below beside the gate verdict.

Was the scorecard even computed over the agent being deployed?

The gate trusts the scorecard's posture, but never checks WHICH agent definition it graded. EB.1 re-derives the deployed definition's fingerprint and compares it to the evidence's bound fingerprint — a scorecard computed over a hardened older prompt cannot certify a deploy of a weakened one. A drifted binding forces the deploy decision to inconclusive. Bind a scorecard below beside the gate verdict.

Load a sample to watch the binding verdict swing — a scorecard computed over a hardened prompt cannot certify a deploy of a weakened one, and a newly-added high-risk tool the scorecard never saw forces drifted.