Generated website input; not proof authority.
Hoxline by HawkinsOperations
HoxlineRun the ProofOps loop.
Executable claim control for AI-assisted security work.
ProofOps control for the AI security era. AI is not the authority. Evidence is. Hoxline controls what AI-assisted security work is allowed to become while Capability Visual Data Pack v1 keeps runtime, signal, public-safe, production, customer, and approval claims blocked unless evidence exists.
Hoxline Engine Room
Run the ProofOps loop against real detection work.
The current public example is HO-DET-001: Hoxline packages the Gauntlet loop, emits reviewer outputs, preserves controlled-validation scope, and hands claim wording to source-owned authority surfaces.
Clone-runnable path
Run the Hoxline review path
Generated status prevents stale website numbers from becoming accidental authority. The source routes and commands make the review path inspectable instead of presentation-only.
- 01HO-DET-001
- 02Gauntlet
- 03Artifacts
- 04Verifier
- 05Claim gate
Download, clone, and run commandsReviewer-runnable
git clone https://github.com/HawkinsOperations/hoxline.gitWorking directory after clone: hoxline repo root
npm run public-status:generateRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
npm run public-status:verifyRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
npm run check:siteRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
npm run typecheckRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
npm run test:visualRepo: HawkinsOperations/hawkinsoperations-website. Working directory: hawkinsoperations-website repo root.
These commands are review paths in their owning repositories. Website rendering displays the route; it does not convert command output into proof authority.
Detection-to-ProofOps route
What enters the loop: source behavior, attack context, validation state.
Hoxline is strongest when the incoming security work already carries source, ATT&CK orientation, telemetry assumptions, and validation boundaries into Claim Authority.
Source truth: detection source packages, ATT&CK orientation, event-field contracts
ATT&CK context: reviewer orientation; not live coverage proof
Controlled validation: 49 controlled validation fires / 106 validation cases
Proof ceiling: proof records and claim ceilings where present
Runtime Candidate Ledger: BLOCKED
Signal Observation: MISSING_EVIDENCE
Hoxline can run the canonical ProofOps loop for HO-DET-001.
Hoxline can emit reviewer-readable JSON.
Hoxline can emit reviewer-readable Markdown.
Hoxline can verify the Gauntlet full-loop output contract.
Hoxline can preserve the CONTROLLED_TEST_VALIDATED proof ceiling.
Hoxline can map artifact state to allowed claim wording.
Hoxline can map blocked claim families to safer wording and missing evidence.
Hoxline can keep runtime and signal gated when evidence is missing.
Interactive visual intelligence
Gauntlet engine
The same controlled-loop data is rendered as a stage orbit, authority constellation, evidence path timeline, and claim decision matrix. These visuals make complexity inspectable without turning the website into proof.
Interactive loop
The 11-stage Hoxline loop
Tap any stage to inspect what exists, the AI role, the output artifact, and the next handoff. Runtime and signal claims stay gated until evidence is promoted.
AI-assisted security work
- What exists
- AI drafts detections, queries, and reviewer notes at speed.
- AI / automation role
- AI produces labor fast; it holds no authority.
- Output artifact
- Draft candidate
- Next handoff
- Hands a named draft to Artifact Intake.
$ ai draft --task ho-det-001 → candidate.draft
build_timeline
Reviewer path from source to gated claims
Tap a node to inspect what exists today and what remains gated.
manifest
HO-DET-001 controlled demo packaging
Controlled demo artifacts and reviewer entry points were packaged.
claim_decision_chart
Allowed, blocked, and required evidence
Toggle the decision families. Blocked claims are visible as boundaries, not as product claims.
allowed
Allowed controlled claim
One allowed controlled-validation claim is present in the visual data pack.
From generated output to claim-ready evidence
What Hoxline Controls
Hoxline organizes the movement from AI-assisted work into reviewer-readable evidence boundaries. Each control keeps one authority surface from being confused with another.
Intake
AI output intake
Generated security work enters as a named artifact with scope, source, and reviewer context attached.
Graph
Evidence graphing
Artifact, validation, runtime candidate, signal, review, and claim nodes stay separated for inspection.
State
Validation state
Controlled fixture status is shown as evidence state, not as runtime or signal truth.
Ceiling
Proof ceiling
The current ceiling travels with the artifact so public language cannot climb past evidence.
Decision
Claim decision
Claim Authority separates allowed controlled-validation wording from blocked stronger families.
Review
Reviewer handoff
The route points reviewers to proof, source, validation, and platform authority before trust is granted.
One artifact, one loop, one bounded claim
HO-DET-001 Controlled Demo Spotlight
HO-DET-001 is the flagship example for the current route. It demonstrates controlled validation boundaries. It does not promote runtime, signal, public-safe, production, customer, or final authorization claims.
Artifact
HO-DET-001: controlled validation bridge
The demo package shows controlled positive and negative fixture validation evidence and keeps the current ceiling visible. It does not authorize stronger public wording.
State
CONTROLLED_TEST_VALIDATED
Controlled validation evidence exists for the bounded package.ProofCard
Rendering route
The website can display the ProofCard context but does not become proof authority.Allowed wording
Safe claim
HO-DET-001 has controlled validation evidence from controlled positive and negative process-creation fixtures and remains under review.
This wording stays below the current evidence ceiling.
Blocked claim
Runtime / signal / public-safe
Runtime, signal, public-safe, production, customer, and final authorization wording remain blocked.PR #7 bridge
Merged HO-DET-001 ProofCard v0 / Gauntlet controlled-validation bridge.
Inspect sourceOpen sourceRelease packet
Merged reviewer packet summarizing bridge, strategy docs, and website route.
Inspect sourceOpen routeHO-DET-001 route
Open the bounded reviewer case-file rendering route.
Inspect routeClaim Authority
Claim Boundary Matrix
Hoxline makes the decision surface visible: what the current evidence allows, what remains blocked, and what needs authority review.
Allowed
Controlled validation evidence exists
HO-DET-001 has controlled positive and negative fixture validation evidence under the current ceiling.Blocked
Runtime or signal promotion
Runtime-active, runtime proven, signal observed, and public signal proof wording remain blocked.Blocked
Public release or deployment wording
public_safe remains false; production, customer, deployment, and SOCaaS status are not claimed.Required
Human and authority review
human_review_required remains true and authority references must be inspected before stronger claims.Seven surfaces, separate authority
Authority Architecture
The architecture is intentionally split. Hoxline controls product flow and claim decisions, while proof, source, validation, platform, rendering, and organization routing keep their own authority boundaries.
Control map
Seven surfaces, separate authority
Select a surface to see what it owns, what stays in another gate, and where to inspect it.
Source
- What exists
- A detection source, SPL, or rule candidate exists and is reviewable.
- Owns
- Owns where work enters the system.
- Output artifact
- HO-DET-001 source
- Boundary
- Runtime and signal claims stay in later gates.
$ open detections/successor/ho-det-001/rule.yml
product/control plane
hoxline
Routes AI-assisted work into evidence-bound claim decisions.
source truth
hawkinsoperations-detections
Owns detection packages, rule context, and source metadata.
behavior truth
hawkinsoperations-validation
Owns controlled fixture behavior status.
contracts/ledgers/promotion authority
hawkinsoperations-platform
Owns schemas, ledgers, and promotion mechanics.
proof authority
hawkinsoperations-proof
Owns proof records and evidence ceilings.
rendering only
hawkinsoperations-website
Displays public reviewer routes without creating proof.
org/reviewer routing
HawkinsOperations.github
Connects org-level review and workflow routing.
Where to begin
Reviewer Start Path
A reviewer should not start by trusting the page. Start with the controlled package, then inspect ceilings and authority references.
Step 1
Inspect the controlled demo package
Clone the Hoxline repo, run `python -B -m hoxline demo quickstart`, then read `.hoxline/demo-runs/<timestamp>/reviewer-pack.md`. The demo is deterministic, local, fixture-based, and not runtime proof.
Step 2
Inspect the proof ceiling and blocked claims
Confirm the ceiling is CONTROLLED_TEST_VALIDATED and stronger claim families remain blocked.
Step 3
Inspect authority references
Check proof, detections, validation, and platform surfaces before trusting public wording.
Reviewer lens
What leadership can trust
Hoxline makes the evidence ceiling and blocked claim families visible before AI-assisted security work becomes public wording.
- The product controls claim movement, not proof truth.
- The safe claim stays below CONTROLLED_TEST_VALIDATED.
- public_safe remains false and human review remains required.
Authority boundary
Hoxline Public Reviewer Packet v0
This route renders the packet as reviewer orientation only. Rendering is not proof, public_safe remains false, private runtime references are not public proof, human review remains required, no ledger append happened, no public proof promotion happened, and no schedule was enabled.
- Packet status
- NOT_PUBLIC_SAFE
- Public ceiling
- CONTROLLED_TEST_VALIDATED
- Private references
- hash references only
- Website
- rendering only
- Human review
- required
- Promotion
- not promoted
Reviewer packet
Current-state panel
Hoxline Public Reviewer Packet v0 keeps public_safe false, human review required, website rendering below proof, and green CI below approval.
Reviewer packet
Allowed claim
HO-DET-001 has controlled validation evidence and remains under governed review.
Reviewer packet
Blocked stronger claims
The packet does not claim runtime proof, signal observation, production readiness, customer deployment, SOCaaS deployment, AI approval, analyst approval, case closure, or public proof promotion.
Reviewer packet
Private runtime candidate boundary
HO-DET-009, HO-DET-010, HO-DET-011, and HO-DET-012 may be referenced only as private runtime candidate and standing collector support. They remain NOT_PUBLIC_SAFE, human review required, and not public proof.
Reviewer packet
Private reference boundary
Private runtime reference digests are hash references only. They are not public proof and do not raise the public proof ceiling.
Reviewer packet
No promotion side effects
No ledger append, no public proof promotion, and no schedule enablement are created by this page.
PR #7 bridge
Merged HO-DET-001 ProofCard v0 / Gauntlet controlled-validation bridge.
Inspect sourceOpen sourceRelease packet
Merged reviewer packet summarizing the bridge, strategy docs, and website route.
Inspect sourceOpen sourcePR #10 draft
Draft controlled demo packaging work. Demo packaging only; not merged proof.
Inspect sourceOpen sourceReviewer packet doc
Read the public reviewer packet boundary and current-state explanation.
Inspect sourceOpen sourceReviewer packet JSON
Inspect the sanitized current-state packet data.
Inspect sourceOpen sourceReviewer packet schema
Inspect the fail-closed schema constants for the packet.
Inspect sourceOpen routeValidation registry
Inspect controlled fixture status and blocked runtime or signal states.
Inspect routeStill gated
What stronger wording still needs
These states remain required before stronger public claims can move.
Website rendering cannot supply these records. Hoxline visualizes the boundary and keeps public_safe false with human_review_required true.
Authority boundary
Trust Boundary
This is the compact operating boundary for the page. Hoxline helps control claims, but it does not create proof authority or promote stronger states by rendering them.
- Website rendering
- not proof
- Hoxline
- not proof authority
- runtime / signal
- blocked
- public_safe
- false
- Human review
- required
- Controlled validation
- current ceiling only
Evidence required before stronger claims
Next Gate
Stronger wording would require separate evidence and authority updates. Website rendering cannot supply those gates.
Required next evidence
Separate runtime evidence from the appropriate authority path.
Required next evidence
Preserved signal evidence tied to the artifact and telemetry contract.
Required next evidence
Updated promotion ledger state in the platform authority surface.
Required next evidence
Proof authority update that raises the ceiling without relying on website rendering.
Required next evidence
