Executive delivery brief
Illustrative receipt · fields and verifier behavior mirror the current format
| Claim | Present | Required | Standing |
|---|---|---|---|
| Bound requirements | 42 | 42 | |
| Blocking gates | 13 | 13 | |
| Named acceptances | 3 | 3 |
The AI SDLC platform for enterprise teams
Any team can put agents on the work now. Almost none can say afterwards what ran, what it was allowed to touch, or who accepted the result.

The shape of it
The work happened in your harness. What comes back here is a record in four parts, and each part is a table with its boundary enforced in the database rather than in the screen in front of it.
Which models saw this work, and where do they run? What did the agents actually do, stage by stage? What were they held to, and what came back? Which tools could they reach, and what was refused?
SprintLoop does not run the agents. It does not execute a build, dispatch a lane or hold a model key, and it does not replace the harness your engineers already work in. Agents report in over a scoped connection: six of its eleven doors only answer questions, the other five write narration and propose test bindings, and none of them can accept, sign or disposition anything.
From a requirement to its proof
A citation, an artifact that resolves at a pinned commit, a test that ran and a runtime observation stay distinct all the way up. A reviewer sees what supports the record rather than one word standing in for all four.
A skipped test creates no binding, and a failing one still binds. A citation that does not resolve at the pin stays visible as a classified finding until a person decides what to do about it.
Rank is carried by how much of the mark is filled, so the ladder survives a grayscale print and a color-vision deficiency. There is no tick at the top: a test that ran may have failed, and a shape promoting a failure to a success would be the exact overstatement this product refuses.
Six classes and no seventh. Adding one is a reviewed product change, so a workspace cannot quietly redefine what a finding means, and two workspaces reading the same register cannot reach different answers about it.
The agentic harness
Workflows are declared with named stages, every run is recorded stage by stage, and parallel lanes declare which files they own.
A lane that declares nothing owns nothing. Usage is recorded in tokens, and money appears only where a dated price exists — never as an estimate.
The AI control plane
Every approval carries a hosting posture — the organization's own hardware, a tenant-isolated private cloud under contract, or a vendor's public API — and the posture is what decides what the model may be shown. A workspace holds several credentials at once, each with its own boundary and its own ceiling, and a retired one stays listed with the date and the person, because the runs that happened under it did happen.
Whether work carrying regulated or member-identifying content may reach a model is a second decision, recorded separately from the hosting posture and defaulting to no. An approval is narrow until a named person widens it.
The register never holds a key — only where one lives, in words. Key-shaped text is refused at write by the database, not by a form.

The register of approvals
Approving a model is an act by a named person, stamped from their session rather than from anything a form sends. The basis is written in their own words and an approval without one fails the write, because an approval nobody had to justify is a checkbox.
Withdrawing an approval records the withdrawal beside it rather than removing the row. The runs that happened under it did happen, and a register that deleted the approval would make them unexplainable.

Tool permissions
The catalog of tools an agent can call is derived from the server that publishes them, and anything that writes is denied until a named person grants it.
A refusal names the tool, never the payload. An agent cannot grant itself a tool: every grant is a named person's act.
These are the exact names a model receives from the endpoint, and the phrase beside each is the description the model itself is given. Read or write is derived from that description rather than from a second list somebody has to remember to update. A door that writes is denied until a named person grants it.
Operating policies
A run may not widen its own permissions, may not pipe fetched bytes straight into an interpreter, may not carry regulated content past its approved boundary, and may not accept its own output. Seven are blocking and two report without stopping the work, and which is which is recorded rather than assumed.
What a policy returned for a run is sealed with a digest over the bytes it covered, and the table has no update path, so a sealed verdict cannot be rewritten after a ship — a correction is a new run. A policy with no verdict against a run reads as not evaluated, never as passed, and a waiver names a person or the database refuses to record it.
The gated AI SDLC
The bands are intake and design assurance, build and runtime security, access and data and operations, and final risk acceptance — architecture review, threat modeling, dynamic testing, penetration testing, identity and data protection reviews among them. One further check runs continuously after deploy and reports without withholding a release.
There is no gate percentage and no gate health score anywhere in the product. A gate is signed by a named person holding the owning role, waived with a recorded reason, or it is open.
A control declares when it acts, and the set is closed — the ingest door refuses anything outside it. The distinction is authority, not lifecycle: a check that runs after a release can never withhold one, so it is never counted among the thirteen.
Evidence that leaves the building
Deck and trail exports carry an Ed25519 receipt over canonical bytes, and the public key travels inside the receipt.
A claim whose count exceeds its own denominator is not rounded: the receipt is not issued. There is no partial receipt.