Web4 Artifacts
AgentUI artifacts are provenance-ready only when public-safe, redacted, and backed by generated or confirmed target-service records. Local-only drafts, operator-only payloads, private approvals, and target-service outputs without confirmation are not verified public results.
Public-safe
Templates, rendered form summaries, public workflow summaries, public run summaries, public artifact hashes, delegation envelopes, manifests, policy files, and route evidence hashes.
Operator-only
Private exports, execution packets, target-service mutations, approval decisions, and persisted artifact writes are not exposed from the public UI.
Never public provenance
Auth tokens, cookies, raw headers, raw IPs, private form inputs, operator-only tool arguments, operator-only tool results, private run logs, and private report exports.
Confirmation rule
AgentUI shows Docs URLs, Evals scorecards, Sandbox logs, BrowserOps screenshots, Sheets references, and Webhook deliveries only after the target service confirms them.