bench:governance

Policy blocks bypass attempts the simulator predicted.

Boetica governance matches enforcer behavior to simulator predictions and proves autonomy escalation and demotion under load against enterprise-control and branch-protection baselines.

Governance blocks every bypass the simulator predicted.ScorecardSigned · Jun 2026Signed scorecard: KMS/Sigstore signed and re-verifiable, dated Jun 2026.

Baselines
Enterprise controls · GitHub branch protection
Collected
2026-06-21
Expires
2026-09-21
Dataset hash
sha256:99887766
Boetica commit
458ed66
App version
engine 2026.6
Sandbox fabric
n/a (policy harness)
Signature state
Signed scorecard — Signed: KMS/Sigstore signed and re-verifiable.

Signed results

Every row reports Boetica against the strongest baseline, names the winner without relying on color, and ties the result to an inspectable artifact.

bench:governance · collected 2026-06-21 · expires 2026-09-21
MetricBoeticaBest baselineWinnerArtifact
Bypass block rate100%PartialBoeticaEnforcer log
Simulator/enforcer consistencyConsistentn/aBoeticaPolicy report
Autonomy demotion proofPresentAbsentBoeticaAutonomy log

Representative end-state figures. Replaced by live signed scorecard data before procurement review.

Verifier passed2026-06-21. Verifier re-ran the packet and the hash chain held.
Signature present and re-verifiable
Algorithm
ECDSA P-256 (cosign keyless)
KMS key
gcpkms://projects/boetica-prod/locations/global/keyRings/evidence/cryptoKeys/scorecards
Sigstore bundle
sigstore-bundle://rekor/boetica/scorecards
Signer
boetica-evidence-signer
Signed at
2026-06-22T08:00:00Z
Digest
sha256:c6f36b77
  1. Policy fixturessha256:99887766
  2. Enforcer logsha256:55443322
  3. Signaturesha256:c6f36b77
Open evidence packetSigned · Jun 2026Evidence packet: KMS/Sigstore signed and re-verifiable, dated Jun 2026.

Plain-text summary: across 3 measured metrics, Boetica leads its baselines on the bench:governance benchmark, signed ECDSA P-256 (cosign keyless) on 2026-06-22T08:00:00Z and re-verifiable from the hash trail above.

bench:governance · methodology

How this benchmark is run

Governance is scored on bypass block rate, simulator/enforcer consistency, and autonomy escalation/demotion proof against enterprise-control and branch-protection baselines.

Fixtures
A policy-fixture suite of attempted bypasses (branch protection, budget, reviewer, model route) with simulator predictions recorded before enforcement.
Baseline collection
Branch-protection and enterprise-control baselines were exercised with the same bypass attempts; partial coverage is recorded where a control is absent.
Statistical method
Bypass block rate is the share of bypass attempts blocked; consistency is the match rate between simulator predictions and enforcer outcomes.
Reviewer
Independent governance reviewer
Last updated
2026-06-21

Inclusion rules

  • Each fixture has a documented expected outcome from the policy simulator.
  • Enforcer decisions are logged and compared to simulator predictions.
  • Autonomy changes require a recorded escalation or demotion event.

Exclusion rules

  • Fixtures where simulator and enforcer run different policy versions.

Limitations

  • Policy fixtures model common enterprise controls and are extended over time.

Other signed domains

Each domain runs through the same trust boundary and leaves its own signed scorecard.

Run it on your own work

Prove bench:governance on your repo, not ours.

Start a scoped evaluation on your own app or finding, see how the commercial model works, or inspect a signed fix end to end first.