Exactly — and the next step is proving that
mapping at the HTTP layer before the request
hits the agent. We sign a trust score into a
request header (HMAC-SHA256) so the gateway
knows it's a verified human session, not an
automated script impersonating one.
Zero PII collected.