Proof

The Receipt That Runs

This document demonstrates the receipt shape. The values are sanitized. The tuning — the weights, thresholds, selection logic, and source assets — is not shown. The public sees the grammar of a receipt. The private repos hold the authored decisions.

The claim

Provenance mode: synthetic. This is a Proof Receipt illustration, not a ConformanceReceiptV1, production evidence, or a certification claim. All identifiers, URLs, and timestamps below are generic fixtures.

The example page serves fresh inventory data, and the data is verifiable.

The claim is a crossing: from “the system says it works” to “the wire proves it works.” The producing layer cannot certify itself. The receipt is the independently verifiable proof.

The receipt object

{
  "schema_version": "1.0",
  "proof_id": "proof_sha256_9f2c...",
  "claim_id": "claim_example_inventory_20260814",
  "claim": "The example page serves fresh inventory data",
  "source_class": "canonical_snapshot",
  "source_ref": "synthetic_snapshot_20260814T110000Z",
  "observed_at": "2026-08-14T11:00:00Z",
  "decided_at": "2026-08-14T11:05:00Z",
  "verification": {
    "method": "served_wire_fetch",
    "artifact": "https://example.com/catalog/example-item",
    "fetched_at": "2026-08-14T11:06:00Z",
    "result": "verified",
    "evidence": "rendered_inventory_matches_snapshot"
  },
  "renderer_bounds": ["translate", "format", "localize"],
  "authority": "synthetic_snapshot_owns_inventory_truth"
}

The verification path

The receipt is verified in three steps. Each step is a crossing. Each crossing has an authority.

  1. The source owns truth. The claim references a synthetic canonical snapshot. The snapshot is the source. The page does not invent the inventory state.

  2. The renderer owns expression, not semantics. The page may translate, format, and localize the value. It may not change the value. The renderer_bounds field declares the allowed set.

  3. The receipt owns proof. An independent fetch of the served wire compares the rendered value to the snapshot. The result is verified or not_verified. The producer’s report is not the evidence. The wire is the evidence.

What is NOT in the receipt

The receipt shows the shape. It does not show the tuning:

  • The implementation formulas and thresholds.
  • The snapshot selection logic.
  • The confidence weights.
  • The source assets.
  • The internal channel taxonomy.

A reader can verify that the grammar works. They cannot copy the tuning that makes the system distinctive.

The diagnostic question

When your system says it succeeded, who else can prove it?

If the answer is “the system itself,” then the crossing has no authority.

The receipt is the answer that survives the projection. It is provenance for behavior. A claim without a receipt is a projection without provenance.