Federal AI procurement evidence

Machine-readable proof for federal AI review.

Planisphere turns a team-owned AI workflow into open-format evidence: graph context, harness result, signed receipt, OSCAL-aligned export, data-catalog metadata, schema-bound validation receipt, and OpenAPI inspection.

01 ·

The federal proof rails.

OSCAL-aligned JSON · DCAT-style metadata · AI acquisition inspection
01 · OSCAL direction

Evidence exports the machine can read.

The export maps workflow decisions, route status, control refs, and signed receipt fields into an OSCAL-aligned JSON read model. It supports package assembly; it is not a FedRAMP Certification Package or an agency ATO.

Open API boundary
02 · Open data posture

Metadata stays portable before publication.

The data-catalog export uses open JSON with access, distribution, and disclosure-review fields. Protected tenant data, raw agency data, secrets, and private engine code stay out of the public catalog path.

Open API boundary
02 ·

The validation profile is explicit.

structural checks · official validation not claimed · owner review stays downstream
01 · OSCAL read model

Structural pass, official OSCAL not claimed.

planisphere.oscal_read_model.v0 checks required sections, FedRAMP anchors, signed evidence packets, raw-content omission, and claim-boundary presence. Official NIST OSCAL schema validation and agency package submission remain downstream.

02 · Open data metadata

Metadata bridge, publication not claimed.

planisphere.project_open_data_metadata_bridge.v0 checks Project Open Data-style core fields, non-public defaults, open distributions, Active Manifest inclusion, and protected-data boundaries. It does not publish a Federal Data Catalog entry.

03 · AI acquisition review

Inspection posture, award not claimed.

planisphere.omb_m_25_22_ai_acquisition_review.v0 checks OpenAPI portability, risk-monitoring evidence, owner routes, private-IP boundary, and proposed-rule watchlist treatment. It does not guarantee eligibility, bid acceptance, or funding continuity.

03 ·

The validation receipt is a workflow.

schema source · tenant binding · local run · owner route
Schema choose source

/tenant/exports/validation-schema-manifest names packaged dev profiles, official-source candidates, promotion gates, and the claim boundary.

Binding record owner choice

/tenant/exports/validation-schema-bindings stores the binding key, schema hash, source type, and owner attestation without storing raw schema payloads by default.

Run preflight artifact

/tenant/exports/validation-runs returns local pass or gap status, schema hash, artifact hash, sanitized errors, and a durable run key.

Review route owner lane

/tenant/exports/validation-runs/overview joins the run receipt to the schema binding, review owner, and raw-content boundary for tenant review.

Visible proof

Fields a buyer can inspect.

  • binding_key and binding_receipt_hash
  • run_key and validation_run_receipt hash
  • schema_hash and artifact_hash
  • validation_status and sanitized error count
  • raw_content_stored=false
  • official_result_claimed=false
Still downstream

What the receipt does not decide.

  • Official NIST OSCAL schema validation
  • Federal Data Catalog publication approval
  • FedRAMP Certification or agency ATO
  • Bid acceptance, award recommendation, or funding continuity
  • Legal, medical, export-control, or procurement approval
  • Release of protected agency or tenant content
04 ·

The claim boundary is inspectable.

strong evidence, narrow claims, no black-box handoff
Planisphere can provide

What a federal team can inspect.

  • OpenAPI route contract and generated examples
  • OSCAL-aligned evidence export over raw-safe metadata
  • DCAT-style data catalog metadata for owner review
  • AI acquisition export for portability and monitoring
  • Validation profile for each federal export
  • Signed receipt fields: payload hash, root, stamp, signature
Planisphere does not claim

What still belongs to the agency or assessor.

  • FedRAMP Certification, agency ATO, or bid decision
  • Official OSCAL validation or catalog publication
  • Public-data release without FOIA, privacy, and IP review
  • Legal, medical, export-control, or procurement approval
  • Raw prompt, raw document, raw key, or secret preservation
  • Customer access to private Planisphere engine code
05 ·

Where this sits in the product.

graph first · harness second · evidence third · compliance before approval
Graph workflow context

Surface, tenant, system boundary, control refs, route owner, and data handling posture.

Harness proposed action gate

The AI action is checked before execution, then routed to the right owner when it needs review.

Evidence signed receipt

The public verifier recomputes the raw-safe receipt metadata without seeing raw content.

Compliance review lane

The export helps internal or external compliance inspect the record before acceptance.