Verifiable Execution
Does a verifiable execution record capture every file written or network call made by the agent?
No, it only captures actions that pass through the Dapr sidecar, such as service invocations, state operations, and pub/sub messages. Direct file I/O, raw network calls, or system commands are not automatically included. To achieve full verifiability, you must design the agent to route every side effect through Dapr, making the record’s scope a conscious architectural choice. The verifiable record is a complete ledger only for Dapr-mediated interactions; any bypassing code leaves blind spots.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Verifiable Execution
What is a verifiable execution record in Catalyst?
A signed, immutable sequence of agent steps enabling auditors to prove run integrity through independent replay. It does not validate decision correctness.
- Verifiable Execution
How does Catalyst ensure that step records are tamper-evident?
Catalyst uses a hash chain and digital signatures per step, so any alteration breaks the chain and becomes detectable through signature verification.
- Verifiable Execution
Can an auditor independently replay a Catalyst agent run to verify its outcome?
Auditors can replay runs using signed step records and initial state to verify output consistency, though non-determinism may limit exact reproduction.