Evidence coverage · v2026-08-03

Coverage by source and evidence depth

A vendor logo does not prove action-level visibility. BeProof shows which sources can support inventory, access, activity, control outcomes, and provenance. When a layer cannot be verified, it records a CoverageGap instead of silently passing the audit.

Current macOS pilot coverage

These are the sources and evidence depths available in the current pilot. A limited cell still represents real evidence, but its observation mode or causal boundary is narrower than universal coverage.

v2026-08-03
Verified today

Supported evidence is available in the current macOS pilot.

Available with limits

The source supplies evidence, with the exact sampling or lineage boundary shown.

Not in current pilot

The capability is not presented as part of today's pilot scope.

Scroll horizontally to inspect every evidence layer

Agent / sourceInstalled / configuredSession observedChild process attributedDirect CLI actionMCP invocationCredential contextDestination / environmentExternal enforcement
CodexmacOSLocal history + explicit-scan samplingAction ChainVerified todayLocal config, automations, install and managed-policy surfaces.Verified todayCodex automation history supplies source event and session evidence.Available with limitsExplicit-scan process sampling only; no background lifecycle capture.Available with limitsgit, gh, aws, kubectl, psql, docker and ssh classifiers during the sampling window.Available with limitsConfigured MCP surfaces and supported history signals; not universal runtime invocation proof.Available with limitsCredential references are available separately; per-action lineage is missing.Available with limitsRepository/project context where the source exposes it; production classification is not universal.Not in current pilotContracts and synthetic fixtures exist; production external-control adapters remain planned.
Claude CodemacOSLocal history + supported MCP history + explicit-scan samplingCausal fixtureVerified todayLocal config, managed settings and MCP definitions.Verified todayLocal history supplies session records when readable.Available with limitsExplicit-scan sampling; ancestry is limited to processes present in one sample.Available with limitsSupported CLI classifiers during the sampling window only.Available with limitsRuntime invocation metadata is available for supported Claude history sources.Available with limitsCredential references can be discovered; session-to-credential lineage is incomplete.Available with limitsProject and supported target metadata where exposed by the source.Not in current pilotSource-attributed production adapters are not shipped.
CursormacOSLocal history + explicit-scan samplingCoverage notesVerified todayRules, hooks, local settings, install and managed-policy surfaces.Available with limitsComposer history supplies source-dependent session signals.Available with limitsExplicit-scan sampling; detached or nested execution may be missed.Available with limitsSupported CLI classifiers during the sampling window only.Not in current pilotConfigured MCP commands are not runtime invocation proof.Available with limitsCredential references are separate from the action chain.Available with limitsProject context where present; production environment is not universally classified.Not in current pilotSource-attributed production adapters are not shipped.
MCP serversmacOSConfiguration + supported vendor historySource matrixVerified todayLocal MCP definitions, commands, endpoints and first-seen baselines.Available with limitsAvailable only where a supported vendor history source exposes a session.Not applicableMCP configuration is not process ancestry evidence.Not applicableDirect CLI is evaluated through the process-observation path.Available with limitsSupported runtime history only; otherwise configuration evidence.Available with limitsEnvironment credential references are metadata-only; secret values are not collected.Available with limitsConfigured network endpoints where present; runtime target can remain unknown.Not in current pilotProduction MCP enforcement-source adapters are not shipped.
CodexmacOS
Action Chain

Local history + explicit-scan sampling

Installed / configured
Verified todayLocal config, automations, install and managed-policy surfaces.
Session observed
Verified todayCodex automation history supplies source event and session evidence.
Child process attributed
Available with limitsExplicit-scan process sampling only; no background lifecycle capture.
Direct CLI action
Available with limitsgit, gh, aws, kubectl, psql, docker and ssh classifiers during the sampling window.
MCP invocation
Available with limitsConfigured MCP surfaces and supported history signals; not universal runtime invocation proof.
Credential context
Available with limitsCredential references are available separately; per-action lineage is missing.
Destination / environment
Available with limitsRepository/project context where the source exposes it; production classification is not universal.
External enforcement
Not in current pilotContracts and synthetic fixtures exist; production external-control adapters remain planned.

Boundary: History-backed automation events are available. Process ancestry and direct CLI evidence are sampling-only; credential context is not action-linked.

Claude CodemacOS
Causal fixture

Local history + supported MCP history + explicit-scan sampling

Installed / configured
Verified todayLocal config, managed settings and MCP definitions.
Session observed
Verified todayLocal history supplies session records when readable.
Child process attributed
Available with limitsExplicit-scan sampling; ancestry is limited to processes present in one sample.
Direct CLI action
Available with limitsSupported CLI classifiers during the sampling window only.
MCP invocation
Available with limitsRuntime invocation metadata is available for supported Claude history sources.
Credential context
Available with limitsCredential references can be discovered; session-to-credential lineage is incomplete.
Destination / environment
Available with limitsProject and supported target metadata where exposed by the source.
External enforcement
Not in current pilotSource-attributed production adapters are not shipped.

Boundary: Session and supported MCP history are source-dependent. Process sampling can support inference, but it is not continuous and does not create a signed session-to-runtime binding.

CursormacOS
Coverage notes

Local history + explicit-scan sampling

Installed / configured
Verified todayRules, hooks, local settings, install and managed-policy surfaces.
Session observed
Available with limitsComposer history supplies source-dependent session signals.
Child process attributed
Available with limitsExplicit-scan sampling; detached or nested execution may be missed.
Direct CLI action
Available with limitsSupported CLI classifiers during the sampling window only.
MCP invocation
Not in current pilotConfigured MCP commands are not runtime invocation proof.
Credential context
Available with limitsCredential references are separate from the action chain.
Destination / environment
Available with limitsProject context where present; production environment is not universally classified.
External enforcement
Not in current pilotSource-attributed production adapters are not shipped.

Boundary: Cursor activity is correlation-backed. Nested shells, detached launches and unavailable tool evidence can leave attribution ambiguous or unobserved.

MCP serversmacOS
Source matrix

Configuration + supported vendor history

Installed / configured
Verified todayLocal MCP definitions, commands, endpoints and first-seen baselines.
Session observed
Available with limitsAvailable only where a supported vendor history source exposes a session.
Child process attributed
Not applicableMCP configuration is not process ancestry evidence.
Direct CLI action
Not applicableDirect CLI is evaluated through the process-observation path.
MCP invocation
Available with limitsSupported runtime history only; otherwise configuration evidence.
Credential context
Available with limitsEnvironment credential references are metadata-only; secret values are not collected.
Destination / environment
Available with limitsConfigured network endpoints where present; runtime target can remain unknown.
External enforcement
Not in current pilotProduction MCP enforcement-source adapters are not shipped.

Boundary: BeProof can inspect configured commands, endpoints and credential references. Configuration alone never proves that an MCP tool executed.

Codex: History-backed automation events are available. Process ancestry and direct CLI evidence are sampling-only; credential context is not action-linked.

Claude Code: Session and supported MCP history are source-dependent. Process sampling can support inference, but it is not continuous and does not create a signed session-to-runtime binding.

Cursor: Cursor activity is correlation-backed. Nested shells, detached launches and unavailable tool evidence can leave attribution ambiguous or unobserved.

MCP servers: BeProof can inspect configured commands, endpoints and credential references. Configuration alone never proves that an MCP tool executed.

Direct CLI and process ancestry on macOS are explicit-scan sampling only. Continuous, automatic and historical process coverage remain gated; missing or unsupported evidence is reported as a CoverageGap.

Roadmap · separate from current scope

Not included in the current macOS pilot

Windows endpoint attribution and production external-control adapters remain roadmap work. They are kept outside the current coverage matrix so future scope cannot be mistaken for a shipped capability.

Not in current pilot

External controls Source-dependent

EDR, DLP, identity and gateway products remain the enforcing systems. BeProof records an outcome only when the named source supplies explicit evidence.

Trust boundaries
Not in current pilot

Coding agents Windows

Windows endpoint attribution is a roadmap capability and is not part of the current macOS release or design-partner pilot.

Platform scope
Inspect technical roadmap depth

Scroll horizontally to inspect every evidence layer

Agent / sourceInstalled / configuredSession observedChild process attributedDirect CLI actionMCP invocationCredential contextDestination / environmentExternal enforcement
External controlsSource-dependentSeparately attributed external sourceTrust boundariesNot applicableExternal control inventory is not the current product wedge.Not applicableAgent sessions come from agent/runtime sources.RoadmapA named EDR process source must pass the same lifecycle and loss-accounting gates.RoadmapContinuous external process evidence has not been approved.RoadmapRequires a production source adapter with action identity.RoadmapRequires source-attributed identity or credential context.RoadmapRequires source-attributed destination metadata.RoadmapContracts and synthetic fixtures exist; production adapters remain planned.
Coding agentsWindowsPlanned Event 4688 / ETW or approved EDR sourcePlatform scopeRoadmapWindows agent discovery is not shipped.RoadmapWindows session adapters are not shipped.RoadmapEvent 4688 / ETW or approved EDR source is planned.RoadmapNo supported Windows direct-CLI attribution today.RoadmapNo supported Windows runtime MCP attribution today.RoadmapNo supported Windows credential-context adapter today.RoadmapNo supported Windows destination classifier today.RoadmapNo supported Windows external-control adapter today.
External controlsSource-dependent
Trust boundaries

Separately attributed external source

Installed / configured
Not applicableExternal control inventory is not the current product wedge.
Session observed
Not applicableAgent sessions come from agent/runtime sources.
Child process attributed
RoadmapA named EDR process source must pass the same lifecycle and loss-accounting gates.
Direct CLI action
RoadmapContinuous external process evidence has not been approved.
MCP invocation
RoadmapRequires a production source adapter with action identity.
Credential context
RoadmapRequires source-attributed identity or credential context.
Destination / environment
RoadmapRequires source-attributed destination metadata.
External enforcement
RoadmapContracts and synthetic fixtures exist; production adapters remain planned.

Boundary: EDR, DLP, identity and gateway products remain the enforcing systems. BeProof records an outcome only when the named source supplies explicit evidence.

Coding agentsWindows
Platform scope

Planned Event 4688 / ETW or approved EDR source

Installed / configured
RoadmapWindows agent discovery is not shipped.
Session observed
RoadmapWindows session adapters are not shipped.
Child process attributed
RoadmapEvent 4688 / ETW or approved EDR source is planned.
Direct CLI action
RoadmapNo supported Windows direct-CLI attribution today.
MCP invocation
RoadmapNo supported Windows runtime MCP attribution today.
Credential context
RoadmapNo supported Windows credential-context adapter today.
Destination / environment
RoadmapNo supported Windows destination classifier today.
External enforcement
RoadmapNo supported Windows external-control adapter today.

Boundary: Windows endpoint attribution is a roadmap capability and is not part of the current macOS release or design-partner pilot.

Evidence depth

Depth is evaluated independently for every source. A shipped inventory adapter does not imply causal activity or enforcement coverage.

Available

Inventory

Agent surfaces, local configs, MCP definitions, install records, and cloud declarations.

Available / partial

Access

Credential references, keychain metadata, grant edges, and connector readiness.

Source-dependent

Activity

Usage and history signals. A correlation is not labelled as a causal action event.

Contract + fixture

Control outcome

Source-attributed allow, warn, deny, and remediation evidence is modelled; production external-control adapters remain planned.

Available / expanding

Provenance

Source references, confidence, freshness, signed exports, and verifiable integrity metadata.

Surface catalog

Status reflects the current macOS release. Cloud and observed columns depend on configured connectors, readable local history, and admin API access. Planned surfaces (e.g. Windows agents) are roadmap items — Separate Windows platform PRD — not in the macOS release or design-partner pilot.

Agent / SurfaceDeclaredGrantedObservedCloudStatusNotes
OpenAI Codex (local)🟡GAConfig, automations, credential metadata; usage via CodexAutomationUsageScanner. Managed: /etc/codex + MDM (POL-X02). Usage gaps when SQLite is locked or history missing.
Codex cloud tasks🟡🟡🟡PartialOpenAI org enumeration and usage require OPENAI_ADMIN_KEY / cloud connector; use Local vs Cloud setup in the macOS app.
Claude Code🟡GA / partialLocal config + ClaudeCodeUsageScanner. Managed: ClaudeCode managed-settings + MDM (POL-X02). Cloud partial without Anthropic admin token.
Cursor🟡GA / partialRules/hooks + CursorUsageScanner. Cloud usage and org context need CURSOR_API_KEY (Enterprise Admin API). Managed: Cursor MDM plist (POL-X02).
Open ClawGADeclared ~/.openclaw (+ clawdbot paths) + OpenClawUsageScanner. Managed: /etc/openclaw + MDM ai.openclaw.mac.plist.
WindsurfGADeclared ~/.codeium/windsurf + WindsurfUsageScanner. Managed: /etc/windsurf/policies + MDM com.exafunction.windsurf (POL-X02).
ClineGAVS Code globalStorage + .clinerules + ClineUsageScanner. Enterprise policy via VS Code managed settings when deployed.
AiderGA~/.aider.conf.yml, project history metadata + AiderUsageScanner. Project-scoped chat history requires project in scan scope.
ContinueGA~/.continue config/rules + ContinueUsageScanner. Session metadata from VS Code globalStorage; contents not parsed.
GitHub Copilot🟡PartialCopilot instruction files (declared). Cloud grant edges when GH_TOKEN configured. No dedicated Copilot usage scanner.
VS Code enterprise (Copilot / MCP policy)GA (managed)/etc/vscode/policy.json + MDM com.microsoft.VSCode plist. Metadata-only path existence for org MCP/Copilot policy.
MCP configs🟡GA / partial.mcp.json, configured commands, network endpoints and env credential refs; configuration does not prove execution. Runtime invocation metadata is available only for supported vendor history sources.
AGENTS.md / instruction files🟡GARepository and workspace instruction surfaces; observed layer is correlation-only (POL-X06).
GitHub OAuth / GitHub Apps🟡🟡PartialGrant edges and scopes when GH_TOKEN or org connector configured (provider account attribution).
Anthropic cloud declarations🟡🟡🟡PartialCloudAgentSurface enumeration + account attribution when Anthropic admin/user token configured.
Homebrew-installed agentsGAInstall inventory (POL-X01); metadata only.
npm / pnpm global agentsGAGlobal npm/pnpm prefix scanner; install_inventory gap when paths unreadable.
VS Code / Cursor / Windsurf extensionsGAIDE extension metadata from install inventory; metadata only.
Windows agents🔴🔴🔴🔴PlannedSeparate Windows platform PRD — not in the macOS release or design-partner pilot.

GAPartialPlannedCoverageGap

Evidence layers

Declared

What exists or is configured — AgentSurface, MCP config, install records

Granted

CredentialRef metadata, keychain refs, cloud GrantEdge records

Observed

UsageEvent signals and explicitly labelled correlations where adapters exist

CoverageGap

Missing, permission-denied, partial, stale, or consent-gated sources

State boundaries

The evidence contract separates these three axes. Until a source supports a state explicitly, BeProof reports it as partial or unknown.

Evidence contract
State axisWhat it meansEvidence boundary
ExecutionFresh evidence that an agent is running, idle, completed, failed, or unknown.Historical usage does not prove a live running state.
GovernanceIn policy, needs review, exception, out of policy, or unknown.A finding or review item is not an enforcement result.
EnforcementAllowed, warned, blocked, failed, unsupported, or unknown.Blocked requires an explicit event from the product that enforced it.

Coverage depends on platform, scan scope, user or admin consent, configured connectors, and source health. BeProof never stores raw secrets, does not inspect network payloads, and does not infer enforcement outcomes without explicit source evidence.