Corobate standalone install · one product

Intake

Every door answers the same five questions about what arrived, and the answers are written onto the record and sealed into the receipt. They do not change a score.

An earlier design scored them. The engine’s own note refuses it: minimum-over-caps is sound because freshness, class and re-ingest ceilings measure different failure axes, and a step between two estimators of ONE axis produces a trough by construction. What an arrival proves about an identity claim is the axis the actor keyring already prices.

The five questions

UNESTABLISHED is a required answer, not a missing field. A door that can leave a question out is a door an attacker configures — last week’s audit found four separate places where an absent field was read as “fine”, including one where omitting a single property skipped half a patent claim while the receipt still read IDENTICAL OCTET FOR OCTET.
#The questionWhy it is asked
1Can we tell WHO sent it?A class is granted from an observer identity. If the arrival establishes nothing about who sent these bytes, the identity is a name somebody typed.
2Can we tell it was NOT ALTERED on the way?Integrity in transit. Without it, the bytes compared are not the bytes sent.
3Can we tell it is not an OLD READING REPLAYED?Freshness binding. A correct measurement presented late is a different fact.
4If we fetched it: WHEN, and FROM WHERE?A retrieval record is real evidence about a public source, and it is not the same evidence as a signature.
5Can the source DENY having sent it?Non-repudiation. This is the audit-log control AU-10 stated as a question about a door.

What a class rests on

The engine decides what evidence is worth from who observed it. Two things can establish that, and they are not equally strong:

Both of the first two are legitimate. What is not legitimate is granting a class the second way in silence, which is why every page that does it says so — machine checked, and the check aims at the route those pages actually take rather than at a setting they never touch.
How the identity was establishedWhat it provesWhat the class rests on
A signature over these bytes, from a key in a signed actor registrythis observer committed to this exact recorda signature
A signed rule table mapping actor names to classesthe operator signed the table; the actor name is still the caller’sthe operator’s control of their own ingest boundary
Neither — no registry configurednothing about who sent itnothing. The default floors every class to SELLER-ASSERTED, and says so on the record.

Which door each product uses

One contract, several implementations. The doors are DISCOVERED rather than listed: an enumerated set of six was proposed and a reviewer put ten real cases against it — a file upload, an email, a photograph, a PDF certificate, a receipt re-ingested from another installation — and six had no honest box. A list of doors typed today stops growing today.
ProductWhat arrivesThe doors it needs
TellmeTiresiasstaff entry and IoT device readingskeyed, device
AttestedAssetshuman entry and API responseskeyed, api
Stock Risk ReceiptAPI feeds, web pages and social postsapi, retrieved
Corobatesupply-chain activity from AI and human agentsagent, keyed
PaymentVerificationoutput of a sealed executionsealed

Where this is honest about not being finished

Corobate · standalone install · one product · built by 27-console/build-console.js from the register, not typed.

This page loads nothing from another origin, makes no request at run time, and touches no browser storage. It works from a file on disk with no server.

Nothing in this console is legal advice.