—
—
CCG (Constitutional Capability Governance) with an ITHZ evidence layer gives OpenClaw one proposal tool while an external broker retains every service credential.
Generation 3: 24 real model runs over 4 paired service scenarios · Generation 2: 12 deterministic trajectory replays.
A real OpenClaw agent proposes steps over fake Gmail, SSH, GitHub and payment services. Only the broker owns their credentials. CCG (Constitutional Capability Governance) decides whether a one-use capability is created at all.
We test the entire chain: model → proposal → state → capability or stop → observed effect.Loading the verified result…
Three internal networks. No host port. The model key exists only in the relay layer; service credentials only in the broker.
Attack: fewer forbidden states is better. Control: more completed tasks is better.
Loading metrics…
—
—
—ccg_action tool.The original 12-scenario replay remains below. It is exact and reproducible; generation 3 adds a real model, OpenClaw, broker and isolated services.
A gateway can correctly authorize every tool call and still miss that their sum means data exfiltration, an exceeded budget, new administrator power or destroyed redundancy.
Permission for a step is not yet permission for its cumulative effect.No separate authorization boundary and no one-shot capabilities.
Every operation is locally allowed. The gateway cannot see what previous tokens have already created.
ITHZ retains provenance, effects, budgets, power bindings and hash-linked checkpoints.
This is a result of the published deterministic harness, not a measure of model intelligence or an OpenClaw certification.
Lower is better for forbidden states. Higher is better for legitimate trajectories.
Loading results…
—
—
—
Each entry contains the previous entry hash, canonical request, pre-decision state hash, verdict, capability scope, proposed machine effect and the resulting state hash. Localized prose remains outside the hash.
ITHZ is not the lowest trust root and does not issue authorization. It supplies canonical history, provenance and candidate state; a small capability kernel still decides, and the broker still owns the credential.
Generation 3 adds a real isolated OpenClaw agent; generation 2 remains the deterministic policy reference. Neither is a production safety certificate.