Why it matters.
Five workflows that show what a Trooth record changes for a person or an AI agent. Each one is an illustration, not a customer story: it names a role, the steps, exactly what is read, where a person decides, and what it cannot do.
Illustrative
Five workflows, step by step
Illustrative sample. Not live data. Every workflow uses what the product does today. For the exact response an agent receives, see the agents page.
01An assistant gives an old answer about a vendorIllustrative
Illustrative sample. Not live data. No customer is named, quoted or measured here.
- Who
- An analyst at a buying company who asks an AI assistant about vendors.
- What they need
- Find out where a vendor stores customer data, and when that was last stated.
- Before
- The assistant answers from old blog posts and a cached security page. Two of its sources disagree, and the answer carries no date.
- Step by step
- The analyst adds the Trooth server to the assistant as a custom connector, using the address on the agents page. No key or account is needed.
- The analyst asks where the vendor stores customer data.
- The assistant calls the trooth_public_trust_profile tool with the vendor's domain.
- Trooth answers with the published profile: each fact with its origin and date, and a status of published, unclaimed, private or unavailable.
- The assistant quotes the facts with their dates and says which ones the vendor declared and which ones Trooth read itself.
- Exactly what is read
- The vendor's published Trust Profile, and nothing that is not published.
- Each fact's origin: declared by the company, read by Trooth, or taken from a public source.
- Each fact's date, and whether it is past its freshness window.
- The response status and provenance, such as honest_absence when Trooth holds no record.
- Where each fact comes from
- Every fact names who said it and when. A fact the company declared stays labeled as declared, so the assistant is never told it was checked.
- Where a person decides
- The analyst reads the dated facts and decides. Trooth does not control what the assistant writes, and a model can still misquote a source.
- Outcome
- The answer names a current source and its date, and says plainly where Trooth holds no record.
- Limitation
- Trooth covers only what a vendor published or what Trooth read. It cannot correct what a model learned elsewhere, and unavailable means try again, not a finding about the vendor.
02A secure connection is not a company recordIllustrative
Illustrative sample. Not live data. No customer is named, quoted or measured here.
- Who
- A security reviewer at a buying company.
- What they need
- Work out what a vendor's secure website does and does not tell them.
- Before
- The site loads over an encrypted connection with a current certificate. That protects the connection and ties it to the domain. It says nothing about who runs the company or what the product does with data.
- Step by step
- The reviewer opens the vendor's page on the Trooth Network.
- The page shows that the company proved control of its domain with a Domain Name System (DNS) record, and when that record was last checked.
- The page shows what Trooth read from outside, including the Transport Layer Security (TLS) setup, each with the date it was read.
- Below that, the page lists the company's disclosures about itself and its product, each with its source and date.
- The reviewer opens a fact to see where it came from and when it was last read.
- Exactly what is read
- The DNS record that shows domain control, and its last check.
- The TLS details Trooth reads from outside, with read dates.
- The company's published disclosures, each with its source and date.
- Where each fact comes from
- Domain control and outside readings are labeled as Trooth's own reads. Disclosures are labeled as the company's word.
- Where a person decides
- The reviewer decides what the disclosures mean for this purchase. Trooth does not grade the company.
- Outcome
- The reviewer can tell what DNS and TLS establish, what they leave open, and reads the rest with a source and a date.
- Limitation
- DNS and TLS say nothing about a company's internal controls. A company's own declaration does not either, which is why it is labeled as declared.
03Last year's questionnaire, still in the folderIllustrative
Illustrative sample. Not live data. No customer is named, quoted or measured here.
- Who
- A procurement lead finishing a vendor review.
- What they need
- Check whether an old questionnaire and PDF still describe the vendor.
- Before
- The packet arrived as a spreadsheet and a PDF with no dates on the answers. Nobody can tell which answers changed since it was sent.
- Step by step
- The vendor sends a link to its Trooth page with the packet.
- The lead opens the link and sees what Trooth read, each item with the date it was read.
- The company's declarations show when they were made, and a fact past its freshness window reads as stale.
- The lead saves the vendor to a list in the buyer workspace, and the change feed shows what changed since the last visit.
- Documents the vendor keeps behind a request, such as an audit report, show a request button rather than the file.
- Exactly what is read
- Current readings, with the date each was read.
- The company's declarations, with the date each was made.
- Changes since the lead last looked.
- The list of documents the vendor offers on request.
- Where each fact comes from
- Each item says whether Trooth read it or the company declared it, and when. A stale fact is labeled stale rather than hidden.
- Where a person decides
- The lead still reviews the answers against the buying company's own policy. Trooth does not replace that review.
- Outcome
- The lead works from dated facts and can see which ones changed since the packet was written.
- Limitation
- A document behind a request arrives only if the vendor grants it. Anything the vendor never published is not on the page.
04An agent that stops when a fact is missingIllustrative
Illustrative sample. Not live data. No customer is named, quoted or measured here.
- Who
- An AI agent a buying company authorized to prepare new integrations.
- What they need
- Check a vendor before proposing to connect it to the company's systems.
- Before
- The agent would read the vendor's marketing site and decide by itself whether the vendor is acceptable.
- Step by step
- The agent calls the trooth_public_trust_profile tool with the vendor's domain.
- It checks the status first: published, unclaimed, private or unavailable.
- It reads identity, product scope, and each fact's origin and date, against the buying company's written policy.
- Where a fact the policy needs is missing, restricted, disputed or stale, it stops and asks a person.
- Where every fact the policy needs is present and current, it proposes the integration and waits for a person to approve it.
- Exactly what is read
- The status and provenance fields of the response.
- Each fact's origin and date.
- The buying company's own policy, which the company holds and Trooth never sees.
- Where each fact comes from
- The agent reports which facts it relied on and where each one came from, in the words of the response.
- Where a person decides
- A person approves before anything is connected. The agent proposes and does not act on its own.
- Outcome
- The agent pauses on a gap instead of inventing a pass or a fail.
- Limitation
- Trooth does not run the agent or hold its policy. The pause is the agent's behavior, set by whoever builds it; Trooth supplies the status and provenance it needs to pause.
05The same facts, in the tool the team already usesIllustrative
Illustrative sample. Not live data. No customer is named, quoted or measured here.
- Who
- A third-party risk analyst whose team works in a governance, risk and compliance (GRC) platform.
- What they need
- Record a vendor review in that platform without retyping the vendor's answers.
- Before
- The analyst copies answers from the vendor's page into the platform by hand, and the dates are lost on the way.
- Step by step
- The analyst saves the vendor to a list in the Trooth buyer workspace.
- They export the list's procurement pack as a CSV or JSON file.
- In their own platform, they paste the vendor's Trooth Trust Center link and upload the file as evidence, the way that platform takes evidence from any vendor.
- Exactly what is read
- The facts in the saved list, each with its source, date and disclosure.
- The vendor's public Trust Center link.
- Where each fact comes from
- Every exported fact keeps its source, date and disclosure, so the platform's copy still says who said what and when.
- Where a person decides
- The risk conclusion in that platform belongs to the analyst's team. Trooth does not supply it, and it is not a Trooth claim.
- Outcome
- The review carries dated, sourced facts without retyping.
- Limitation
- Trooth has no native connector for any of these platforms. The uploaded file is a copy and does not change when the Trooth record changes.
Read a company's record yourself.
Every page reads the current record, and every fact carries its source and the date it was last read.