Why a one-time test decays
A vendor passes the conformance suite during procurement. Six weeks later they ship a prompt change to improve call completion rates, and the new opening line buries the disclosure two turns deeper. Nothing in a procurement-time test result would tell you.
Continuous conformance re-runs the same open test suite whenever an agent version changes, and treats a regression as an operational event with an owner — not a document that expires quietly.
TrustLayer runs the same deterministic controls as the open framework — this module adds operations around them, not different rules.
Worked example
An agent update is detected. The suite re-runs. Two controls hold; one regresses.
Illustrative monitoring output — not live product data.
Action: human review required. A DBC-01 regression is not an alert to be acknowledged and cleared. It routes to a named reviewer, with the failing case and the prior passing version attached, and the agent’s status in the registry reflects the open finding until someone resolves it.
What triggers a re-run
Agent version change
A new agent version registers, or a vendor reports an update to a deployed agent.
Scope or delegation change
Permissions widen, an owner changes, or a delegation is renewed with different bounds.
Scheduled interval
Periodic re-evaluation so an unchanged agent still produces a current result, not a stale one.
Suite update
When the open conformance suite adds cases, existing agents are re-measured against the new bar.
Related
The same tests, run once or run continuously.
TrustLayer by NHID-Clinical is in active development. It is not an accredited standard, a certification, or a regulatory compliance guarantee. The open framework it enforces remains free under CC BY 4.0 and is never gated behind a plan.