PublishedGuidanceLAST REVIEWED · 30 AUG 2026
Continuous assurance
Reassess trust after material changes and control failures.
Change triggers
- Model, provider, routing, and system-prompt changes.
- New tools, MCP servers, permissions, memory stores, or data destinations.
- Containment, policy, identity, and credential changes.
- Material incidents or new adverse evaluation results.
State decisions
The release-gated Trust service recomputes effective status from the latest fresh evidence, matching scoped assessment, certificate validity, and restrictive state. Evidence and scope changes revoke the current certificate. Unknown or expired evidence never counts as ACTIVE. Runtime enforcement and external evaluation operations remain separate rollout steps.
Was this page helpful?