# What a receipt records about who acted

Canonical: https://www.meshqu.com/knowledge/actor-identity

Does a Decision Receipt prove who took the action?

No. MeshQu records and cryptographically binds the actor identifier the calling application supplies. It does not check that identifier against an identity provider, and the record does not establish which model or agent implementation acted behind a credential. Binding an unverified claim is still worth doing, because it converts a mutable log line into something that cannot be edited after the outcome is known, but it is narrower than attribution.

## In more detail

Two questions sit close together and have different answers. The authenticated API key identifies the calling system, and that identification is cryptographic. The actor field identifies the responsible party within that system, and that is a claim the calling system makes. MeshQu binds the claim so it cannot be altered afterwards, which is a real property, but binding is not authentication. Your application is responsible for ensuring the actor is accurate at the moment of the call, and your identity and permission controls remain necessary. A second boundary sits behind the first. The subject of a credential is a credential. The record does not say which model, version or agent implementation acted behind it, so a question about which system produced an output is not one the receipt answers. Describing what a receipt carries as attribution is the easiest way to overstate it.

## Limits

- Actor is the safe noun and approver is not. A receipt records who acted, not necessarily who approved.
- Actor attribution is optional. The documentation states that where decisions are fully automated and actor identity is not a compliance requirement, it need not be supplied.
- Storing names in the record has data-protection consequences MeshQu does not manage. The documentation advises against putting full names, email addresses or other personal data in the actor identifier.
- This entry does not quote the permitted values of the actor type field. The documentation states two different pairs on different pages, and the discrepancy is unresolved.
- Binding an actor identifier says nothing about whether the named party had authority to act. Authority is a separate question from identity.

## Where it applies

- Answer an auditor who asks whether a receipt establishes the identity of the person named on it.
- Decide what your application must supply, and what it must continue to control, before a receipt is offered as evidence of responsibility.
- Separate the question of which system called from the question of who within that system was responsible.

## Sources

- [MeshQu docs - Actor attribution](https://docs.meshqu.com/guides/actor-attribution): Which actor fields are covered by the integrity hash, and the documentation owner's statement that MeshQu does not authenticate actor identities against an identity provider.
- [MeshQu docs - Trust model](https://docs.meshqu.com/security/trust-model): The two-layer split between a client-supplied attestation and a cryptographically verified API-key identity.
- [MeshQu docs - Responsible-AI evidence](https://docs.meshqu.com/concepts/responsible-ai-evidence): Why a bound but unverified actor claim is worth recording, and why calling it attribution overstates it.
- [MeshQu docs - Receipt reference](https://docs.meshqu.com/concepts/receipt-reference): The statement that the subject of the record is a credential, not a model or agent implementation.

## Related answers

- [The limits of verification](https://www.meshqu.com/knowledge/limits-of-verification): What does verifying a Decision Receipt actually prove?
- [Decision Receipts: what the record contains](https://www.meshqu.com/knowledge/decision-receipts): What is in a Decision Receipt, and what does it prove?
- [What a receipt evidences about a responsible-AI commitment](https://www.meshqu.com/knowledge/responsible-ai-evidence): Can a Decision Receipt show that an AI decision was fair, accurate or correct?

## Next step

[Actor attribution guide](https://docs.meshqu.com/guides/actor-attribution)

Updated 11 September 2026
Machine-readable: https://www.meshqu.com/knowledge/actor-identity.json
All reviewed answers: https://www.meshqu.com/knowledge
