Who this is for: Engineering teams, compliance officers, and GRC analysts deploying Meta Muse agents in regulated environments. Covers EU AI Act (GPAI providers), NIST AI RMF, SR 11-7, CMMC, and ISO 42001.

1. What SWT3 Does in Muse

SWT3 is a passive compliance witness. It observes your Muse agent's actions and creates tamper-proof cryptographic evidence of what happened. It never modifies agent behavior, never adds latency to the critical path, and never sends your prompts or responses to any server.

How it works: SWT3 hashes your inputs and outputs locally, extracts numeric factors (latency, token count, pass/fail status), and anchors them into a cryptographic fingerprint. The auditor gets verifiable evidence. You keep your data.

When connected to Muse, SWT3 records evidence for:

Each event produces a witness anchor with a unique cryptographic fingerprint that anyone can independently verify has not been altered.

2. One-Message Setup (Stdio)

Muse natively supports MCP servers. The fastest integration path is a single message in any Muse conversation. Copy and paste:

Build a custom integration to the SWT3 AI Witness MCP server.
Install it with: npx @tenova/swt3-mcp
It runs over stdio with Node.js. No authentication is needed for
demo mode. Connect to it, test the witness_inference and
list_procedures tools end to end, show me the results, and save
the integration as a reusable skill.

This installs the MCP server on Muse's VM and connects immediately. Demo mode creates local anchors with no account required.

Connected mode (persistent ledger)

To persist anchors to a cryptographic ledger where auditors can verify them, add your API key:

Build a custom integration to the SWT3 AI Witness MCP server.
Install it with: npx @tenova/swt3-mcp
It runs over stdio with Node.js. Set the environment variable
SWT3_API_KEY to my key (I'll provide it through the secure
credential flow). Connect, test witness_inference and
list_procedures, and save as a reusable skill.

Muse stores credentials through its Secure Credentials Store, separate from the agent runtime. Your API key is never visible in conversation text.

No API key yet? Use the signup tool inside Muse to create a free account and get one instantly.

3. URL-Based Setup (Streamable HTTP)

For teams running a self-hosted SWT3 MCP endpoint, Muse can connect via URL instead of installing the npm package.

Build a custom integration to the SWT3 AI Witness MCP server.
It is a remote MCP server over streamable HTTP at:
https://your-endpoint.example.com/mcp
No authentication is needed for the MCP connection itself.
Connect to it with the official MCP SDK, test witness_inference
and list_procedures end to end, and save the integration as a
reusable skill.

Running the HTTP endpoint

# Start the streamable HTTP server (localhost:3100)
npx @tenova/swt3-mcp-http

# With API key for persistent anchors
SWT3_API_KEY=axm_live_... npx @tenova/swt3-mcp-http

# Custom port
SWT3_MCP_PORT=3200 npx @tenova/swt3-mcp-http

The server binds to 127.0.0.1 by default. Place a reverse proxy (Caddy, nginx) in front for TLS and public access.

4. What Gets Witnessed

SWT3 exposes 68 witnessing tools via MCP. The ten most relevant for Muse agent governance:

ToolProcedureWhat It Records
witness_inference AI-INF.1 Every model call: model identity, prompt/response hashes, latency. Raw text is hashed locally and never leaves the machine.
witness_authorization AI-ACC.1 Pre-action permission decisions. Records whether a request was authorized before execution.
witness_guardrail AI-GRD.1 Safety classification results from guardrail checks on inputs or outputs.
witness_chain_handoff AI-CHAIN.1 Multi-agent delegation events. Records custody transfer from one agent to another with a shared chain identifier.
witness_human_review AI-HITL.1 Human-in-the-loop review completions. Records reviewer identity and decision.
witness_consent AI-CONSENT.1 Consent collection and lawful basis documentation for data processing.
witness_nhi_scope NHI-SCOPE.1 Service account authorization scope. Records what credentials the agent is permitted to access.
witness_mcp_security AI-MCP.1 MCP server security posture assessment. Evaluates 8 security checks with a composite score.
list_procedures -- Browse the full UCT procedure registry (280 procedures across 77 regulatory frameworks).
verify_anchor -- Verify the cryptographic integrity of any existing witness anchor.

All 68 tools are available to Muse. Run list_procedures in any conversation to browse the complete registry filtered by framework, namespace, or keyword.

5. Clearing Levels

You control exactly what information leaves the machine. SWT3 clearing levels determine data retention granularity:

LevelNameWhat Is Recorded
0 Analytics Full metadata: model identity, latency, token counts, all context fields. For internal dashboards and trend analysis.
1 Standard Hashes, model identity, and context. The default level. Suitable for most compliance requirements.
2 Sensitive Hashes and model identity only. Context fields are stripped. For environments with heightened data sensitivity.
3 Classified Numeric factors only. Model identity is hashed. For classified or air-gapped environments.

At every level, raw prompt and response text stays on your machine. Only cryptographic hashes and numeric factors are transmitted.

Set the clearing level via environment variable:

SWT3_CLEARING_LEVEL=2 npx @tenova/swt3-mcp

6. Demo vs. Connected Mode

Demo ModeConnected Mode
Setup No account, no API key Free account + API key
Anchors Logged to stderr (local only) Persisted to cryptographic ledger
Verification Local fingerprint only Public verification via swt3.ai/verify
Auditor access Not available Shareable audit trail with assessor portal
Retention Session only 90 days (free), unlimited (paid tiers)
All 68 tools Available Available

Demo mode is fully functional for evaluation. Every tool works identically. The only difference is where anchors are stored.

To upgrade from demo to connected mode, use the signup tool inside Muse:

Use the signup tool to create a free SWT3 account.

This creates your account and returns an API key without leaving the conversation.

7. Framework Coverage

SWT3 witnesses map to 77 regulatory frameworks through the UCT (Unified Control Taxonomy) crosswalk engine. Frameworks most relevant to Muse deployments:

FrameworkRelevance to MuseKey Procedures
EU AI Act Meta is a GPAI provider under Articles 52-55. Every Muse deployer inherits transparency and risk management obligations. AI-INF.1, AI-HITL.1, AI-CONSENT.1, AI-EXPL.1, AI-DATA.1
NIST AI RMF US federal and enterprise AI risk management. Governs model transparency, bias testing, and incident response. AI-INF.1, AI-GRD.1, AI-FAIR.1, AI-INCIDENT.1, AI-GOV.1
SR 11-7 Federal Reserve model risk guidance. Required for financial institutions using AI agents for decision-making. AI-INF.1, AI-MDL.5, AI-DRIFT.1, AI-HITL.1
ISO 42001 AI management system certification. Applicable to any organization seeking third-party AI governance certification. AI-GOV.1, AI-INF.1, AI-HITL.1, AI-DATA.1, AI-INCIDENT.1
OWASP MCP Top 10 MCP-specific security risks. SWT3 is the first MCP server with full coverage of all 10 risks. AI-MCP.1, AI-MCP.2, AI-MCP.3, AI-MCP.4, NHI-SCOPE.1

Use resolve_crosswalk inside Muse to look up how any procedure maps to your specific framework.

8. How It Works

Muse Agent SWT3 MCP Server Axiom Ledger | | | |--- tool call request ------->| | | |--- process + respond ---->| |<-- tool call response -------| | | | | | (response already sent) | | | |--- hash inputs locally | | |--- extract factors | | |--- mint fingerprint | | |--- POST anchor ---------->| | | |--- store + verify | | | | | Auditor / Assessor | | | | | |--- verify anchor | | |--- export evidence

The response is already on the wire before the witness fires. SWT3 cannot add latency, cannot cause tool failures, and cannot modify agent behavior. This is a deliberate architectural decision: compliance evidence collection must never interfere with the system it observes.

9. Common Questions

Does SWT3 see my prompts and responses?

SWT3 hashes them locally using SHA-256 and only transmits the hash (first 16 hex characters). The raw text never leaves your machine at any clearing level.

Can SWT3 interfere with my Muse agent?

No. The witness fires after the response is already committed to the wire. It cannot delay, modify, or fail any tool call. If the witness POST fails (network error, server down), the tool call still succeeds normally.

What happens if I do not have an API key?

SWT3 runs in demo mode. All 68 tools work identically. Anchors are logged to stderr instead of the ledger. Use the signup tool to create a free account from inside Muse.

How do I verify an anchor?

Use the verify_anchor tool in Muse with any anchor string, or visit swt3.ai/verify to verify in a browser. Verification checks that the anchor's cryptographic fingerprint has not been altered.

Which Muse tier do I need?

SWT3 works with any Muse tier (Free, Power, Maximum). The MCP server is an open-source integration. SWT3's own tiers (Free, Pro, Enclave) control ledger retention and export formats, not connectivity.

Can my auditor access the evidence?

Yes. Connected mode (with API key) stores anchors in a cryptographic ledger. Auditors can verify individual anchors, access an assessor portal with read-only controls, and export evidence in OSCAL, HTML, or W3C Verifiable Credential formats.

Is this the same MCP server listed on the MCP Registry?

Yes. @tenova/swt3-mcp is listed on the MCP Registry as io.tenova/swt3-witness. The Muse integration uses the same server, same tools, same protocol.

How many tools are available?

68 witnessing tools covering 280 compliance procedures across 77 regulatory frameworks. 9 procedure namespaces: AI, NHI, HBOM, DPP, ADR, FIN, CON, HCF, and INF.