Skip to main content

The limits of verification

What does verifying a Decision Receipt actually prove?

Verification checks the signed record, bound policy and context, evidence references and applicable proofs. Integrity and signature checks work together to detect changes to bound content; a signature alone is insufficient. It does not prove true inputs, authenticated actor identity, a correct decision or that an action was carried out. Offline checks also require the necessary material and separately trusted keys, with export enabled for the deployment.

In more detail

A receipt evidences the policy version that governed the recorded assessment, the supplied context, the outcome and integrity information. It does not settle whether the inputs were true, whether a person was who the calling system said, whether the decision was correct, or whether the application carried out the action. The actor identifier is supplied by the caller; role and authority are display annotations. The record does not explain a model's internal reasoning or establish its version or configuration. Tamper evidence needs integrity recomputation and signature checking together: a content edit can leave the signature over stored integrity information valid, so a signature alone is not a content-integrity verdict. Offline checking depends on the required material, export enablement and independently obtained trust roots. There is no audit-proof or guaranteed-compliance claim.

Limits

  • Integrity and signature checks together detect changes to bound content; a valid signature alone does not establish unchanged content.

  • It does not prove that the inputs were true, that the decision was correct or that the action was carried out.

  • The actor identifier is supplied by the calling system. MeshQu does not independently authenticate it; displayed role and authority are not verified identity.

  • The record does not establish which model, version or configuration produced a result, or explain a model's internal reasoning.

  • A receipt describes the policy, rules checked, context and outcome. A rule-by-rule assessment view does not establish the outcome for each individual rule or the evidence for each rule in the signed record.

  • Offline verification requires the necessary material and separately trusted keys. Export must be enabled for the deployment.

  • No audit-proof, guaranteed-compliance or quantified-savings claim is made.

Where it applies

  • Set expectations with a reviewer, auditor or regulator about what a signed record does and does not settle.

  • Identify what a counterparty needs before independent checking is promised: separately trusted public keys.

Sources

Related answers