Skip to content

Witnessing

Retained history and verifiable conflicting commitments.

A receiving party can keep an ActionReceipt after the agent or provider goes offline. The file retains the provider’s transaction record; it does not prove that the reported action occurred.

If the issuer is the only party retaining a copy, the record can still be deleted or withheld. A witness checks the exact receipt, commits it to a separately operated append-only log, and returns proof of inclusion.

plurality instrument · 2026-08-24
1
operated logs
0
receipt witnesses
0
independent logs
published operator kit
operator manifest
ActionReceipt witnesses · 0 · the operated log above is a composition-deed registry, not an ActionReceipt witness; an operated log does not itself establish independent plurality

Limits of this evidence

An operated composition-deed log or project-controlled witness fixture is not independent ActionReceipt witness plurality; W is derived only from active repository qualifications under unique outside control domains.

The independent-witness intake is open at W0. Run the published operator kit and submit a public candidate. A valid package remains NOT_COUNTED until outside control is reviewed and a qualification event merges.

Requirements for a witness record

FunctionWhat it establishes
VerifyThe receipt’s hashes and structure recompute
RetainThe exact receipt exists outside the issuer’s runtime
ProveThe witness returns the leaf, log size, and root
ExposeAuthentic same-size conflicting roots become equivocation evidence

Limits of this evidence

Witness evidence establishes what entered a witnessed history; it does not prove the underlying execution occurred or reveal omitted actions.

Fork discovery and the witness covenant

A verifier can establish an objective fork after receiving two authentic checkpoints from the same operator, log, authority epoch, and tree size with different roots. One view alone cannot establish the conflict.

The repository-source witness covenant covers that non-equivocation duty. Before service begins, the operator accepts the fault predicate, challenge checkpoint, settlement authority, dedicated allocation, destination, and maximum remedy. A verified fork may make the bounded remedy eligible after challenge closes; a separate authority must still authorize the exact consequence.

The fixture-reported bond changes recourse only. It does not improve receipt truth, history integrity, witness independence, custody, collectibility, or the provider’s claims.

Run the witnessed-fork example or inspect its evidence and operating boundary.

Example: retaining a routed-inference receipt

The draft profile carries one full term commitment throughsingle_route_single_provider. Parent references bind the exact observed occurrence and vouched envelope. They do not make an actor-supplied timestamp, execution claim, or remedy endpoint independently true.

bulla.routed-inference/0.1-draft · 14 local adversarial traces · identity verification

01

inference.order

02

inference.route

03

inference.accept

04

inference.delivery

05

bulla.rely

Answerability

covered-on-conforming-local-traces

Bindings remain retained; v0.1 supports no discharge.

Recourse

verified-on-conforming-local-traces

Conveyance is checked; operational reachability is unverified.

Accounting

signed-declarations

Signed declarations only; settlement is unverified.

Reproduction

14/14 traces

0 external implementations; local handoff demo true.

draft · single_route_single_provider · disclosure full · live provider false · settlement adapter false · external implementations 0 · independent ActionReceipt witnesses 0Download evidence bundle →

The ledger can detect a contradiction in signed charges: each hop must reconcile its upstream charge, downstream charge, and retained amount, and the root quote must stay within the order ceiling. That is accounting conformance, not evidence of actual compute consumption or payment.

The offline handoff demo isolates the harness, router, provider, relier, and stranger verifier. It is still local: transport, retention policy, operator discovery, pooling, and a public WitnessBundle format wait for operational evidence.

Limits of this evidence

The routed profile is a local, full-disclosure, single-router/single-provider draft with no live provider, settlement adapter, or independent implementation.

Separate institutional roles

A witness keeps a record in one consistent history and proves it is there. It does not decide whether the record is legitimate—that a claim is true, that a process met its terms, or that a loss should be paid. Those are distinct roles, and holding them apart is what keeps a record layer from becoming the court that rules on its own logs.

Separate roleAnswers a question the witness does not
AdjudicatorWhether a contested claim or procedure holds—heard in a named forum, not by the log
AppraiserWhether process evidence meets the agreed policy—an attester under a declared standard
UnderwriterWhat stake backs the claim, and who pays when it fails—capital, never the record-keeper

Limits of this evidence

A consistently conveyed remedy adapter establishes recourse terms, not that a forum, remedy, or settlement path is operational.

Witness role · planned

Evidence required from an outside operation

ActionReceipt witnesses · 0

The intended service verifies a receipt on intake, commits it to an append-only log, and returns proof. No ActionReceipt witness is currently evidenced. No access is offered and no operators are recruited; the role and the evidence required to claim it are specified below.

Example A · unsigned local receipt

integrity
verified
authority
unauthenticated
inclusion
absent
actor time
unresolved

Example B · team-witnessed receipt

integrity
verified
inclusion
team-operated witness
independence
absent
actor time
unresolved

Example C · independently witnessed

status
not yet available

witness inclusion never resolves actor time or underlying execution; independence is a control-domain property, not an infrastructure property

Criteria for protocol status

01

Service evidence

Run one manual receipt witness against real actions.

02

Operating evidence

Measure retention, privacy, latency, omission, and proof delivery.

03

Interoperability

Prove append, proof, and gossip behavior with a second independent operator.

04

Protocol

Freeze a format only after independent operators have exercised it.

Bulla’s witness-covenant source profile now specifies one objective fault and a constructed Test-ledger remedy path. No independent operator, real custody, collection, or witness market is claimed.

Roadmap — a witnessed record proves what entered witnessed history; it cannot prove the underlying process occurred or what was left undone. A drafted commitment slot opens a record before an act, so coverage becomes an obligation: a slot opened must close, and one still open past its deadline is objective evidence of omission.