Which record answers which question?
A receipt can preserve a claim without proving the event. A witness can retain the receipt without judging the claim. A buyer can rely on evidence without turning it into universal truth.
An agent transaction can cross several systems. Each system may pass its own checks while no one retains the complete handoff. ActionReceipts preserve the transaction claims. Bulla checks the parts a supplied policy can decide. A witness can keep the exact receipt in a separate log. These jobs remain separate so one successful check cannot silently answer a different question.
Keeping responsibility attached across handoffs
The routed-inference draft states the program’s current operational invariant as answerability conservation: no consequential transition may create an orphaned consequence or silently discharge an inherited binding. Attributable principals, applicable terms, and conveyed recourse remain attached until a future authenticated closure or novation protocol exists.
answerability(edge) =
attributable principals
+ exact parent occurrence
+ conserved terms and slot
+ conveyed recourse
+ no silent dischargeEvidence strength behaves differently. A chain is only as well supported as the evidence needed at each hop. Receipts preserve responsibility; they do not manufacture proof of execution.
Seven separate checks
Inclusion under a host-served root is still the host’s assertion. The relying party must pin, gossip, or independently anchor the root before the proof reaches independently grounded inclusion depth.
What this check cannot tell you
A host's assertion about its own root is not independent grounding; the relying party must obtain or anchor the root separately.
A witnessed record can establish that a particular receipt entered an authenticated history and can make same-size conflicting heads objective equivocation evidence. It cannot establish that the provider performed the process it described or that no unlogged action occurred.
What this check cannot tell you
Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions.
Recourse conveyance and recourse reachability are intentionally different report dimensions. The current routed corpus can verify consistent conveyance; reachability remains unverified.
What this check cannot tell you
A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational.
Where semantic-composition diagnosis fits
Bulla’s original diagnostic compares the full conventions needed by a composition with the conventions its public schemas disclose. Its coboundary-rank difference localizes independent undisclosed dimensions:
disclosure_deficit = rank(delta_full) - rank(delta_observable)This is a valid formal and operational object inside the pinned composition model. A diagnostic can be referenced by an ActionReceipt, and an executable convention can be recomputed by a verifier. Neither operation turns the diagnostic into authority, execution evidence, persistent witnessing, or a remedy.
What this check cannot tell you
The coherence fee measures undisclosed conventions in a pinned composition model; it is not Bulla's safety foundation or an execution-failure predictor.
In characterized finite regimes, Bulla can identify a minimum-cost set of fields whose disclosure repairs the modeled deficit. “Exact” names that optimization result. It does not certify the resulting system’s behavior, economics, or legal sufficiency.
What this check cannot tell you
Exact means minimum-cost within the pinned finite repair model; it is not proof of safe execution or a universal real-world cost.
Coverage asks a different question
Verification starts with a receipt and asks whether it recomputes. Coverage starts with a separately supplied action log—the list being checked—and asks which actions left no receipt. The two operations are complementary: perfect verification of the records an issuer chose to show cannot reveal the records it omitted.
Current end-to-end profile
The routed-inference draft applies the architecture to a finite grammar:inference.order → inference.route → inference.accept → inference.delivery → bulla.rely. It supports single_route_single_provider,full term disclosure, retained bindings, no discharge, and a signed-declaration budget ledger. 14 adversarial traces exercise the grammar; the live-provider, settlement-adapter, and independent-implementation counts remain0, 0, and 0.