Skip to main content

What a receipt records about who acted

Does a Decision Receipt prove who took the action?

No. MeshQu records and cryptographically binds the actor identifier the calling application supplies. It does not check that identifier against an identity provider, and the record does not establish which model or agent implementation acted behind a credential. Binding an unverified claim is still worth doing, because it converts a mutable log line into something that cannot be edited after the outcome is known, but it is narrower than attribution.

In more detail

Two questions sit close together and have different answers. The authenticated API key identifies the calling system, and that identification is cryptographic. The actor field identifies the responsible party within that system, and that is a claim the calling system makes. MeshQu binds the claim so it cannot be altered afterwards, which is a real property, but binding is not authentication. Your application is responsible for ensuring the actor is accurate at the moment of the call, and your identity and permission controls remain necessary. A second boundary sits behind the first. The subject of a credential is a credential. The record does not say which model, version or agent implementation acted behind it, so a question about which system produced an output is not one the receipt answers. Describing what a receipt carries as attribution is the easiest way to overstate it.

Limits

  • Actor is the safe noun and approver is not. A receipt records who acted, not necessarily who approved.

  • Actor attribution is optional. The documentation states that where decisions are fully automated and actor identity is not a compliance requirement, it need not be supplied.

  • Storing names in the record has data-protection consequences MeshQu does not manage. The documentation advises against putting full names, email addresses or other personal data in the actor identifier.

  • This entry does not quote the permitted values of the actor type field. The documentation states two different pairs on different pages, and the discrepancy is unresolved.

  • Binding an actor identifier says nothing about whether the named party had authority to act. Authority is a separate question from identity.

Where it applies

  • Answer an auditor who asks whether a receipt establishes the identity of the person named on it.

  • Decide what your application must supply, and what it must continue to control, before a receipt is offered as evidence of responsibility.

  • Separate the question of which system called from the question of who within that system was responsible.

Sources

Related answers