Pass
Controlled Validation
Controlled validation is limited to controlled positive and negative process-creation fixtures.
Hoxline by HawkinsOperations
Executable claim control for AI-assisted security work.
Capability Visual Data Pack v1 shows what Hoxline can verify today: HO-DET-001 loop execution, reviewer-readable outputs, output contract checks, bounded claim decisions, and still-gated runtime and signal evidence.
Pass
Controlled validation is limited to controlled positive and negative process-creation fixtures.
Hoxline Engine Room
The current public example is HO-DET-001: Hoxline packages the Gauntlet loop, emits reviewer outputs, preserves controlled-validation scope, and hands claim wording to source-owned authority surfaces.
Clone-runnable path
Generated status prevents stale website numbers from becoming accidental authority. The source routes and commands make the review path inspectable instead of presentation-only.
Generated website input; not proof authority.
git clone https://github.com/HawkinsOperations/hoxline.gitWorking directory after clone: hoxline repo root
python -B -m pytest -q testsRepo: HawkinsOperations/hoxline. Working directory: hoxline repo root.
python -B -m hoxline gauntlet verify --input examples/gauntlet/ho-det-001-full-loop-run-v0.json --schema schemas/gauntlet-full-loop-run-v0.schema.jsonRepo: HawkinsOperations/hoxline. Working directory: hoxline repo root.
npm run check:siteRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
npm run buildRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
These commands are review paths in their owning repositories. Website rendering displays the route; it does not convert command output into proof authority.
Detection-to-ProofOps route
Hoxline is strongest when the incoming security work already carries source, ATT&CK orientation, telemetry assumptions, and validation boundaries into Claim Authority.
Source truth: detection source packages, ATT&CK orientation, event-field contracts
ATT&CK context: reviewer orientation; not live coverage proof
Controlled validation: 49 controlled validation fires / 106 validation cases
Proof ceiling: proof records and claim ceilings where present
Runtime Candidate Ledger: BLOCKED
Signal Observation: MISSING_EVIDENCE
Hoxline can run the canonical ProofOps loop for HO-DET-001.
Hoxline can emit reviewer-readable JSON.
Hoxline can emit reviewer-readable Markdown.
Hoxline can verify the Gauntlet full-loop output contract.
Hoxline can preserve the CONTROLLED_TEST_VALIDATED proof ceiling.
Hoxline can map artifact state to allowed claim wording.
Hoxline can map blocked claim families to safer wording and missing evidence.
Hoxline can keep runtime and signal gated when evidence is missing.
Controlled capability before gated states
Capability Visual Data Pack v1 makes the product feel like an engine: it records the canonical HO-DET-001 loop, reviewer outputs, output contract checks, bounded metrics, visual modules, and remaining gates without promoting runtime or signal claims.
What Hoxline can verify today
Positive capability is shown first; the PR #13 maturity chart keeps gated areas visible without taking over the story.
Hoxline can run the canonical ProofOps loop for HO-DET-001.
examples/gauntlet/ho-det-001-full-loop-run-v0.jsonHoxline can emit reviewer-readable JSON.
examples/gauntlet/ho-det-001-full-loop-run-v0.jsonHoxline can emit reviewer-readable Markdown.
examples/gauntlet/ho-det-001-full-loop-run-v0.mdHoxline can verify the Gauntlet full-loop output contract.
schemas/gauntlet-full-loop-run-v0.schema.jsonHoxline can preserve the CONTROLLED_TEST_VALIDATED proof ceiling.
examples/gauntlet/ho-det-001-full-loop-run-v0.jsonHoxline can map artifact state to allowed claim wording.
examples/gauntlet/ho-det-001-proofcard-v0.jsonHoxline can map blocked claim families to safer wording and missing evidence.
examples/gauntlet/ho-det-001-full-loop-run-v0.jsonHoxline can keep runtime and signal gated when evidence is missing.
examples/gauntlet/ho-det-001-full-loop-run-v0.jsonHoxline can represent authority separation across the seven-repo system.
README.mdHoxline can show one artifact, one loop, one safe claim, and blocked stronger claims.
docs/gauntlet/HO_DET_001_GAUNTLET_RUN.mdstage_status_distribution
Capability Visual Data Pack v1 exposes the loop as status data, not as a flat warning list.
$env:PYTHONPATH='src'; python -B -m hoxline gauntlet run --artifact HO-DET-001 --format json
$env:PYTHONPATH='src'; python -B -m hoxline gauntlet run --artifact HO-DET-001 --format markdowngenerated_outputs_chart
Reviewer-readable outputs are surfaced as artifacts. They are routes to inspect, not proof promotion.
json
Target reader: reviewer or website data loader.
Open artifact ->visual modules
The website renders the exact visual modules defined by the Capability Visual Data Pack v1.
Show Hoxline as a working ProofOps control plane for one artifact.
Render the 11-stage loop with status coloring.
Show generated outputs and verifier command.
Separate built capabilities from gated capabilities.
Show seven-repo authority separation.
Trace artifact data from demo packaging through Gauntlet output.
Show one allowed claim and collapsed blocked families.
Show the concrete artifacts available to reviewers and website loaders.
Show how a reviewer moves from source references to safe claim.
Summarize remaining gates without making them the primary story.
Show bounded counts that explain the amount of working structure.
Hoxline by HawkinsOperations
Executable claim control for AI-assisted security work.
ProofOps control for the AI security era. AI is not the authority. Evidence is. Hoxline controls what AI-assisted security work is allowed to become while Capability Visual Data Pack v1 keeps runtime, signal, public-safe, production, customer, and approval claims blocked unless evidence exists.
Interactive visual intelligence
The same controlled-loop data is rendered as a stage orbit, authority constellation, evidence path timeline, and claim decision matrix. These visuals make complexity inspectable without turning the website into proof.
Gauntlet engine
Tap a node to inspect status, reviewer note, authority refs, and missing evidence.
Pass
Controlled validation is limited to controlled positive and negative process-creation fixtures.
authority_surface_chart
Hoxline is the control route. It does not replace proof, source, validation, platform, website, or org routing boundaries.
control
ProofOps control plane
Owns claim boundary packaging, Gauntlet runner, output contract, and website-ready data; does not own proof authority.
build_timeline
Tap a node to inspect what exists today and what remains gated.
manifest
Controlled demo artifacts and reviewer entry points were packaged.
claim_decision_chart
Toggle the decision families. Blocked claims are visible as boundaries, not as product claims.
allowed
One allowed controlled-validation claim is present in the visual data pack.
AI speed meets evidence discipline
AI can draft convincing security claims faster than an organization can safely prove them. Hoxline keeps generated output, evidence, validation, telemetry, proof ceilings, and human review from collapsing into one public sentence.
Problem
AI-assisted work can create detection ideas, summaries, and reviewer notes quickly.
Problem
Evidence, validation, telemetry, proof records, and review gates must stay explicit.
Problem
The dangerous step is turning useful output into wording that sounds stronger than the evidence.
Authority boundary
Hoxline is the control layer for claim movement. It does not make the website a proof source, does not promote public_safe, and does not convert controlled validation into runtime or signal proof.
From generated output to claim-ready evidence
Hoxline organizes the movement from AI-assisted work into reviewer-readable evidence boundaries. Each control keeps one authority surface from being confused with another.
Intake
Generated security work enters as a named artifact with scope, source, and reviewer context attached.
Graph
Artifact, validation, runtime candidate, signal, review, and claim nodes stay separated for inspection.
State
Controlled fixture status is shown as evidence state, not as runtime or signal truth.
Ceiling
The current ceiling travels with the artifact so public language cannot climb past evidence.
Decision
Claim Authority separates allowed controlled-validation wording from blocked stronger families.
Review
The route points reviewers to proof, source, validation, and platform authority before trust is granted.
Separate the layers
The product value is not a bigger claim. It is a disciplined route that keeps generated output, evidence, validation, proof records, public rendering, and claim authority in separate compartments.
Layer
Useful draft material, never authority.
Layer
References attached to source-controlled artifacts.
Layer
Controlled behavior checks with explicit fixture scope.
Layer
Owned by the proof authority surface, not this page.
Layer
Readable website surface only.
Layer
Hoxline capability for allowed and blocked wording.
Interactive control diagram
Tap a step to inspect the control. The active step shows what happens, what control applies, and what remains blocked.
Interactive ProofOps loop
Tap a step to inspect the control.
5 of 11: Controlled Validation
Active gate
One artifact, one loop, one bounded claim
HO-DET-001 is the flagship example for the current route. It demonstrates controlled validation boundaries without promoting runtime, signal, public-safe, production, customer, or final authorization claims.
Artifact
The demo package shows controlled positive and negative fixture validation evidence and keeps the current ceiling visible. It does not authorize stronger public wording.
State
ProofCard
Allowed wording
HO-DET-001 has controlled validation evidence from controlled positive and negative process-creation fixtures and remains under review.
This wording stays below the current evidence ceiling.
Blocked claim
Merged HO-DET-001 ProofCard v0 / Gauntlet controlled-validation bridge.
Inspect pathOpen routeMerged reviewer packet summarizing bridge, strategy docs, and website route.
Inspect pathOpen routeOpen the bounded reviewer case-file rendering route.
Inspect pathClaim Authority
Hoxline makes the decision surface visible: what the current evidence allows, what remains blocked, and what needs authority review.
Allowed
Blocked
Blocked
Required
Seven surfaces, separate authority
The architecture is intentionally split. Hoxline controls product flow and claim decisions, while proof, source, validation, platform, rendering, and organization routing keep their own authority boundaries.
product/control plane
Routes AI-assisted work into evidence-bound claim decisions.
source truth
Owns detection packages, rule context, and source metadata.
behavior truth
Owns controlled fixture behavior status.
contracts/ledgers/promotion authority
Owns schemas, ledgers, and promotion mechanics.
proof authority
Owns proof records and evidence ceilings.
rendering only
Displays public reviewer routes without creating proof.
org/reviewer routing
Connects org-level review and workflow routing.
Where to begin
A reviewer should not start by trusting the page. Start with the controlled package, then inspect ceilings and authority references.
Step 1
Start with the HO-DET-001 bridge, release packet, and existing bounded case-file route.
Step 2
Confirm the ceiling is CONTROLLED_TEST_VALIDATED and stronger claim families remain blocked.
Step 3
Check proof, detections, validation, and platform surfaces before trusting public wording.
Reviewer lens
Hoxline makes the evidence ceiling and blocked claim families visible before AI-assisted security work becomes public wording.
Authority boundary
This route renders the packet as reviewer orientation only. Rendering is not proof, public_safe remains false, private runtime references are not public proof, human review remains required, no ledger append happened, no public proof promotion happened, and no schedule was enabled.
Reviewer packet
Hoxline Public Reviewer Packet v0 keeps public_safe false, human review required, website rendering below proof, and green CI below approval.
Reviewer packet
HO-DET-001 has controlled validation evidence and remains under governed review.
Reviewer packet
The packet does not claim runtime proof, signal observation, production readiness, customer deployment, SOCaaS deployment, AI approval, analyst approval, case closure, or public proof promotion.
Reviewer packet
Both remain waiting on real operator evidence; marker hits without governed execution IDs do not establish operator receipt evidence.
Reviewer packet
Private runtime reference digests are hash references only. They are not public proof and do not raise the public proof ceiling.
Reviewer packet
No ledger append, no public proof promotion, and no schedule enablement are created by this page.
Merged HO-DET-001 ProofCard v0 / Gauntlet controlled-validation bridge.
Inspect pathOpen routeMerged reviewer packet summarizing the bridge, strategy docs, and website route.
Inspect pathOpen routeDraft controlled demo packaging work. Demo packaging only; not merged proof.
Inspect pathOpen routeRead the public reviewer packet boundary and current-state explanation.
Inspect pathOpen routeInspect the sanitized current-state packet data.
Inspect pathOpen routeInspect the fail-closed schema constants for the packet.
Inspect pathOpen routeInspect controlled fixture status and blocked runtime or signal states.
Inspect pathStill gated
These states remain required before stronger public claims can move.
Website rendering cannot supply these records. Hoxline visualizes the boundary and keeps public_safe false with human_review_required true.
Authority boundary
This is the compact operating boundary for the page. Hoxline helps control claims, but it does not create proof authority or promote stronger states by rendering them.
Evidence required before stronger claims
Stronger wording would require separate evidence and authority updates. Website rendering cannot supply those gates.
Required next evidence
Required next evidence
Required next evidence
Required next evidence
Required next evidence