What the decision rests on today
A log, about itself.
Every one of these is believed because of who supplied it. None of them can be checked by the person who has to answer for what a machine did.
A log is written by the thing it describes. It can be edited by whoever runs it, and usually is, by policy.
A timestamp is whatever the writer's clock said. There is no second clock to hold it against.
A retention policy decides what survives the incident. The evidence you need is the evidence most likely to be gone.
What oddly puts on the record
The same thing, observed.
Two clocks on every row: when the source said it was true, and when we looked. A root a day. An anchor outside us. Nothing here is our word.
The standards index and the crawler registries, re-observed on their own cadence: the parts of the web everything else depends on.
When the source published it, and when we looked. Where the source runs ahead of us we show the sign rather than hide it, because the flattering reading is the one that must never win.
The day your agent's actions are observed the same way, its receipts sit under the same roots. Declared, not sold, until it exists.
The verbs
Observe. Seal. Publish. Anchor.
The same four on every surface. A product here is the record read for one decision, never a second machine.
Read the source as it is published, and write down both clocks.
Hash the row with its predecessor, so no receipt can move without every later one changing.
Fold the day's receipts into one root and put it where anyone can read it.
Submit the root to a chain we do not run. From then on, checking us does not involve us.
One receipt from this surface, read live
One document, its two clocks, and the seal over both.
Every slot below is read at load. A row reads [unread] when the newest observation on the ledger belongs to another class, because printing somebody else's receipt under this heading is the one thing this surface exists to refuse.
- observation
- [unread]
- subject
- [unread]
- class
- [unread]
- attribute
- [unread]
- value now
- [unread]
- value before
- [no public read serves a change pair]
- source
- [unread]
- observed
- [unread]
- fetched
- [unread]
- clock gap
- [unread]
- receipt
- [unread]
- day root
- [today's root]
- anchored in block
- [pending]
- confirmed
- [pending]
The ruled landing for this surface is a document whose status CHANGED, with the value before and the value after. The estate holds those pairs and no public read serves one: the observation read answers with the newest row and nothing else, and the change count published beside it is taken across every class at once, which is a different fact. So the value before slot stays empty rather than borrowing a number, and the anchor reads [pending] until a day has been confirmed in a block, because a pending batch has no block height.