Rubicon tells you exactly where Bob's rollback stops — and proves what remained after rollback. Classify every action. Enforce a human permit at the boundary. Independently verify every state domain.
When an IBM Bob agent runs in auto-approve mode, it can execute dozens of tool calls without manual review. Bob's rollback recovers workspace files — but only a bounded subset of what the agent actually changed.
Every Bob agent action is mapped to one or more state domains. Rubicon determines which side of the line each domain lives on before execution.
* Verified metrics from the 21-drill causal benchmark (Arm A baseline vs. Arm B & C enforced). All SHA-256 state manifests and Ed25519 receipts cryptographically verified.
Rubicon integrates directly into IBM Bob IDE as an essential safety gate — not a superficial claim.
Blocks dangerous actions before execution via exit code 2. Configured in .bob/settings.json.
Records post-execution state for manifest comparison. Observational only — does not alter execution.
Invoked by the human in Bob IDE. Rubicon independently inspects all domains to prove whether restoration succeeded.
The proof page answers all 10 required judge questions with verifiable evidence, including receipt hashes, domain-level verdicts, and Ed25519 signature checks.