Verification model
What a permitted party can confirm at the interface. Verification is not the same as trusting a PDF or a chat transcript.
Exclusions: What verification excludes.
What you can confirm
| Question | Confirmable at the interface |
|---|---|
| Where is the shared record | Scoped shared state on Stratum when entitled to read |
| Who connected as the agent | Credential subject / actor digests as published for callers |
| What pack bound the call | Granted packs on the short-lived credential |
| Whether a write was only prepared | Prepare payloads with commit: false until submit of a signed payload |
| Whether an external signature was required | Write path always requires external sign before commit |
| Whether evidence has a fingerprint | When Arbiter interface exposes it (maturity labeled) |
Who verifies
| Party | Typical confirmation |
|---|---|
| Operator | Entitlement, readiness, credential minting |
| Counterparty reader | Shared-record revision and integrity signals they are entitled to see |
| Security / GRC | Authority boundary, disclosure package, framework mapping as evidence mapping |
| Assessor (when Arbiter entitled) | Fingerprint / seal / export surfaces labeled for that environment |