This is the whole stack, top to bottom. The tools most organisations rely on sit to the side and watch. The place a decision actually has to be proven is the layer beneath it — and that layer is nearly always empty.
Logging platforms, dashboards, alerting. They read what the system emits and show it back to you. The record they keep lives in a database your own team can edit, so it says what you currently claim happened — not that nothing changed it since.
watches · cannot proveContent filters and policy layers that inspect what a model says. Useful, but they act on the text after the model has produced it, and they keep no evidence a regulator can check without trusting the vendor who wrote them.
filters · cannot proveThe model, the agent, the automated decision itself — the moment something is actually decided and acted on. This is the event that has to be evidenced. It is also the moment the watching layers above only ever see second-hand.
Each decision is sealed into a hash chain at the moment it is made, anchored to a clock nobody controls, and cross-witnessed by independent systems. Not a record you keep and hope is believed — a record anyone can verify with your company switched off.
When software did what it was told, watching it was enough — the inputs implied the outputs, and a log of the inputs was as good as a record of what happened. That is no longer true.
An autonomous system produces outputs you cannot derive by looking at the inputs. So the output has to be recorded as a fact in its own right, at the moment it happens, in a form nobody can quietly change afterwards. A layer that watches from the side cannot do that — by the time it sees the decision, the decision has already happened, and the only record is one the operator can edit.
This is why the volume problem bites. One reviewed decision a day can be watched by a person. Millions of automated decisions a month cannot — and the moment one is contested, "our dashboard showed it" is not evidence. It is an assertion with good formatting.
On the watching layer, yes — the record sits in a database they control. On the evidence layer, changing one record breaks every record after it.
On the watching layer, no — you log into the vendor to see it. On the evidence layer, a standalone verifier checks it with no account and no network call back.
On the watching layer, the date comes from a field the system could set to anything. On the evidence layer, the timing is fixed by a clock nobody involved controls.
On the watching layer, order is not recorded. On the evidence layer, the reviewer's decision is sealed before the machine's verdict is shown to them.
Every claim on the evidence layer is verifiable right now, with no account, with our company switched off. Start with the live chain, or read the full architecture.
Read the whitepaper See the live chain