Standing register, last read 2026-09-05
8 systems, read against 20 requirements drawn from the four conformance levels. Every verdict cites a file and a line at a pinned commit, and an absent verdict cites where the assessor looked and did not find it, which is the difference between a measurement and an accusation.
This is not a certification and nobody applied for it. It is a reading of published source, and it is wrong in the ordinary way that readings are wrong. The remedy is below and it does not involve persuading anybody.
| System | TR-1 | TR-2 | TR-3 | TR-4 | Reaches | Read by | Last read |
|---|---|---|---|---|---|---|---|
| AutoGen | 1/5 | 2/4 | 1/7 | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| CrewAI | 1/5 | 0/5 | 1/7 | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| Graphiti | 4/5 | 3/5 | n/a | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| LangGraph | 4/5 | 0/4 | 2/7 | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| Letta Code | 3/5 | 0/4 | 3/7 | 1/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| mem0 | 3/5 | 0/5 | n/a | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
| OMEM the author's own | 5/5 | 5/5 | 7/7 | 3/3 | TR-4 | Michael Brandon Clifford | 2026-09-05 |
| OpenAI Agents SDK | 2/5 | 1/5 | 2/7 | 0/3 | none yet | Michael Brandon Clifford | 2026-09-04 |
A count is met out of applicable. A system that does not act is not marked down for having no gate, and the requirements that do not apply to it are not counted against it.
Does a consequential action produce a durable entry whether or not it ran?
| System | R3.1 | Where it was read |
|---|---|---|
| AutoGen | part | python/packages/autogen-agentchat/src/autogen_agentchat/agents/_code_executor_agent.py:69-73 ApprovalRequest |
| CrewAI | part | lib/crewai/src/crewai/agents/crew_agent_executor.py:984-989 |
| Graphiti | n/a | |
| LangGraph | yes | libs/langgraph/langgraph/types.py:851 interrupt |
| Letta Code | yes | src/agent/check-approval.ts:26-34 |
| mem0 | n/a | |
| OMEM | yes | server/tests_testimony_export.py |
| OpenAI Agents SDK | part | src/agents/run_state.py:1356-1370 _serialize_tool_invocations |
It is a file. Open a pull request against the subject file naming the requirement and where to look, or write to troy@machinetestimony.com with the same. A correction that lands changes the file, this page, and the date on the row. There is no fee, no membership, and no requirement to use any software of mine.
Arguing with me is not the remedy and does not work. Pointing at code is, and has: this register carries corrections that came from being told I had read something wrong.
All of them, Michael Brandon Clifford, which is the weakest thing about this register. A reading nobody has repeated is one person's reading, however carefully it cites its sources.
The instrument is not reserved. The rubric is CC BY 4.0 and the tooling is MIT, commercial use included and expected: if you audit AI systems, or advise on Article 12 or Article 14, or have to answer a procurement question about what a supplier's agent records, you can run these questions yourself and bill for it without asking anybody. How to do that, including how to put the result here with your own name on the row, or keep it and publish it yourself.
Being absent is not a judgement. It means nobody has done the reading yet. The rubric and the harness are in the repository, so you can run the questions against your own system before anybody else does, and the answer will be the same one I would get.
One row is the author's own implementation, of the format the questions derive from. It scores well here the way a dictionary's author spells well, and it carries no evidential weight. It is included so the questions are applied to the system that produced them before they are applied to anybody else's.
That has not been costless. Five findings so far are recorded against this assessment, three of them against its author, including one after publication: on 5 September 2026 the top conformance level was found not to be checking what it claimed, and the author's own passing row was the one affected. It is written up in full rather than quietly repaired.
Some of these questions a reader can settle from a record alone: whether cited evidence exists, whether a refused action is also recorded as executed, whether a digest is the digest of what it covers. Others are attestations, and no reading of source can confirm them: that a risk class really came from a registry, that an approver's name really came from the session it names. The specification marks the difference and the validator reports it, and a conformance claim that does not distinguish them is weaker than it looks.