Skip to content
Perspectives
← All perspectives

WEB4-043 · WEB4

Security Evidence and Provenance for Machine Authority

Evidence should preserve the whole authority-to-outcome story.

01

Big idea

Evidence should preserve the whole authority-to-outcome story.

02

Picture

See the structure

A sealed evidence bag connecting permission, action, outcome, revocation, and later review.

Open two-rail trace connecting actor and workload identity, authority source, delegation, policy, decision, execution, outcome, revocation, provider state, evidence, provenance, and independent verification.
Machine Authority Provenance. Figure 1. Machine-authority provenance preserves a causal trace from actor and workload identity through authority, policy, decision, execution, outcome, termination, enforcement state, evidence packaging, and independent verification. The final proof remains historical evidence; it never loops back into current authority.
03

The simple version

Explain it like I’m ten

After a window breaks, one photo is not enough. The teacher needs to know who had the ball, who allowed the game, what rule applied, what happened, whether play was stopped, and which facts are still missing.

04

Tell it at dinner

A story worth remembering

After a window breaks, one photo is not enough. The teacher needs to know who had the ball, who allowed the game, what rule applied, what happened, whether play was stopped, and which facts are still missing.

Now make the same problem larger: replace the children and ordinary objects with people, organizations, AI agents, robots, records, and resources moving at machine speed. Machine-authority evidence must connect identity, authority, policy, decision, execution, outcome, revocation, and later trust state with honest VERIFIED, REFUTED, or INCONCLUSIVE claims. Claim-oriented evidence improves incident response, audit, accountability, and cross-domain assurance without pretending that logs prove more than they do.

Pause at the moment the small system could go wrong. That is the design question the paper keeps in view: not whether people or helpers are clever, but whether the surrounding structure preserves the intended meaning when action scales.

That is why the small story holds: evidence should preserve the whole authority-to-outcome story.

05

Explain it to a CEO

Why leaders should care

Claim-oriented evidence improves incident response, audit, accountability, and cross-domain assurance without pretending that logs prove more than they do. Machine-authority evidence must connect identity, authority, policy, decision, execution, outcome, revocation, and later trust state with honest VERIFIED, REFUTED, or INCONCLUSIVE claims.

06

Explain it to an engineer

What the model means

Use evidence profiles, correlation, provenance envelopes, signer-generation trust, trusted-time boundaries, privacy minimization, and runtime-independent verification. Integrity, signer trust, and claim truth remain separate dimensions; evidence never creates authority.

Talk hook

A log can show that something happened. Can it show why it was allowed and what happened next?

Ask the room

Which future claim about a machine action could your evidence actually verify today?

Go deeper

The Canon is the source of truth.

WEB4-043 formalizes this structure: Machine-authority evidence must connect identity, authority, policy, decision, execution, outcome, revocation, and later trust state with honest VERIFIED, REFUTED, or INCONCLUSIVE claims. The ordinary-life story is an intuition aid, not a replacement definition; the canonical paper remains authoritative for scope, terminology, limitations, and argument.

Read WEB4-043 — the authoritative paper →

Same idea. Different resolution.

Perspectives explain the Canon. The research papers remain authoritative.

Open the Canon library