Skip to content

Keep a receipt after its issuer is gone.

A witness is a separate operator that retains an ActionReceipt and returns proof that the exact file entered its log.

The receiving party can keep an ActionReceipt after the agent or provider goes offline. That preserves the provider’s transaction record; it does not prove that the reported action occurred.

If the issuer is the only party retaining a copy, the record can still be deleted or withheld. A witness checks the exact receipt, commits it to a separately operated append-only log, and returns proof of inclusion.

plurality instrument · 2026-07-15
1
operated logs
0
receipt witnesses
0
independent logs
draft
operator manifest
ActionReceipt witnesses · 0 · the operated log above is a composition-deed registry, not an ActionReceipt witness; an operated log does not itself establish independent plurality

What this check cannot tell you

An operated composition-deed log is not independent ActionReceipt witness plurality; the current independent-witness count is zero.

What the witness must establish

FunctionWhat it establishes
VerifyThe receipt’s hashes and structure recompute
RetainThe exact receipt exists outside the issuer’s runtime
ProveThe witness returns the leaf, log size, and root
ExposeAuthentic same-size conflicting roots become equivocation evidence

What this check cannot tell you

Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions.

Example: retaining a routed-inference receipt

The draft profile carries one full term commitment throughsingle_route_single_provider. Parent references bind the exact observed occurrence and vouched envelope. They do not make an actor-supplied timestamp, execution claim, or remedy endpoint independently true.

bulla.routed-inference/0.1-draft · 14 local adversarial traces · identity verification

01

inference.order

02

inference.route

03

inference.accept

04

inference.delivery

05

bulla.rely

Answerability

covered-on-conforming-local-traces

Bindings remain retained; v0.1 supports no discharge.

Recourse

verified-on-conforming-local-traces

Conveyance is checked; operational reachability is unverified.

Accounting

signed-declarations

Signed declarations only; settlement is unverified.

Reproduction

14/14 traces

0 external implementations; local handoff demo true.

draft · single_route_single_provider · disclosure full · live provider false · settlement adapter false · external implementations 0 · independent ActionReceipt witnesses 0Download evidence bundle →

The ledger can detect a contradiction in signed charges: each hop must reconcile its upstream charge, downstream charge, and retained amount, and the root quote must stay within the order ceiling. That is accounting conformance, not evidence of actual compute consumption or payment.

The offline handoff demo isolates the harness, router, provider, relier, and stranger verifier. It is still local: transport, retention policy, operator discovery, pooling, and a public WitnessBundle format wait for operational evidence.

What this check cannot tell you

The routed profile is a local, full-disclosure, single-router/single-provider draft with no live provider, settlement adapter, or independent implementation.

Roles kept separate from witnessing

A witness keeps a record in one consistent history and proves it is there. It does not decide whether the record is legitimate—that a claim is true, that a process met its terms, or that a loss should be paid. Those are distinct roles, and holding them apart is what keeps a record layer from becoming the court that rules on its own logs.

Separate roleAnswers a question the witness does not
AdjudicatorWhether a contested claim or procedure holds—heard in a named forum, not by the log
AppraiserWhether process evidence meets the agreed policy—an attester under a declared standard
UnderwriterWhat stake backs the claim, and who pays when it fails—capital, never the record-keeper

What this check cannot tell you

A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational.

Witness role · planned

The next proof is operational.

ActionReceipt witnesses · 0

The intended service verifies a receipt on intake, commits it to an append-only log, and returns proof. No ActionReceipt witness is currently evidenced. No access is offered and no operators are recruited; the role and the evidence required to claim it are specified below.

Example A · unsigned local receipt

integrity
verified
authority
unauthenticated
inclusion
absent
actor time
unresolved

Example B · team-witnessed receipt

integrity
verified
inclusion
team-operated witness
independence
absent
actor time
unresolved

Example C · independently witnessed

status
not yet available

witness inclusion never resolves actor time or underlying execution; independence is a control-domain property, not an infrastructure property

How operation earns a protocol

01

Service evidence

Run one manual receipt witness against real actions.

02

Operating evidence

Measure retention, privacy, latency, omission, and proof delivery.

03

Interoperability

Prove append, proof, and gossip behavior with a second independent operator.

04

Protocol

Freeze a format only after independent operators have exercised it.

Collateral is not part of the current surface. It requires an objective fault predicate, a real settlement rail, and independent operators before an economic mechanism can be specified honestly.

Roadmap — a witnessed record proves what entered witnessed history; it cannot prove the underlying process occurred or what was left undone. A drafted commitment slot opens a record before an act, so coverage becomes an obligation: a slot opened must close, and one still open past its deadline is objective evidence of omission.