Replay and trust
Replay recomputes a decision from the receipt’s inputs using a verifier’s local kernel. Agreement establishes the comparison performed. It does not automatically identify which binary produced the original record.
A signature is checked against a key. Trust asks how that key was independently associated with the intended operator. A public sample key shipped with its sample is useful for learning, but it cannot establish an unknown sender’s authority.
Browser and kit implementations can run separately from the gate while sharing kernel and format dependencies. Agreement can therefore reflect a shared defect. Keep versioned conformance evidence and actual key provenance alongside results.
Protect receipts keep authority and occurrence unverified. Decision-receipt profiles have their own pin requirements. Read profiles, keys, and the dependency boundary before relying on a top-level success label.
Previous: A decision is not an effect. Up: Concepts. Next: Scope glossary.