Example example · read off a live run

A sealed receipt, as a counterparty receives it

This is what the other side gets when you send them one decision. It was written the moment the decision was made — nobody typed it up afterwards, and nobody had to remember to.

Decisiondcn_t2
QuestionMay lot OLIVE-OIL-3312 be released for payment and acceptance?
VerdictWITHHELD
How far it gotnowhere — one required thing is not covered, so the answer is no
The weak linkfree_acidity — the whole answer rests on this one
Sealed at2026-08-20T09:00:00.000Z
Template it was decided undersha256:535cd0f69b421e20e85827685f34ff8fd…
Inputs on the record5

What you were relying on, and how it held up

ClaimObserverClassReliabilityStatusWhy
origin_declarationactor:org:CERT-ORIGIN-ES-77VERIFIED0.95admittedsparse track record: 1 independent observation(s); no failure recorded, so the class ceiling stands
free_acidityactor:org:LAB-OIL-4410VERIFIED0withheldcontradicted memory: an independent observation of the same claim disagrees
free_acidityactor:org:LAB-OIL-9021VERIFIED0withheldcontradicted memory: an independent observation of the same claim disagrees
free_acidityMISSING0coverage_gapEVIDENCE_PRESENTED_FAILED
transport_temperatureMISSING0coverage_gapNOTHING_SUBMITTED

Read the last column. Two laboratories tested the same thing and got answers that cannot both be right, so neither counts — the record does not quietly pick a winner for you. And the claim they were both answering shows as they sent something and it did not qualify, which is a different sentence from nobody sent anything. In a year, that difference is the whole conversation.

What this does not tell you

It says what you needed, what turned up, what did not, and why. It does not say the lot is good — only that the evidence behind your decision would stand up. And if the standard you wrote has a hole in it, this has the same hole: it checks what you asked for, not what you forgot to ask for.

Break it yourself — it takes under a minute

Everything above is a claim until somebody who does not trust you can check it. So here is the checking, done twice: once on this receipt as it was sealed, and once on the same file with one character changed.

Showing the receipt as it was sealed. 20 of 22 checks agree, and 2 do not apply to a receipt of this kind.

  1. Content reproduces (JCS + SHA-256)agrees — matches sha256:5401e474316624a90684265790375e07a390c9e11c4dc4aea8dc07195063bfec
  2. Hash chain links (entry = H(prev||content))agrees — head sha256:06b45bc0373139f6ded59fe16240db960847630a0287043bf44b37973e8508f4
  3. Confidence gated by weakest critical inputagrees — min over critical = 0, bound_by lot:OLIVE-OIL-3312::free_acidity (MISSING)
  4. Verdict follows the threshold ruleagrees — 0 => WITHHELD; recorded WITHHELD
  5. Point-in-time seal (no input past data_horizon)agrees — all inputs <= 2026-08-06T13:00:00.000Z
  6. Anchor covers the head, and the timestamp token re-readsagrees — internally consistent; NO external anchor was requested — this is not a validated timestamp
  7. Criteria travel with the receipt and reproduceagrees — policy_body hashes to sha256:a6b69b7d20f7fb04d522364af1d92992058b04a5835fcec9d1c9f2261c7ef636
  8. Reliability re-derives from recorded evidenceagrees — all 5 inputs re-derive exactly
  9. Outcome trials and lineage discounts re-deriveagrees — 3 input(s) re-derive: 0 credited outcome trial(s), 0 lineage-discounted corroboration(s); every reliability is at or under its class ceiling
  10. Re-ingested receipts respect their weakest-input ceilingagrees — no re-ingested receipts: every input rests on a primary observation
  11. Release quorum re-derivesagrees — WITHHELD_NO_EVIDENCE - below the top exposure tier, no multi-party requirement applies
  12. Risk acceptance re-derivesagrees — no risk acceptance: this decision stands or falls on its evidence
  13. Observer credentials were not revoked as of observation timeagrees — revocation list 1 (0 entries, issued 2026-07-31T09:00:00.000Z, next update due 2026-08-07T09:00:00.000Z) reproduces; 3 observer signature(s) judged as of their own instant, none under a key revoked as compromised or retired by then
  14. The cryptographic suite is named and is one this verifier implementsagrees — sealed under CB-1-ES256-SHA256 (ES256 / sha256, attest-canon/2); this verifier implements it; the suite states it is NOT quantum resistant
  15. Regulatory bindings are attributed and were enforcedagrees — no regulatory instrument was consulted for this decision (regulatory: null) - a stated absence, not a gap
  16. Role-view commitments re-derive, and the customs view carries no moneyagrees — 6 role-view commitment(s) re-derived from this receipt’s own body by this verifier’s independent projection; the REGULATOR view carries no commercial figure
  17. AI-authored input was admitted only where an authority allowed itagrees — no regulatory instrument was consulted, so no authority took a position on AI-authored evidence and none was enforced - a stated absence
  18. State digest recomputes from the ledger alonedoes not apply to this receipt — NOT APPLICABLE — you supplied no ledger, so the state digest cannot be re-derived from anything. This receipt commits to the corpus the deciding system held at the instant it sealed, and that commitment is checked by recomputing it from the append-only ledger and comparing; with no ledger in hand there is no second artefact to recompute from. The receipt is not at fault and nothing here is missing from it. Obtain the ledger from the issuer and re-run with --ledger <file>, or verifyReceipt(r, {ledger}). Nothing here has failed and nothing here has passed.
  19. Registry membership re-derives for every key relied onagrees — all 2 key(s) relied on re-derive to the entries root registry v1 committed to and the trust root signed
  20. Geometric support re-derives, and an unevaluated record is not a supported oneagrees — no regulatory instrument was consulted, so no authority required geometric support and none was enforced - a stated absence
  21. The cause of every uncovered requirement re-derivesagrees — all 2 uncovered requirement(s) re-derive their cause from this receipt's own rows. What notice is ADEQUATE is not decided here: this check establishes what the record says and that the record agrees with itself.
  22. The sealing party is the one you were told to expectdoes not apply to this receipt — NOT APPLICABLE — you supplied no trust bundle, so nothing here establishes who sealed this. Identities 1 to 20 prove that this document agrees with itself; not one of them asks whose trust root it was sealed under, and a document that agrees with itself about a decision nobody made agrees with itself perfectly. Obtain the issuer's corobate:trust-bundle:1 out of band, confirm its spoken fingerprint with them by voice, and re-run with --trust-bundle <file> --expect-fingerprint <what you heard>. Nothing here has failed and nothing here has passed.

What was changed. One number: the weight carried by origin_declaration moved from 0.95 to 0.9501. Nothing else in the file was touched — no hash was recomputed, no signature was re-made.

Run through the same checker, that single change is caught by 4 of the 22 checks, and each one says which part of the record no longer adds up. You do not have to understand any of them. You have to know that somebody who wanted to could run this without asking us.

Two words the checker uses, in plain English

The lines above are the checker's own wording, not ours — it is a separate program and it says what it says. Two of its words are worth translating once:

Doing it on your own machine

Both runs above came out of verify-receipt.js — a program that does not import the engine that wrote the receipt, holds no key, makes no request and has no account to sign in to. It keeps working if we stop trading.

node verify-receipt.js receipt.json

The file is receipt.json, beside this page. Or do it here, now, with nothing installed: open this record in the checker. It is the same file, and the checker did not come from us either — it re-derives every number from the record and holds no key.

The row near the top naming the standard is how a reader knows which version of your requirements this was decided under — useful when your requirements change, as they do.

Every number on this page came out of a real run. The company and the lot are invented; the workings are not. The page opens from a file — no server, no sign-in, nothing fetched.

Nothing here is legal or financial advice.

Everything on this site

Terms · Privacy · Licence · partners@corobate.com · Corobate LLC, North Carolina, USA