{"core-extras.96d330537a":"Base IR","core-extras.bee831a169":"Substrate","core-extras.61a0822826":"Apps on Core","core-extras.15438cc098":"not supported","core-extras.ad565d9d01":"Feature","core-extras.0155bf03e5":"Segment legend","core-extras.8b7110078e":"Algorithm groups by data type","core-extras.25ab4276a6":"Scrollable capability matrix","page-breadcrumb.c766e66518":"Breadcrumb","qa-block.002ff59811":"Question","qa-block.a16a4eda7c":"Answer","trace.8d9d62c12e":"Trace, evidence and replay","trace.a0c42208bc":"Keep the decision","trace.5f41b5caee":"and what shaped it","trace.9e304712a5":"An AI answer is only one part of the story. In observability terms, logs record events; a trace follows one request or case through its spans. Dweve's trace keeps the relevant record of what happened, which material and rules mattered, who had authority, what can be checked, and what still needs human judgement.","trace.3c3ade93ce":"Read the distinction","trace.8b1950fa25":"See your controls","trace.4735dbd09a":"Decisions need","trace.2b11bd3a37":"a durable record","trace.1e63621f2a":"A trace turns an AI-assisted operation into a record that can move between operations, risk, audit and the affected person. It preserves the decision context without pretending that integrity, evidence and accountability are the same claim.","trace.175593a581":"Read the record contract","trace.9c9841f647":"Map responsibility","trace.f253c22344":"Capture the run","trace.a53b0a2bf3":"then test the claim","trace.76e162a659":"Trace is the stack-wide guide to evidence, provenance and replay contracts. It separates event capture, explanation, source lineage, integrity checks and re-execution, then shows where each Dweve system contributes a scoped record rather than one universal proof artefact.","trace.81a88e0a0a":"Logs record events. A trace keeps the source, rule, owner, and replay scope in one bounded record that can be checked later.","trace.679e6213cf":"Start with the model","trace.239569740f":"Compare replay contracts","trace.8b67744434":"Three different records","trace.6d90cc1784":"A log records events","trace.b765f1a75c":"a trace binds the case","trace.b92b2da7c9":"A log helps an operator see that something happened. An explanation helps a person understand a result. A trace carries the relevant inputs, state, versions, actions and evidence as a checkable record. One system may produce all three, but they answer different questions.","trace.a80f164cbc":"The useful distinction","trace.3405b83a8e":"Logs are usually arranged around system events: a request arrived, a tool returned, a job failed. They are valuable for operations, but a pile of timestamps does not by itself identify the decision contract or show which evidence supported the result.","trace.e9d7597ae1":"An explanation is written for understanding. It may summarise why a route was taken or name the sources used. A trace is the underlying record that lets another person check those statements, including the parts the explanation leaves out for clarity.","trace.c5f548a22c":"EVENTS","trace.16818ed44e":"MEANING","trace.31355a2868":"RECORD","trace.7a8f2603ad":"Five questions","trace.e453a9016f":"The record should answer these","trace.7f69b62a34":"reading rule","trace.dc71b11bab":"one claim at a time","trace.b8298c102a":"A trace is useful when its boundary is visible","trace.7661e6591f":"What happened","trace.0aa5b2a221":"The action or result being recorded.","trace.b999bd2a2f":"What shaped it","trace.50cf95502d":"Relevant input, state, policy and version.","trace.d19381d6c5":"What is checkable","trace.7eca7f2c7b":"The exact claim the record supports.","trace.e7ab8f09de":"Log, explanation and trace","trace.7aaa64f717":"three jobs","trace.00f53740a1":"Use the record that answers the question in front of you","trace.236efa252b":"The app records an event","trace.1324d1be70":"A recommendation was returned at 14:32.","trace.3876f29ecc":"The person gets a summary","trace.a0b5c9b3dc":"A plain account says which factors mattered.","trace.dc4db1b626":"The case can be reviewed","trace.3f30af044e":"The relevant state, authority and evidence travel with the result.","trace.e9c086ef63":"The distinction matters most when you open the record itself","trace.d909b69dcb":"Made during the work","trace.48d1b8e5c7":"The record is written","trace.3d3c852226":"as the action happens","trace.4598a45997":"A useful trace is produced as the work runs. It records the material state that was available then, the version that acted, the rule or authority in force and the result that followed. It is not a story reconstructed later from a dashboard and somebody’s memory.","trace.8fa988dbfc":"Why timing matters","trace.27562fe1b5":"Reconstruction tends to keep the visible result and lose the awkward context: a refusal, a changed source, an unanswered approval, an external service response or the exact version that was active. Those details are often the reason a decision is disputed.","trace.3d6159619a":"Runtime capture does not mean recording everything. The record should keep what its declared claim needs and name what remains outside it. That is more useful than an exhaustive surveillance stream whose purpose, owner and retention period are unclear.","trace.9d0ad07bff":"DURING","trace.0a1d8afb8c":"SCOPED","trace.06d55361b1":"VERSIONED","trace.94cb8f4ee1":"At the moment of action","trace.838ec9b434":"What survives the handover","trace.76fe34c90f":"not included","trace.3e1619ec0b":"private hidden reasoning","trace.fd106f4ac2":"Capture the decision context, not a private thought stream","trace.74f39697ac":"Before","trace.3bbbfb4cc8":"Input, policy and authority are identified.","trace.b47565e21d":"During","trace.8ced6b2802":"Actions, checks and refusals are appended.","trace.79ba5e1b3f":"After","trace.d79c811fc0":"Output and verification scope are sealed together.","trace.afbe2aac2a":"handed over","trace.323257fe3f":"A record assembled in sequence","trace.f5783b5add":"during execution","trace.e08945ce96":"The final answer inherits the context recorded beside it","trace.575fc030eb":"A request arrives","trace.3bf28ecb74":"The source set, policy and active version are identified.","trace.1caf9b3177":"The work is recorded","trace.73ad1b88a3":"Routes, checks, refusals and approvals are added as they happen.","trace.abf47960a9":"The record leaves with the result","trace.5b66ae928b":"Evidence references and responsibility stay attached.","trace.9a2b7ea08b":"Once the record exists, the next question is what it proves","trace.ee07619350":"Evidence has a boundary","trace.55d298dbbb":"Integrity is one test","trace.e710d8149d":"evidence is another","trace.b2c31323c7":"A signature can show who issued a record and whether it changed. It cannot make the recorded decision correct. Evidence can support a claim, but it can still be incomplete or contested. A good trace keeps those differences visible instead of collapsing them into a single trust badge.","trace.31d17272d4":"What remains open","trace.cfdbac0adb":"Identity and integrity answer whether this is the record that a named producer issued. They do not establish that a source was accurate, that the policy was fair, that the authority was legitimate or that the final judgement was sound.","trace.9a92f90beb":"Evidence should stay attached with its origin, version and disagreement. That lets a reviewer challenge the claim without first attacking the container. The record can be intact while the decision is still revised, appealed or rejected.","trace.5003bde348":"IDENTITY","trace.c4418db3b9":"EVIDENCE","trace.9c590af566":"LIMIT","trace.2731aeb01a":"Claims kept apart","trace.2bf653281b":"One record, several tests","trace.ab722f4972":"strongest claim","trace.1abc8facef":"must be named","trace.7ec3311155":"A pass should say exactly what passed","trace.7e5a975b6a":"Identity","trace.c7df4949a7":"Names the issuing key or producer.","trace.9c7de2f70e":"Integrity","trace.6946895b1e":"Shows whether recorded bytes changed.","trace.7ea014de7b":"Evidence","trace.1aff0536ae":"Supports a stated proposition.","trace.38b60e8ff2":"Judgement","trace.5ddc2fc6c2":"Remains open to challenge and appeal.","trace.c763b4131a":"The claim boundary","trace.c82f526219":"integrity is not truth","trace.c808804c36":"A sound record makes disagreement easier to locate","trace.4f2bb80c99":"A decision is challenged","trace.9b5a52320e":"The record is identified","trace.7d8cefff77":"The reviewer sees who issued it.","trace.e764532f78":"Its integrity passes","trace.12f6b41cd7":"The retained record has not changed.","trace.5cc307f7b7":"The evidence is disputed","trace.c912036d8e":"One source is incomplete or out of date.","trace.42a5156ec4":"open question","trace.4f4c35ca13":"A human review opens","trace.591a069fd1":"Integrity remains valid while the decision is reconsidered.","trace.afb6b3bc9a":"That boundary belongs in the record you keep and control","trace.e3663fb7a3":"Keep, export and let go","trace.e4151ee132":"Name the record owner","trace.b97a442faa":"and set retention","trace.53d23b863f":"The person or organisation responsible for the work should know where the record lives, who may export it, how long it remains available and what happens when material must be restricted or removed. Portability is a governance choice, not a download button added at the end.","trace.b6b047f090":"Control after the decision","trace.bc66f04e13":"An export should preserve stable identities, versions, evidence references and the verification instructions needed outside the original interface. If a recipient only gets a screenshot or a prose summary, the most important parts of the record have not travelled.","trace.ece9cc4943":"Retention is not the same for every layer. The operational event, the evidence it references and the personal material around it may have different lawful purposes and clocks. Deletion, redaction and restriction should leave an intelligible account of what changed.","trace.501e489055":"OWNER","trace.c0b9641f51":"EXPORT","trace.32d052c31a":"RETENTION","trace.709c37b722":"The custody decision","trace.94129f7fc5":"Three controls after the run","trace.c372b56982":"portable means","trace.c0a231f499":"checkable elsewhere","trace.67e6e05968":"A record without custody rules becomes another data liability","trace.3bd3283228":"Hold","trace.72c24ca1a2":"Name the system and accountable owner.","trace.76cdb95072":"Move","trace.737398ce48":"Export identities, versions and references.","trace.24d948e4bd":"Limit","trace.4373a6ed3b":"Apply purpose, access and retention rules.","trace.64fbd995d3":"Change","trace.e867f9efe2":"Record restriction, redaction or expiry.","trace.b654835ddb":"Custody follows the record","trace.3588c7cdc6":"export and retention","trace.c801f51ff8":"Each transfer carries the same identifiers and declared limits","trace.7edc999949":"A person asks to see the record","trace.ccee919766":"The owner locates the case","trace.89a111a687":"A named workspace holds the primary record.","trace.41006ef1af":"A portable copy is prepared","trace.26de31945c":"Stable identifiers, versions and references stay attached.","trace.12b7433fcb":"Access follows policy","trace.3de97de2a1":"Purpose and review date govern what remains available.","trace.51b1830803":"The handover stays intelligible","trace.8d5c46b7ab":"Any restriction or redaction is visible in the history.","trace.b0f3320872":"Control matters most when two people read the record differently","trace.1348a9b4e1":"Disagreement stays possible","trace.4e577aba04":"A trace enables challenge","trace.5d4820d7d0":"it cannot settle it","trace.5aa8e68e8c":"If you disagree with a decision, the trace should help locate the difference. You may dispute the input, the source, the rule, the authority, the action or the interpretation. The machine can present the record. A responsible person must still hear the challenge and decide what follows.","trace.52bcb57dd8":"The appeal path","trace.6c5462f793":"A useful challenge names the point of disagreement against a stable record: this source was out of date, this approval was missing, this policy version was not applicable or this output does not follow from the evidence shown. A challenge that names none of those is an opinion about the answer.","trace.b17309e965":"The reviewer should be able to preserve the original record, add the challenge and issue a correction or superseding decision. Overwriting the earlier result would make the appeal harder to understand and erase the reason the system changed.","trace.e9166b5b8a":"CHALLENGE","trace.ed6912ad70":"REVIEW","trace.6aea7ebed9":"CORRECT","trace.9d86cd3255":"Where disagreement lands","trace.515bcb9152":"A challenge names its target","trace.2f83fd2406":"machine role","trace.fcf12678d7":"present the record","trace.7e686f5200":"The human role is to decide what the record means for the case","trace.b568d47f2e":"Input","trace.98db7c5bc1":"Wrong, incomplete or not mine.","trace.78e1790e29":"Rule","trace.46c5f38765":"Outdated, inapplicable or unfair.","trace.d3f0610632":"Outcome","trace.ebf131c430":"Unsupported or disproportionate.","trace.5434d5fa43":"One record, two readings","trace.3b32a234b2":"history preserved","trace.ffe51b7c93":"The correction adds a new decision instead of erasing the first","trace.6c3abb464f":"The original decision stays visible","trace.2925c69baa":"Its input, source, policy and result remain pinned.","trace.58a74a7aa4":"version 1","trace.0cffd1d80e":"The person raises a challenge","trace.5d0e0a492c":"They dispute the policy version and source date.","trace.677ff1d623":"The reviewer records the remedy","trace.d9ef1c7229":"A new decision is added without erasing the first.","trace.85de840f8b":"version 2","trace.369bb17e5f":"No single component carries this whole record on its own","trace.45113ca0ff":"Several systems contribute","trace.7d6ab34b3b":"The record has layers","trace.993bb25937":"each makes one promise","trace.ee4a08367e":"Dweve products contribute different parts of the evidence story. Loom can expose a weave trace. Nexus records governed work and authority. Spindle keeps source provenance and disagreement. Mesh can leave an execution receipt. AION checks named certificate families. None of these replaces the others.","trace.7ccb83c5fc":"Why the layers stay separate","trace.eda0cac066":"A source record cannot prove that hardware behaved honestly. An execution receipt cannot prove that a policy was fair. A reasoning certificate cannot reproduce an external producer it did not capture. Keeping the layers separate makes each promise easier to check. Collapsing them into one claim is what makes a record unreadable later.","trace.ff2c98f10c":"The product you use determines which records exist and which replay contract applies. Ask for the record tied to the actual workflow, its export format, its retention rule and the verifier or review process that understands that record. Two products can hold different records for one workflow, so ask which one.","trace.ebc6242725":"WORK","trace.055d363a8e":"EXECUTION","trace.9f7885dd57":"A layered handover","trace.54ba5ef87b":"Different records answer different questions","trace.6f823ff059":"selection rule","trace.e1a647b3c1":"follow the workflow","trace.1ec73bd70e":"No universal artefact is implied","trace.00040bab8a":"Work","trace.9fbe02f2a6":"Objectives, actions, approvals and owners.","trace.485a04fef4":"Nexus","trace.dec1fccaba":"Knowledge","trace.d72e420f64":"Origin, versions, evidence and conflict.","trace.4a86080d67":"Spindle","trace.6d525b7156":"Execution","trace.ad9108d14a":"Workload, nodes, resources and output identity.","trace.873132a799":"Mesh","trace.8146fae346":"Product evidence map","trace.b5e847bca4":"not one proof format","trace.8282f83ca5":"Start with the decision, then follow the records it actually produced","trace.a55b23bd9c":"A question becomes governed work","trace.e1e40788da":"Loom exposes the weave; Nexus records authority and approvals.","trace.91dcbfda11":"Sources stay attached","trace.2002c27a6d":"Spindle keeps origin, version, evidence and disagreement visible.","trace.d6b6bf14a6":"The approved action runs","trace.4f38ea2b83":"Core, Kera or Mesh provide their scoped execution records.","trace.c47840e9b4":"The stated claim can be checked","trace.38beeddee6":"AION or a producer verifier checks only the declared contract.","trace.6164e40498":"That map is the starting point for a serious adoption conversation","trace.e55769b498":"The operating record","trace.74c0e0736a":"The answer leaves","trace.45174c2259":"with its context","trace.fdc942e141":"A trace gives operations, risk and audit a common record of an AI-assisted decision. It keeps the action, relevant state, evidence, authority and outcome together. This reduces the need to rebuild a case from application logs, model-provider exports, tickets and recollection after something goes wrong.","trace.600c72e9d2":"What changes operationally","trace.52f44ed9f5":"Without a shared record, each team assembles a different version of the same event. Operations sees calls and failures, risk sees policy, the business owner sees the outcome and the affected person sees a message. Reconciliation becomes the investigation.","trace.94ca3763e6":"With a trace contract, those views refer to stable identities and versions. Teams may still disagree about the decision, but they disagree over the same recorded material. That shortens handovers and makes missing evidence visible instead of silently filling the gap with assumptions.","trace.2c554fa29b":"ONE CASE","trace.68cd0df09b":"NAMED STATE","trace.b31cf0d2d5":"HANDOVER","trace.67dfebd561":"The shared case file","trace.cbe2e39bd6":"What each function needs","trace.14492980cd":"primary benefit","trace.0b57710548":"less reconstruction","trace.9e42256fb4":"A common identifier joins different professional views","trace.a1fdaa6b2a":"Operations","trace.a8531d2563":"Action, timing, tools and failure state.","trace.5a8f23f567":"Risk","trace.893daa4d15":"Policy, authority, evidence and exception.","trace.89ff31225c":"Owner","trace.a139d8bb6f":"Decision, approval and accountable role.","trace.a74f16c117":"Reviewer","trace.09e010a61f":"Stable export and challenge path.","trace.ae8089ae55":"Three records around one decision","trace.dd66c1d5f3":"log, explanation, trace","trace.7d49a5c51a":"The trace is the reference point, not the only view","trace.afbfa8838e":"Operational log","trace.0a4cc6e3ce":"Service events, timings and failures.","trace.de4d9551e9":"Decision explanation","trace.5d5ca23214":"The account written for a person or reviewer.","trace.9208cf6222":"Trace contract","trace.de148bb70f":"The state, authority and evidence tied to the action.","trace.c63856db79":"A common case file still needs a precise content contract","trace.7fd973e7f2":"The record contract","trace.35674d8b3f":"Identity and evidence","trace.843359f4d2":"stay with the action","trace.298620598c":"A business trace should name the work, producer, versions, authority and evidence relevant to its declared claim. It should also preserve checks, refusals, approvals, outcome identity and known external dependencies. A signature may protect identity and integrity, but the evidence still carries the substantive argument.","trace.d31e094f3c":"The minimum useful content","trace.ba0409ce4a":"Identity answers which piece of work and which actor the record concerns. Versions answer which model, policy, source and executable state were active. Authority answers who or what was permitted to act and whether a person had to approve it.","trace.4ddd3208c7":"Evidence answers why the decision may be defensible. It includes supporting and contradicting material where the workflow produces both. The record must name the exact checkable claim, because a file that merely says verified gives procurement and audit nothing stable to test.","trace.490fb49f60":"AUTHORITY","trace.949f05eea8":"Six fields worth carrying","trace.3ce5a96a64":"A compact business contract","trace.79e7a8d44a":"integrity check","trace.b4d4c5fe38":"scoped by producer","trace.fb6e33b937":"The producer defines the fields its record can defend","trace.09dd0d0490":"Work, action, actor and output.","trace.a239107ef2":"Versions","trace.f703dbdc7f":"Model, policy, source and executable state.","trace.03fb134b89":"Support, contradiction and missing material.","trace.155e60d996":"The portable record","trace.c06a498103":"claim named","trace.5e3b6a4422":"Every field exists to answer a predictable review question","trace.69b0fbc429":"Work identity","trace.5a7e25c638":"Stable identifiers for the case, action, actor and result.","trace.f4f726b7d8":"who and what","trace.cdf0aca2f4":"Version manifest","trace.5e19347686":"The applicable model, policy, source and runtime versions.","trace.6ef240873f":"which state","trace.71e05685a0":"Authority record","trace.4f5c67bef6":"Permissions, approval requirement, approver and refusal.","trace.c5c697650b":"who could act","trace.a3184058c1":"Evidence set","trace.eeba9c2a91":"Supporting, contradicting and unavailable material with origin.","trace.2414636131":"what supports it","trace.8e55ed0608":"Those fields are most reliable when captured during the work","trace.fe8c6ae919":"Runtime capture","trace.2ac9db87a1":"Write during the run","trace.48b9ad598b":"or lose key context","trace.2b518afbf2":"The strongest operational record is generated by the workflow, not assembled after an incident. Runtime capture can preserve refusals, policy gates, external responses, approval state and the exact versions that later reports tend to omit. The scope should remain proportionate to the decision and the stated evidence purpose.","trace.73b81a609e":"Reconstruction risk","trace.07158358ba":"After the fact, teams can usually recover the final response and some service events. They often cannot recover the policy state as it was, an external result that changed, a candidate route that was refused or the condition attached to a human approval.","trace.30dc59c682":"Capturing those elements during execution makes them ordinary data rather than forensic work. It also forces design decisions early: which events matter, which values may be stored, what must be referenced instead, who owns the record and how long each layer remains available.","trace.e80d55f5a7":"CAPTURE","trace.70d8979e21":"REFUSALS","trace.9e8e5a246e":"VERSIONS","trace.1c2daac9b3":"What reconstruction loses","trace.8107f7a4ef":"The missing fields are predictable","trace.80cd3f718c":"design point","trace.5f53e413fa":"inside the workflow","trace.dd958b0a56":"The runtime knows the context while it still exists","trace.d1352b5fba":"Before action","trace.9adb0562b7":"Policy, source set and authority.","trace.5f79a942bf":"At action","trace.ab7a63f80b":"Route, tool, refusal and approval.","trace.65d6a6732f":"At handover","trace.5515732a2a":"Outcome, claim and verification scope.","trace.6c738adb55":"The runtime write path","trace.cf17ed8e16":"not reconstructed","trace.77fb37bf3f":"The record grows with the work and closes with the outcome","trace.61c34ad3c6":"Bind context","trace.2e42432ddb":"Work, inputs, versions, authority and policy.","trace.d412adcdcc":"Append actions","trace.f81046c931":"Routes, tools, checks, refusals and approvals.","trace.ab09944ba2":"Close the claim","trace.8e0e49543f":"Output identity, evidence references and stated limits.","trace.f33def3841":"A runtime record becomes valuable when another party can verify it","trace.99f3c2e038":"Verification and dispute","trace.e1a0bba918":"A verifier tests","trace.b1b1eb84b6":"different claims","trace.ad0dd19f13":"Verification is not one green light. A reviewer may check producer identity, record integrity, evidence origin, policy applicability, authority and replay under a named contract. A failure should identify the field or boundary that differs. That turns disagreement into a tractable investigation rather than a contest of confidence.","trace.beabbe0dbe":"A useful failed check","trace.f1ac219cd6":"If the bytes changed, the integrity check should say where the chain or digest no longer agrees. If a source changed, the evidence comparison should name the dependency. If replay is out of scope, the verifier should not simulate certainty by returning a generic pass.","trace.402a34fbf4":"A business review can then distinguish tampering, version drift, a changed external dependency, an authority problem and a substantive disagreement with the decision. Those lead to different owners and remedies, so flattening them into verified or failed destroys operational value.","trace.c2b45e43d8":"INTEGRITY","trace.57c5f0062f":"DIFF","trace.fe6178db7f":"Four possible findings","trace.ae0df4d6f6":"The remedy follows the failure","trace.da0432ddb4":"good output","trace.6c7bfdf889":"a located difference","trace.db41138e5d":"A mismatch is evidence about the boundary","trace.5b457edca4":"Changed record","trace.3f3afea3de":"Digest or chain no longer matches.","trace.aeb2b702f0":"Changed source","trace.f3b553d098":"An external dependency has moved.","trace.516afe0f1f":"Wrong authority","trace.07d147f923":"The action exceeded its permission.","trace.94763e98b5":"Different result","trace.1a0e402c38":"Replay or interpretation diverged.","trace.fbb609ef14":"Disagreement resolved by field","trace.42e75767b2":"not one verdict","trace.25d42a3e35":"The finding routes to the owner who can act on it","trace.8faab13a35":"Retained record","trace.2f7008d2ee":"Policy v4, source revision 8, approval present.","trace.c433f741df":"Reviewed record","trace.ed7002fce0":"Policy v4, source revision 9, approval present.","trace.57e8becd7a":"Finding","trace.243ba7507f":"Integrity holds. The external source version changed.","trace.01f70a3315":"dependency drift","trace.a70975651d":"A review also needs control over who keeps and exports the record","trace.e08c51b737":"Ownership and retention","trace.53c85e8725":"Ownership is","trace.471863f2a2":"an operating choice","trace.6164a0c040":"Before rollout, decide who owns each record, where it is stored, who can export it and which retention rule applies. The decision trace, its evidence and the access log may have different purposes and lifetimes. Portability should preserve checkability without copying restricted source material into every export.","trace.cd2cc48c28":"Questions for procurement","trace.5319d36c9e":"Ask whether records can be exported in a documented form, which identifiers and verification material travel with them, whether checking depends on the original vendor and how restricted evidence is referenced when it cannot leave its source system.","trace.3c8df41a80":"Ask who sets retention, how expiry and redaction are recorded, which audit trail covers access to the trace itself and how an organisation keeps an earlier decision verifiable after a model, policy or provider changes. These are operating responsibilities, not feature labels.","trace.8d3082255e":"CUSTODY","trace.280208592c":"PORTABLE","trace.64ae0efa4e":"PURPOSE","trace.39ef37e00e":"Four procurement questions","trace.b914504c95":"Control after the contract","trace.899ad7cc92":"exit question","trace.8b725b7da1":"can we still check it","trace.287cb1d763":"The export should outlive the interface that created it","trace.2e6ac4f739":"Custody","trace.25ac9ffc06":"Who holds the primary record.","trace.2f81a22de0":"Access","trace.dd064ecc4e":"Who may inspect and export it.","trace.c7199d9e95":"Retention","trace.ac2bcf31c0":"Purpose, duration and review date.","trace.f83b6fe3ae":"Exit","trace.97e9d99fea":"What remains checkable after change.","trace.934fe6e38f":"The retention and export route","trace.d571907c8a":"separate clocks","trace.cffa83ec53":"The operational record and its evidence can follow different clocks","trace.0150493202":"Active work","trace.a169f30f7c":"Full operational access while the case is open.","trace.a71965486e":"Review period","trace.af0d026d4d":"Decision record retained with controlled evidence access.","trace.05c8117cb5":"Restricted history","trace.5d3e1e8483":"Minimal record and change notices remain where justified.","trace.b03d789333":"Custody cannot answer the separate question of who is responsible","trace.7c6e3b28ec":"Human and machine roles","trace.4c233836fc":"Automation acts","trace.b05a766df0":"under named authority","trace.fcd1f12888":"A trace can show that an agent checked a rule, requested approval, received a response and performed an action. It cannot transfer accountability to the software. The organisation still defines the permitted scope, the human review points, the appeal route and the owner who responds when evidence or outcomes are challenged.","trace.ac96f5b6dc":"The responsibility boundary","trace.ee559215a1":"The machine is responsible for faithfully executing its configured contract and recording the relevant events its producer promises to capture. The record should make refusal, escalation and exceeded authority visible rather than treating only successful actions as work worth keeping.","trace.0b6f6b4951":"People remain responsible for setting the policy, granting authority, reviewing high-impact or ambiguous cases and deciding remedies. A named approver is evidence that approval happened, not evidence that the underlying decision was fair or correct.","trace.0844e3b928":"SCOPE","trace.97efc8640f":"APPROVAL","trace.e1a476f66b":"APPEAL","trace.ad585d191a":"Who carries what","trace.9944006303":"Responsibility is not a checksum","trace.66a4008cf1":"part of the workflow","trace.889f637854":"Authority is evaluated before the action, not inferred later","trace.65bb1b78be":"Machine","trace.77eeb0068a":"Execute, refuse, escalate and record.","trace.d0e687b079":"Operator","trace.cee160c13f":"Set scope, policy and review points.","trace.f18fc1523c":"Approver","trace.6b2fe0af9a":"Accept or reject a bounded action.","trace.b3c0f520fe":"Answer challenge and provide remedy.","trace.8e978fb83f":"The responsibility handoff","trace.c253747cba":"human decision retained","trace.f6921cfeb8":"The record joins machine action to human governance without confusing them","trace.d9690dbf76":"Governed action","trace.452ba76543":"Machine contract","trace.08bed23e05":"Execute within scope, record checks and refuse excess authority.","trace.cff9f500c8":"Human policy","trace.1167cbf7d2":"Define purposes, limits, review points and unacceptable outcomes.","trace.8cc047ac17":"Approval","trace.42fe6111c8":"A named person decides the action when the policy requires it.","trace.d8cb03e330":"Appeal","trace.32a605000f":"A responsible owner hears challenge and issues the remedy.","trace.b7b228228f":"Once roles are clear, the remaining choice is which record layer each system supplies","trace.244b533e18":"The Dweve evidence map","trace.46b71e82b6":"Several systems","trace.7060f34d53":"each supplies one layer","trace.8af55b0fa7":"Trace is a guide across the Dweve stack, not a separate universal proof product. Loom, Nexus, Spindle, Mesh, Core and AION each expose a different contract. Adoption starts by mapping the business decision to the records the chosen workflow actually produces and the limits attached to each one.","trace.7cafb85504":"A practical adoption sequence","trace.f07fa4b1cd":"Start with the decision and the party who must defend it. Name the evidence, authority and replay questions that matter. Then select the product records that answer those questions, rather than requiring every system to emit one large artefact nobody can interpret.","trace.584d07ce77":"During a pilot, test export, verification, disagreement and retention as first-class workflows. A successful demonstration should include a refused action, a changed dependency and a human challenge, because those cases reveal whether the record is operational or merely present.","trace.c2aa3e4760":"MAP","trace.ba7c70b77b":"PILOT","trace.80d7ba4f26":"BOUNDARY","trace.945cfba304":"Pilot acceptance","trace.037d49f87c":"Test the awkward cases","trace.520b824c40":"do not accept","trace.5ffc9b2421":"a generic verified badge","trace.05fdee3bc1":"A useful pilot proves the handover, not only the happy path","trace.6d4685a6dc":"Refusal","trace.c598dc70ab":"An action stops with a named reason.","trace.4375776a4c":"Dependency change","trace.db5d622822":"The difference is located at its boundary.","trace.bb9d653f4e":"Challenge","trace.9f403e2572":"A reviewer can preserve and supersede.","trace.e71a21357e":"Product records by question","trace.ecf47892f9":"scoped contracts","trace.f04eb921dd":"The chosen workflow determines the evidence package","trace.efc82b26d8":"Loom and Core","trace.4dc568cf92":"Cognitive execution and execution-cell replay contracts.","trace.af3b7bf6cc":"model and compute","trace.808c7b06f3":"Work, agents, authority, approval and operational outcome.","trace.6d3bd13aaa":"governed work","trace.604fd3f377":"Source origin, versions, evidence, disagreement and rights state.","trace.6a958445c3":"Mesh and AION","trace.c863cf2e0f":"Execution receipts and checking for named certificate families.","trace.f9cd141a77":"The result is a defensible record with a visible boundary","trace.fb575f44f0":"Three contracts","trace.18fa6820bf":"Logs report events","trace.c96df7dd51":"traces bind the run","trace.9c78ef016d":"A log is an event stream optimised for operation and diagnosis. An explanation is a human-facing interpretation. A trace binds selected events to the input, state, version, authority, evidence and output identities needed for a declared verification or replay claim. The three artefacts may share data without sharing semantics.","trace.3fe6f757cb":"Model before format","trace.a1d4a64435":"Start by defining the claim. An execution trace may support exact replay, seeded replay, restoration, integrity checking or only a field-level comparison. A provenance record may support source lineage and disagreement without containing enough runtime state to execute anything again.","trace.6200c97790":"Only then choose the event schema, canonicalisation, digest, signature, storage and export form. Treating a Merkle tree, HEDL encoding or AION envelope as the universal starting point reverses the design: those are scoped mechanisms where a producer contract actually uses them.","trace.1e9edfb9ee":"SEMANTICS","trace.084904bffc":"CLAIM","trace.55da543ab5":"The five-question schema","trace.2b675b7bbc":"Every producer answers in its own form","trace.5813d2215c":"format rule","trace.1bcb768d63":"follows semantics","trace.202537a82b":"No shared container can replace a shared meaning","trace.ad8919ace0":"Event","trace.c71a0e305d":"What happened and in which order.","trace.a725020675":"State","trace.7fbb3f02b0":"Relevant input, memory, policy and version.","trace.dc4e08a408":"Claim","trace.494df3e6be":"The exact property another party can test.","trace.fef0c4f9a6":"Semantics before container","trace.ff7fdea335":"three artefacts","trace.d51ba74bbd":"Define the question before selecting the verification mechanism","trace.572fd6bf3a":"Event log","trace.215eb3289a":"Append-oriented operational observations.","trace.b32ef340ea":"Explanation","trace.324c497cf8":"A readable account derived for a specific audience.","trace.2f38169a71":"Trace","trace.57a02a84e2":"Bound identities and state for a named check or replay contract.","trace.2364e6135e":"Once the semantics are fixed, capture belongs on the execution path","trace.09bc409053":"Capture during execution","trace.2582183979":"Capture belongs on","trace.72a12e34b7":"the execution path","trace.7fc2ba4a70":"The producer emits trace material as the run proceeds: initial identities and manifest, ordered actions and checks, external boundary calls, refusals and approvals, then output identity and final scope. Post-hoc correlation can enrich a record, but it cannot recover state that was never captured or prove an ordering the producer did not retain.","trace.da1b210e64":"The write contract","trace.2fbc8e433f":"Capture must be atomic enough for its claim. A partial trace should report which stage closed and which did not. Correlation identifiers join distributed events, but they are not a substitute for causal or logical order when replay depends on that order. State the ordering the trace guarantees, so a reader knows what a gap means.","trace.f69f321928":"The producer should also state what it deliberately does not capture. Private chain-of-thought is not a trace requirement. Relevant typed artefacts, routing outcomes, solver results, source references, policy checks and refusals can provide inspectability without exposing an invented transcript of hidden reasoning.","trace.9ae61f13c6":"MANIFEST","trace.025e07020e":"APPEND","trace.dbc8742034":"CLOSE","trace.86d853bfa8":"Write phases","trace.a86d606174":"A trace has a lifecycle","trace.ddde4ecf62":"partial failure","trace.5947e8befd":"stage remains visible","trace.38d89f4cf1":"A truncated record must say where capture stopped","trace.cf9b77061f":"Open","trace.0b85fdc062":"Bind work, producer, input and versions.","trace.6b3a602280":"Append","trace.fdee3c763f":"Record actions, boundaries, checks and refusals.","trace.bbfa773e5a":"Close","trace.7ddb39a696":"Bind outcome, claim and completion state.","trace.64520be916":"Trace write path","trace.bacd7eddd1":"partial state explicit","trace.29efc5378d":"The record closes only when its declared completion condition holds","trace.85d3e9ebea":"Open manifest","trace.99e0eee208":"Producer, run, inputs, versions, policy and authority.","trace.46e24cb72a":"Append ordered work","trace.54ad2e2e7e":"Actions, boundaries, evidence, checks, refusals and approvals.","trace.7785d27f38":"t1 to tn","trace.36e53a9b00":"Close record","trace.868e57fe03":"Outcome identity, final state, verification scope and completeness.","trace.9a82e1d7b2":"The manifest is what makes the captured events interpretable","trace.fc4bc4fc02":"Identity and dependency binding","trace.8ef68ad213":"Pin each dependency","trace.f07ee36b6b":"name each authority","trace.0adfc2551b":"A replayable or verifiable run needs stable identities for the work, inputs, graph or executable, model, policy, source state and output. It also needs the authority context that permitted each consequential action and an evidence set whose origin and version remain attached. Missing fields narrow the claim rather than becoming implied defaults.","trace.7e472a9803":"Authority is runtime state","trace.d1905d3d3e":"Permissions can change between capture and review. The trace should record the authority evaluated at the moment of action, including approval requirements and refusals. A later role lookup cannot establish what the actor was allowed to do then.","trace.a60a8e20f8":"External dependencies need an identity and handling rule. A captured response may be replayed from the record, a live dependency may be re-queried and compared, or the boundary may remain explicitly unreplayable. The manifest should distinguish those cases before execution starts.","trace.39a0d2c825":"Manifest completeness","trace.a2149d693c":"Missing means narrower scope","trace.8c6aa25e6c":"default value","trace.e518fe6829":"none implied","trace.10a44db60e":"A producer cannot verify state it did not identify","trace.a25e0d8752":"Execution identity","trace.162697dd9f":"Graph, executable, model and operation.","trace.2c0d2db323":"Governance identity","trace.71eb444038":"Policy, authority, approval and refusal.","trace.d923f21e66":"Evidence identity","trace.886ee83592":"Source, version, origin and contradiction.","trace.d2936e61be":"The state manifest","trace.a4997b08ad":"absence narrows scope","trace.9efe8a56ed":"The replay contract is a property of this complete manifest","trace.8bccee85f0":"Work and input","trace.a7d2c7c0b6":"Stable work identity, canonical input references and initial state.","trace.3cb2f406d4":"Graph or executable, model, operation ordering and numerical contract.","trace.823619e079":"Governance","trace.fa53633ea6":"Policy, actor authority, approval requirement and refusal state.","trace.6029864d96":"Evidence and boundary","trace.c10c5a90fe":"Sources, external calls, capture mode and known exclusions.","trace.bb787f8486":"A complete manifest does not imply that every run has the same replay mode","trace.7209ab50bb":"Replay taxonomy","trace.f511d3f0a4":"Replay has","trace.2c2a1a6c74":"more than one contract","trace.37d9aa2d44":"Deterministic replay is available only where the producer’s execution contract supports it. Core states determinism per execution cell and foundation: covered non-floating Core Native paths can be pure, native floating families use seeded replay, and supported Core on Kera paths can be pure. Other records may restore state or compare outcomes without reproducing execution.","trace.68c83b7765":"Do not collapse the modes","trace.654c9498dc":"Pure replay fixes the complete represented state and produces the same controlled result under its supported contract. Seeded replay adds an explicit seed but still depends on the named runtime and numerical conditions. Both require compatible versions and captured dependencies. Neither form makes the result true; both make it reproducible.","trace.d793b12d01":"Captured replay substitutes recorded boundary material where the product defines that behaviour. Live replay calls the current external dependency and must report change. Restore rehydrates a saved state. Comparison checks two records. These operations answer different questions and should use different verbs.","trace.38d63311e9":"PURE","trace.7b2513bac6":"SEEDED","trace.8e436c247e":"BOUNDED","trace.a354cc0576":"Replay modes","trace.3d59d50989":"Same word, different guarantees","trace.80dc5b6f5d":"selection basis","trace.30418cfa4d":"producer and path","trace.ce27ff5371":"Replay mode belongs in the trace, not in marketing copy","trace.b075a99f17":"Pure","trace.3ff0f18409":"Complete supported state fixes the controlled result.","trace.5e2d2abc1e":"no seed","trace.51095bb5db":"Seeded","trace.607f5cf5fc":"Seed and named conditions reproduce the path.","trace.1bb360f468":"Bounded","trace.6f27a3d322":"Restore, capture or compare under explicit limits.","trace.4c50134e0e":"Replay contracts by path","trace.a3dd92237a":"Core example","trace.79f077a361":"A path without the required conditions reports its boundary instead of promising replay","trace.21329998a6":"Pure Core Native","trace.270eae034e":"Covered non-floating execution cells under their complete contract.","trace.831cb8935b":"Seeded Core Native","trace.054265f6d5":"Native floating, bfloat, block-scaled and microscaled families.","trace.aa13068bb8":"Pure Core on Kera","trace.cdb19a065b":"Supported floating-family paths with graph-native conditions fixed.","trace.2be9845965":"External dependencies are where an otherwise valid replay most often changes meaning","trace.2b8c9e04c1":"External dependency handling","trace.12dcb1d512":"A changed boundary","trace.53086a69ae":"must stay visible","trace.3ddeeaab38":"A trace cannot make an external source, model endpoint, human decision or physical device deterministic. It can identify the dependency, capture the response where policy permits, record the version or attestation available and state how replay treats the boundary. Changed or unavailable dependencies are results, not noise to hide.","trace.1609139bc4":"Captured and live replay","trace.448a8996af":"Captured replay uses the retained response and verifies its identity against the record. It reproduces the producer’s handling of that response, not the behaviour of the external system that originally created it. The source may still have been wrong.","trace.5f737b59c2":"Live replay asks the current dependency again. If the response, source version or availability differs, the verifier should locate that difference before comparing downstream outputs. Treating the new answer as if it were the old input would turn dependency drift into a false execution failure.","trace.732711debc":"CAPTURED","trace.6990f01ad9":"LIVE","trace.7d72a12dc7":"DIFFERENCE","trace.2a7044cd8e":"Boundary policies","trace.2b007ccd6a":"Declare handling before the call","trace.ca77eb8403":"unavailable case","trace.716e9f54d1":"reported, not guessed","trace.5503239c58":"A boundary can be identified without being controlled","trace.e3d85d3ec8":"Captured","trace.b160e160d4":"Use retained response and verify identity.","trace.bbbfb9f195":"reproduce handling","trace.65c821a596":"Live","trace.6fe045c001":"Call again and compare the new response.","trace.8e4203e923":"detect drift","trace.ec5531c3e8":"Referenced","trace.a1066075fa":"Keep identity while content stays at source.","trace.ea0a4e3d56":"verify access","trace.2c9c1f7914":"Unavailable","trace.6b106b9a03":"Stop or narrow the replay claim.","trace.e2b8e7dcfd":"explicit limit","trace.6def1d2df1":"One boundary, three outcomes","trace.a87911be1e":"external state","trace.0c00851ce9":"The downstream comparison starts only after the boundary result is known","trace.6ea72ed79a":"External call","trace.3c51bf911e":"Captured response","trace.e89f666507":"Retained bytes match the recorded identity.","trace.56f523b7fe":"replay locally","trace.1b6c05d53b":"Live response","trace.9ec037bf46":"Current result differs from the retained version.","trace.44abf71024":"report drift","trace.869ef6a13c":"Reference only","trace.452c2a65e0":"Identity remains, content stays under source control.","trace.9ddfc02279":"check access","trace.88b83f05a7":"The trace narrows or stops the replay contract.","trace.7c82afbd11":"no substitution","trace.83555e308d":"Once boundaries are located, verification can return precise findings","trace.f9693ec835":"Verification and difference","trace.d1ba35d03b":"Verification can fail","trace.81628099d1":"in useful ways","trace.a978ceccea":"A verifier should evaluate the claims its record type defines: schema and completeness, producer identity, integrity, version compatibility, evidence references, authority and replay or comparison where supported. It should return structured differences rather than one boolean whenever the record contains enough information to locate them.","trace.a6bf791c3f":"Failure semantics","trace.371dfa6096":"Integrity failure means the retained content no longer matches its expected digest, chain or signature contract. Compatibility failure means the verifier cannot interpret the producer version or required feature. Evidence failure means a reference is missing, changed or outside the declared policy.","trace.f56576c267":"Replay difference means the run completed under its stated conditions but a field or output diverged. Authority failure means an actor was not permitted to perform the recorded action. A substantive reviewer may still reject a fully intact, compatible and reproducible decision on its merits.","trace.ccaa4ad4b0":"SCHEMA","trace.e53c801a9c":"FINDING","trace.c4f5da0289":"Verifier outputs","trace.1b7a01b403":"Each class routes differently","trace.ff5a900adc":"boolean pass","trace.b4ec55fd25":"insufficient for diff","trace.13c3f5c886":"The output should preserve expected and observed values","trace.eff173c931":"Interpret","trace.550ecdf4cc":"Schema, version and feature compatibility.","trace.652ea0a6cd":"can read","trace.d71095c651":"Recompute","trace.4f1a2f678a":"Digests, chains, signatures and references.","trace.08d8a6932a":"same record","trace.8d105cf44d":"Compare","trace.789bb101c0":"Replay outputs, boundary responses and authority.","trace.d335b19faf":"field diff","trace.a39671da03":"Structured verification result","trace.a310472121":"expected and observed","trace.1c6b0276e5":"The mismatch becomes a first-class record for review","trace.6ac87f3446":"Expected","trace.204885a641":"Source revision 8, policy v4, output digest ending 7a2f.","trace.2e159b4438":"Observed","trace.d3b97990ec":"Source revision 9, policy v4, output digest ending 91bc.","trace.9d21d860c7":"Producer and policy match. Source and downstream output differ.","trace.c307af644d":"boundary change","trace.0c49f9ad17":"A precise machine finding still needs a responsible human response","trace.000035325b":"Authority and responsibility","trace.f211c64642":"Machines carry actions","trace.b288850ab1":"people own decisions","trace.0be283d871":"The trace should record authority evaluation before consequential actions, including requested scope, policy result, approval requirement, approver response, refusal and escalation. That makes the machine’s contract inspectable. It does not make the machine the accountable owner of the policy, the deployment or the remedy.","trace.dcd0d3c900":"Responsibility in the data model","trace.d3026a9856":"Represent proposed actions separately from committed actions. Preserve the actor, target, arguments, authority decision, expiry and any required human confirmation. A refusal is an outcome and should remain queryable rather than disappearing because no external side effect occurred.","trace.3793901bdf":"Represent human decisions as their own signed or authenticated events where the producer contract supports it, with conditions and reasons. Do not treat a human click as a proof of correctness. It establishes that a named approval step happened under the recorded identity context.","trace.50a6c8a789":"PROPOSE","trace.9ac924360f":"AUTHORISE","trace.17e4d77388":"COMMIT","trace.768f611411":"Action state machine","trace.55494c3e4e":"Authority precedes side effects","trace.778558bd1b":"refusal state","trace.e9f00b0e96":"retained as outcome","trace.9126210de5":"The committed action points back to the authority decision","trace.70cbd1d6b1":"Proposed","trace.5ba2d2b210":"Actor, target, arguments and expiry.","trace.9ae844e7e6":"Authorised","trace.6a719d20d2":"Policy and required approval evaluated.","trace.c03939d551":"Committed or refused","trace.1cefb998ce":"Side effect or stop recorded explicitly.","trace.c6e068c08f":"The authority boundary","trace.60fcce4949":"action and approval distinct","trace.abf3a259b9":"A complete trace shows both the automated path and the accountable role","trace.9d00b2a45c":"Consequential action","trace.5ce2e6f402":"Agent","trace.1455f53096":"Proposes and executes only inside the granted contract.","trace.4030a57544":"Policy owner","trace.7f8fae0ad9":"Defines scope, prohibited actions and review thresholds.","trace.a6a5fd7eff":"Accepts, conditions or rejects the bounded proposal.","trace.09cd0d85de":"Accountable owner","trace.fb08a72e3b":"Responds to incidents, challenge and remedy.","trace.3aef4388fa":"Responsibility persists for as long as the organisation retains the record","trace.04dcda234f":"Lifecycle and portability","trace.b1177dc488":"Retention changes","trace.fc24bc85a4":"what remains verifiable","trace.93b3f5490e":"Export and retention are part of the trace contract. An export needs stable identifiers, producer and schema versions, integrity material, evidence references and the declared verification instructions. Retention policies may preserve the decision record while restricting or redacting referenced content. The resulting change must remain intelligible to later verification.","trace.607c28fc04":"Compatibility over time","trace.1fc5956099":"A verifier should state which schema versions and feature families it understands. Unknown fields may be retained for forward compatibility, but required unknown semantics should fail explicitly. Silent coercion can produce a technically readable record whose claim has changed.","trace.586414de30":"Redaction should distinguish removal of personal or restricted content from tampering. A retained placeholder, digest, source identity or change event can preserve the shape of history without keeping content beyond its justified purpose. The exact method remains producer-specific.","trace.b33892fbdd":"VERSION","trace.0f03e66273":"REDACTION","trace.506d7480b9":"Long-lived checks","trace.a41252905c":"What an export needs","trace.9385b36f1d":"compatibility rule","trace.f85449a4b2":"fail on required unknowns","trace.497ae28443":"Keep the claim interpretable after the original UI is gone","trace.b5230ecdf4":"Schema","trace.e32ace9996":"Producer version and required features.","trace.8286c0ce7a":"Digests, chain or signature as defined.","trace.5d20d0fee3":"References","trace.b89f8f1605":"Evidence identities and access conditions.","trace.033df3d297":"Lifecycle","trace.99ce7d15bb":"Restriction, redaction, expiry and supersession.","trace.d3d014697e":"Trace lifecycle after execution","trace.db2a697e1b":"separate retention clocks","trace.3eda52ea14":"Verification reports lifecycle changes instead of treating them as unexplained corruption","trace.8459f93535":"Operational","trace.d2b0015e97":"Full record available to the active workflow.","trace.d591ef7fb2":"Exported","trace.02d9bc4b53":"Portable package with version and verification instructions.","trace.aa2a08d2af":"Restricted","trace.886910134c":"Sensitive content removed or access limited with a change event.","trace.8b462d9208":"Superseded","trace.1e7d8b4971":"Earlier decision remains identifiable beside its replacement.","trace.c2ccce388c":"The final architecture question is which record layer owns each claim","trace.aec83d1842":"Stack evidence map","trace.0a1ae7471b":"Record layers","trace.5f71b30c32":"stay distinct","trace.6ed86cbbcc":"Dweve does not emit one universal Trace artefact. Loom exposes an observable weave trace. Nexus records governed work and authority. Spindle maintains provenance, evidence and conflict. Mesh can leave layered execution receipts. Core publishes path-specific determinism. AION verifies named certificate families. FMI distinguishes restore from replay.","trace.5d702b1419":"Composition without conflation","trace.5b699a9a7f":"A workflow may link several records through stable work, artefact and output identities. That creates an evidence package without forcing each producer into one schema. The package should retain the contract and verifier for every layer, plus the relationships among them. Without those relationships the package is a folder, not a trail.","trace.dcef65b322":"When a claim crosses layers, state the join explicitly. A Mesh software signature does not establish hardware honesty or mathematical correctness. A Spindle signature establishes identity, integrity and process, not truth. An AION checker validates the certificate family it understands, not every producer upstream.","trace.20f9a99b35":"LAYER","trace.9a3f6528f2":"JOIN","trace.4e7175c5ab":"Record families","trace.c830488287":"Each layer keeps its own verifier","trace.4f5122a922":"join key","trace.cf1fd00d1a":"stable identity","trace.535af2a832":"Composition links contracts without widening their claims","trace.c9fccc194b":"Decision and work","trace.03788135ec":"Loom and Nexus execution context.","trace.daeb3fb03e":"Spindle source, evidence and conflict state.","trace.8d0f0ad292":"Compute and proof","trace.86db43f176":"Core, Kera, Mesh and AION scoped records.","trace.14d11f8463":"Dweve record layer map","trace.30adb3cea0":"linked by identity","trace.a28cc1e7aa":"Trace is the guide that tells a reviewer which promise belongs to which record","trace.3a30cfe830":"Cognitive execution","trace.7b0ecd5f1e":"Loom weave trace and Nexus governed operational record.","trace.d45d5631b9":"what acted","trace.5c76d8725a":"Knowledge provenance","trace.1c9aca6a6a":"Spindle origin, versions, evidence, conflict, rights and policy state.","trace.a4b9c143a6":"what supported it","trace.1e831420fd":"Execution contract","trace.7a31730129":"Core and Kera path identity, numerical contract and replay mode.","trace.3ec9192862":"how it ran","trace.01e824e611":"Infrastructure and checking","trace.ed01b65931":"Mesh receipts and AION checks for named certificate families.","trace.988010d232":"what was verified","trace.4be31eba13":"A reviewer can now ask the right question of the right record","trace.46afafe84b":"The honest boundary","trace.72773ad3ac":"An intact record","trace.d504892847":"can carry a bad claim","trace.0f1fc8e2c9":"Integrity shows that the record is the one a producer issued and that its retained content has not changed under the stated mechanism.","trace.09938ad4cb":"Evidence, authority and human review remain separate questions. Keeping them separate is what makes a challenge useful.","trace.75d4e75b5f":"Four readings","trace.f9877a246e":"separate claims","trace.f17fa975ac":"Producer identity","trace.de027811bd":"Who issued the record.","trace.347635e302":"Record integrity","trace.c1c02d274e":"Whether retained content changed.","trace.b356b316c3":"Evidence quality","trace.8b7283fe01":"Whether the claim is supported.","trace.30e964acf7":"Decision quality","trace.0bf7d8d33a":"Whether the outcome should stand.","trace.2dc584e790":"Strongest safe statement","trace.81ea16c078":"The record is intact, not infallible","trace.14e3d41534":"Trace, consumer guide","trace.65bb62594a":"What you should receive","trace.29eb6444e7":"The record travels","trace.77eeddaf90":"responsibility stays","trace.cc4019124a":"A portable record helps you see what shaped a decision and gives a reviewer a stable place to start.","trace.2565550242":"The organisation that used the system still owns the decision, the appeal and the remedy.","trace.e0637fe4a2":"Decision handover","trace.f4cacee0f2":"Decision identity","trace.16a06284d9":"The case and outcome.","trace.343428d88f":"Evidence references","trace.28162b0428":"Support and disagreement.","trace.ef62340ea5":"Who could act and approve.","trace.0cd8220aa5":"Appeal owner","trace.59ed7c554e":"Who must answer a challenge.","trace.e636665c5f":"Handover complete","trace.c2502eef60":"Checkable record, accountable owner","trace.4a6e7f5a4d":"The investigation clock","trace.275fdb1354":"Reconstruction starts","trace.3dec69901d":"where evidence stopped","trace.09596029b3":"A post-incident team can recover the visible response and scattered service events. It cannot recover a policy state, refusal or external result that was never retained.","trace.22b9daa238":"Runtime capture turns those missing pieces into ordinary, governed record fields.","trace.c88f282190":"The first review hour","trace.ab5a50a9dd":"without runtime capture","trace.62a19dce32":"Find the response","trace.162584f778":"The outcome is usually available.","trace.c018adce42":"Find the policy","trace.c55906ef15":"The current version is not the executed version.","trace.a2988c355a":"Find the approval","trace.f209e26791":"A ticket says yes without its condition.","trace.6b16ab012c":"Find the refusal","trace.e462fb12e1":"The unused route was never logged.","trace.13e8e0fdc8":"Review state","trace.0c801d6c74":"Outcome found, decision context incomplete","trace.bfb869a8db":"Trace, business guide","trace.80e7ca034d":"Accountability","trace.532035d16e":"The machine records","trace.eb0c5aa32c":"the operator decides","trace.5826c5e830":"An automated workflow can preserve its checks, refusals and approval events with far more precision than a manual account.","trace.a44c493536":"That precision supports governance. It does not transfer the duty to set policy, review harm or provide a remedy.","trace.09808cdadc":"Responsibility split","trace.4509550e29":"named roles","trace.05a9ed3ec2":"Human duty","trace.9befbffa61":"Execute within scope","trace.a6ecb35598":"Record actions and refusals.","trace.8e62a039aa":"Escalate uncertainty","trace.80eff6f4d7":"Stop when authority is insufficient.","trace.48a1eee4b0":"Set the policy","trace.d26529ec3b":"Choose purpose, limits and review points.","trace.923301ea79":"Answer the challenge","trace.996c598490":"Decide correction and remedy.","trace.e6515a1b97":"Operating principle","trace.5ef5e7d409":"More evidence, same accountability","trace.778184da86":"Completeness","trace.f4777e5b4e":"A missing dependency","trace.f526ba6f9b":"narrows the contract","trace.9fe85603e6":"A trace may be perfectly intact and still lack the state required for replay or the evidence required for a substantive review.","trace.02c4259405":"Completeness is evaluated against the producer’s declared claim, never against an imaginary universal schema.","trace.62378fcfdc":"Manifest gate","trace.21657fd896":"claim scoped","trace.5bf76c5045":"Graph, executable and operation path.","trace.084db6e7d5":"Policy and authority","trace.d0be03d754":"State evaluated at action time.","trace.b5ac76ad11":"External response","trace.1965e7b389":"Identity present, bytes not captured.","trace.df173f1491":"Replay claim","trace.92f82f3f80":"Narrowed to live comparison.","trace.9769842e44":"Safe contract","trace.402215b0d6":"Live comparison, not pure replay","trace.44380a5bb2":"Trace, technical guide","trace.940d8bc320":"A mismatch is a result","trace.b89d59e47d":"Verification shows","trace.db008952a2":"what changed","trace.b7c302a8cd":"A useful verifier preserves expected and observed values, the contract used and the first boundary at which they diverged.","trace.1f2cc59a3e":"That evidence distinguishes corruption, incompatibility, dependency drift, authority failure and a genuinely different execution result.","trace.0c8557c63d":"Field comparison","trace.44d8ff61ad":"difference retained","trace.d7d287493f":"Policy v4","trace.887844a7ba":"Authority approved.","trace.23e85af43f":"Source revision 8","trace.360368a815":"Captured reference.","trace.7ea8a60c7d":"Source revision 9","trace.b694baced1":"Live dependency moved.","trace.a02d350d96":"Integrity holds, external source changed","trace.3af5c18d3b":"Review route","trace.af97a653b8":"Ask the right question","trace.2ed79740cf":"of the right record","trace.cc9b83beac":"The product map is intentionally layered. Each producer exposes the contract, identifiers and checks that belong to its part of the work.","trace.a8d55a8ffc":"Link the records through stable identities, then preserve every layer’s limit.","trace.bf6dba27a9":"Evidence route","trace.3de96e8700":"Loom and Nexus.","trace.d69521be0a":"Spindle.","trace.6efa586f63":"Core, Kera and Mesh.","trace.97876b8380":"Checking","trace.aeb4d8ea0c":"AION and producer verifiers.","trace.103f20e21a":"Review principle","trace.48b6a0c9b3":"Contracts compose, claims do not expand","trace.ed781993dc":"scope first","trace.5006ed0248":"event","trace.ec2727b3b7":"context","trace.013872e31d":"claim","trace.513fd31089":"separated","trace.7babc233de":"log","trace.73b8427ebc":"explanation","trace.d0fa554885":"trace","trace.6637105cad":"runtime written","trace.4d46077c78":"bound","trace.8204fbd54f":"recorded","trace.d19695c5fe":"captured","trace.51de2b835b":"before","trace.ffed391ca2":"during","trace.405906c9d5":"after","trace.3a5592bbc8":"no trust badge","trace.b7adf77905":"who","trace.ff33905573":"same","trace.10cff4034c":"why","trace.d787f56b08":"human","trace.a45c2264b8":"explicit","trace.1db089a9f8":"identity","trace.eab9dd6e95":"intact","trace.dfcb43ff4e":"outcome","trace.729fe226c8":"owner governed","trace.bb610c5e8a":"custody","trace.bc109fb076":"portable","trace.c072e8329e":"bounded","trace.2238839604":"visible","trace.c6dda4f283":"owned","trace.5171340993":"export","trace.7eb6050d05":"retain","trace.a3391cfe78":"review required","trace.86d9312fdc":"contest","trace.61e62b213a":"review","trace.201bd9db24":"remedy","trace.729e6ed847":"disputed","trace.5fc7e38bff":"open","trace.e4e5f91807":"layered","trace.e274eeff76":"work","trace.cce245fbd9":"knowledge","trace.1e21474598":"execution","trace.7fa0103eec":"one reference","trace.df6ad19037":"run","trace.2aeede80be":"control","trace.d1f30ba13f":"duty","trace.d56d985300":"check","trace.3bea4606b8":"aligned","trace.ddb3ef2a32":"operate","trace.8e73840bbf":"understand","trace.864a0aafb6":"claim bound","trace.ed04ff4dab":"which","trace.30603fa9e0":"when","trace.b67aa1adf5":"complete for scope","trace.8b7e351118":"capture early","trace.d145a2a905":"pin","trace.db43bff34c":"append","trace.401244715d":"in sequence","trace.2b020927d3":"start","trace.7d50f37dd6":"handover","trace.1d277bd60f":"field level","trace.b9b4d1f138":"integrity","trace.100ec4462d":"evidence","trace.56b8e6bb95":"governance","trace.af938869ec":"difference located","trace.02ab610f42":"reference","trace.4d04521b65":"comparison","trace.0c58cf1d1f":"owner named","trace.579233b2c4":"owner","trace.037c883f00":"roles","trace.83655a5560":"clock","trace.9fc237f08b":"policy bound","trace.04489a12bb":"use","trace.e4d68c5a97":"limit","trace.5b78884598":"roles named","trace.24aaa8e99e":"escalation","trace.d61ceadbdb":"contract","trace.a4880e8741":"govern","trace.d14809f05a":"decide","trace.ca20728d35":"account","trace.03fb8742ca":"authority checked","trace.f4746222ad":"governed","trace.cb4c0a136a":"answerable","trace.51efacdcd7":"decision led","trace.58317b6a81":"diagnosed","trace.20b9ca04a2":"mapped","trace.35f8b7463f":"infrastructure","trace.f7016622e8":"claim first","trace.bf78d7a8e0":"behaviour","trace.e977c53830":"contracts separated","trace.77e720c8ee":"diagnose","trace.14889e1212":"interpret","trace.86a4261d84":"verify","trace.2f6d3eca5a":"ordered","trace.c5beef2de7":"manifest","trace.82d50d9042":"events","trace.14e60ace3d":"receipt","trace.4d55ab79c5":"runtime emitted","trace.f503ccbc3d":"t0","trace.b295c12c5c":"tn","trace.7eefafb04c":"explicit fields","trace.6bdd4db977":"bind","trace.f7064cd754":"cite","trace.9263812436":"dependencies named","trace.c692273deb":"version","trace.6d244f5836":"permission","trace.aacd3103f3":"scope","trace.1150ab0314":"contract selected","trace.92713d4709":"seed","trace.6543f14e1a":"scoped","trace.afe003f117":"pure","trace.9ad3dc4c49":"seeded","trace.bcb6e271db":"difference visible","trace.60e38ceb30":"handled explicitly","trace.7a24571bdc":"structured findings","trace.341d953e69":"replay","trace.3e4edeca51":"fail closed","trace.e22586930a":"pending","trace.6f7a02ca61":"responsibility retained","trace.7817c52b25":"machine","trace.8501a34f34":"decision","trace.9d30010e5c":"recompute","trace.4e7a20843e":"resolve","trace.f7c1380a0d":"explain","trace.8f49abf441":"history intelligible","trace.405ab5d2b9":"current","trace.7601834e54":"independent","trace.66f79d8a63":"history","trace.2b0d468fda":"composable","trace.2b20ac5608":"provenance","trace.7298df3923":"contracts preserved","trace.b3428b3cf0":"checkable","trace.20988a5ccb":"attached","trace.b627147007":"named","trace.2739bb260c":"found","trace.6f1fa906d7":"uncertain","trace.355705cf62":"partial","trace.5a013c4950":"missing","trace.50644481c7":"present","trace.35fa91ce25":"referenced","trace.5dcbdf371f":"expected","trace.37c6c57bed":"changed","trace.34eb4c4ef0":"action","trace.f2e18ffc17":"runtime","trace.next.eyebrow":"Continue with the contract","trace.next.title":"Follow the record across the stack","trace.next.stack.category":"Architecture","trace.next.stack.title":"Map the ownership","trace.next.stack.description":"See where products, open foundations, and research keep separate responsibilities and handoffs.","trace.next.openSource.category":"Open source","trace.next.openSource.title":"Inspect the foundations","trace.next.openSource.description":"Open the repositories that implement narrower mechanisms with their own licences and boundaries.","trace.next.research.category":"Research","trace.next.research.title":"Read the evidence status","trace.next.research.description":"Follow active questions, working papers, and investigations without turning a draft into a release.","trace.next.trust.category":"Trust centre","trace.next.trust.title":"Review the controls","trace.next.trust.description":"Check security, data, and model records alongside the trace and replay contract.","trace.8417cc73e7":"The record you can check","trace.05f6a0c57f":"A record you cannot check","trace.23cb69163f":"is only a claim","trace.b750f417c1":"Trace is the contract that keeps identity, authority and evidence attached to an action while it runs. The controls beside it and the foundations underneath it stay open to the same reading.","trace.f51e9b562a":"Open the trust centre","trace.21529d4c55":"Open the foundations","trace.f6369b4104":"What the record carries","trace.be237de2af":"TRACE CONTRACT","trace.8ea6344a46":"The record names who acted and under what authority.","trace.772a4bcb65":"Capture","trace.1470c543f8":"The trace is written during the run, not reconstructed after it.","trace.03128bed90":"Verification","trace.b0bf38aba8":"A verifier tests identity, integrity and difference, not truth.","trace.35ed7a79e5":"Read the record before you rely on the result","trc-accountability-scenarios.0bbbef9c9b":"Trace, Consumer","trc-accountability-scenarios.9520c0279e":"The proof does not depend on trusting Dweve. It depends on math anyone can check.","trc-accountability-scenarios.f0f633a9b7":"Imagine you ask an AI for advice and it gives you something misleading. With most systems\n          you have a screenshot and an argument. With Dweve you have a signed receipt anyone can\n          replay to see exactly what the AI produced and why.","trc-accountability-scenarios.a1e6a8447c":"If something goes wrong, you can prove it.","trc-accountability-scenarios.80e7ca034d":"Accountability","trc-accountability-scenarios.d693c70230":"The trace shows whether the model changed, the documents changed, or the rules changed. You find the cause instead of guessing.","trc-accountability-scenarios.639aa765ad":"With a trace","trc-accountability-scenarios.659f43f54a":"You ask the same question twice, get different answers, and have no idea why.","trc-accountability-scenarios.2954939311":"Without a trace","trc-accountability-scenarios.f837cf6b56":"A changed answer","trc-accountability-scenarios.0ec993a4a2":"Scenario 03","trc-accountability-scenarios.74b0caf03c":"The trace shows whether the safety rule fired or whether it was accidentally bypassed. The AI should have warned you, and now you can prove if it did not.","trc-accountability-scenarios.062acbae7a":"Nobody can tell whether the safety warning was skipped or never existed.","trc-accountability-scenarios.3eda3323eb":"A missing disclaimer","trc-accountability-scenarios.c0b9ff1a7a":"Scenario 02","trc-accountability-scenarios.b8c5752048":"You replay the exact moment and show what the AI actually said, not what someone claims it said. The receipt is signed and tamper-proof.","trc-accountability-scenarios.a76be7b514":"You have a screenshot and an argument. It is your word against the system.","trc-accountability-scenarios.f2aacc4400":"A bad recommendation","trc-accountability-scenarios.2c11ab0c07":"Scenario 01","trc-compliance-map.d75a4de2ef":"EU AI Act","trc-compliance-map.a047749950":"Annex IV","trc-compliance-map.f4487cd822":"High-risk AI systems must maintain logs and technical documentation.","trc-compliance-map.0fe0ed430c":"The trace satisfies reproducibility and record-keeping requirements with a single artefact containing inputs, outputs, policy checks, and a digital signature.","trc-compliance-map.bbcf64a3a2":"Inputs","trc-compliance-map.7835db447b":"Outputs","trc-compliance-map.777c7ac75c":"Policy checks","trc-compliance-map.2f32be1dc7":"Signature","trc-compliance-map.8788b8a933":"DORA","trc-compliance-map.f94be30d35":"ICT risk","trc-compliance-map.898ad46976":"Evidence of third-party ICT risk management for financial entities.","trc-compliance-map.d5487b951d":"The trace proves what a decision-support system did during an incident, who authorised it, and whether the policy gates were respected.","trc-compliance-map.b54e687e46":"Incident record","trc-compliance-map.97a9869cf8":"Authority","trc-compliance-map.fb18e63063":"Policy gates","trc-compliance-map.2812ca576b":"GxP / MDR","trc-compliance-map.42c3a024b3":"Medical device","trc-compliance-map.e34ccbf9c2":"Reproducible decision records for device submissions and quality systems.","trc-compliance-map.9349e5e47b":"The trace attaches directly to device documentation as a replayable record of exactly what the model produced for every validation input.","trc-compliance-map.96ea8a86a6":"Validation inputs","trc-compliance-map.4f6a36b4a7":"Replayable record","trc-compliance-map.ab017d8c70":"Device docs","trc-compliance-map.0b587346be":"What it requires","trc-compliance-map.5be22c65ea":"What the trace provides","trc-compliance-map.fe794c06be":"Regulators want evidence, not promises. The trace is signed, timestamped, and replayable\n          years later without access to your production environment.","trc-compliance-map.19bc45c40b":"Trace, Business","trc-cross-backend.836722b952":"Trace, Technical","trc-cross-backend.c7083cd8c3":"The WASM verifier runs in-browser and produces the same VERIFIED output as the native CLI.","trc-cross-backend.e362275e94":"The CLI keeps a content-addressed cache of verified traces. Re-verifying a trace\n                already in the cache returns instantly. Cache hits are validated by root-hash lookup,\n                and the cache is integrity-checked on startup.","trc-cross-backend.ba54c0c153":"Replay cache","trc-cross-backend.004b0cb3f5":". The verifier dispatches to the right backend\n            implementation for each operation, and hard-determinism mode keeps the arithmetic exact\n            regardless of target.","trc-cross-backend.40687ce67e":"The same trace replays on","trc-cross-backend.048800325b":"One trace","trc-cross-backend.b62ab05b70":"one trace, every backend","trc-cross-backend.1b644b3fd2":"aion verify --target","trc-cross-backend.1ee31f9d8d":"Same VERIFIED output","trc-cross-backend.57788e654e":"In-browser","trc-cross-backend.4e946026a7":"WASM","trc-cross-backend.c88551b9e4":"Same root hash","trc-cross-backend.15ca7b6e01":"Sovereign silicon","trc-cross-backend.89493ecb60":"Edge, mobile, server","trc-cross-backend.29d8dec43e":"ARM","trc-cross-backend.bd42d31987":"Native CLI verifier","trc-cross-backend.341bbb7c95":"Server, desktop","trc-determinism-dial.20a89915f1":"Hard","trc-determinism-dial.b49304d968":"Bit-identical everywhere","trc-determinism-dial.ad868efa8a":"Every operation is reproduced byte for byte across x86, ARM, and RISC-V. Floating-point work is routed through Numerus exact arithmetic so there is no platform-dependent rounding. This is the default for regulatory submissions and contractual proofs.","trc-determinism-dial.298425b24e":"Regulated workloads","trc-determinism-dial.51095bb5db":"Seeded","trc-determinism-dial.5d04cf32bf":"Reproducible from a seed","trc-determinism-dial.2bc7e4e8f6":"Any randomness is drawn from a recorded seed, so the same trace replayed with the same seed reproduces the same result. Useful where a controlled amount of sampling variation is wanted but the run must still be exactly reconstructable.","trc-determinism-dial.ff802eed58":"Reproducible sampling","trc-determinism-dial.20ccbc66c1":"Creative","trc-determinism-dial.e774d67bc1":"Best-effort record","trc-determinism-dial.c3ccaf0577":"The trace still records inputs, operations, and policy decisions, but does not pin every sampling choice to a fixed result. Useful for development and exploratory work where the audit record matters more than exact reproduction.","trc-determinism-dial.c2866ff77a":"Development, exploration","trc-determinism-dial.11aaf6f297":"three documented modes","trc-determinism-dial.f78543277d":"Determinism strength","trc-determinism-dial.057ed53c33":"Replay re-executes the same operation graph on the same inputs. The mode controls how\n          strictly results must match. The default for regulated work is Hard.","trc-determinism-dial.836722b952":"Trace, Technical","trc-format-bridge.2d7145b1c1":"AION native","trc-format-bridge.8cb4e19789":"Default format","trc-format-bridge.b834f582b3":"A HEDL-encoded proof artefact with canonical field order, an Ed25519 signature over the root, and optional zstd compression. This is the format most users stay on. The verifier reads it directly with no transform step.","trc-format-bridge.72e8e24f69":"Alethe","trc-format-bridge.27f05dd053":"SMT interop","trc-format-bridge.270ef5fdc4":"A standard proof format used by SMT solvers. AION emits a lossless transform to Alethe proof terms, which is useful when you need to feed the proof into SMT-LIB workflows or academic toolchains that already speak Alethe.","trc-format-bridge.479769609f":"LRAT","trc-format-bridge.d075b5d173":"SAT interop","trc-format-bridge.d46bb1fd0f":"A clause-based format consumed by certified SAT checkers. AION converts to LRAT when the proof contains boolean-satisfiability sub-problems, such as constraint-solving steps in policy evaluation. The same verification guarantee holds across the transform.","trc-format-bridge.ec6b743c8f":"aion convert","trc-format-bridge.4478046b97":"lossless, both directions","trc-format-bridge.e6c67de15e":"Proof formats","trc-format-bridge.111e993962":"One proof, three formats. The native format is the default; Alethe and LRAT exist for\n          interop with proof tooling your reviewer already trusts.","trc-format-bridge.836722b952":"Trace, Technical","trc-hero-glyph.df948ac041":"RECORD","trc-hero-glyph.64b080ec54":"RUN","trc-hero-glyph.95d2057bd8":"AUTHORITY","trc-hero-glyph.f9aca9fb84":"EVIDENCE","trc-hero-glyph.aaa398a28b":"STATE","trc-hero-glyph.e9ae0ed784":"REQUEST","trc-hero-glyph.a17fe045d2":"CLAIM SCOPED","trc-keep-check-share.chromeVerification":"Verification","trc-keep-check-share.0bbbef9c9b":"Trace, Consumer","trc-keep-check-share.2d30efe6f8":"It is your data, so you should own the proof.","trc-keep-check-share.52ebb05754":"Runs on your machine. Costs nothing.","trc-keep-check-share.be99fea5b5":"The receipt matches. Nothing was tampered with.","trc-keep-check-share.d42a2db3fe":"Verified.","trc-keep-check-share.22637c4092":"Nothing leaves your computer.","trc-keep-check-share.d0c70d1126":"Drop your trace here","trc-keep-check-share.e01fa717ba":"Offline","trc-keep-check-share.313e735e10":"The EU AI Act and GDPR both say you deserve transparency from automated systems. Dweve built the trace so those rights are not just legal text. They are a file on your computer that proves what happened.","trc-keep-check-share.80a2607ffd":"Built for your rights","trc-keep-check-share.e71102d544":"Your rights","trc-keep-check-share.63ef35a597":"Send the trace to a regulator, a journalist, a lawyer, or a friend. They verify it with the same free tool. The proof does not depend on trusting Dweve. It depends on math anyone can check.","trc-keep-check-share.ed5b779bda":"Show someone else","trc-keep-check-share.09ca55ca52":"Share","trc-keep-check-share.69bd6d606d":"The trace is a small file you download and keep. It does not live on a server that might shut down next year. It does not need a subscription. It is yours, and it stays verifiable for as long as you keep it.","trc-keep-check-share.5c12257168":"No expiring links","trc-keep-check-share.466fc49274":"Keep","trc-keep-check-share.5361bb7fcb":"Drag the trace file into your browser. The check runs entirely on your computer. No upload, no cloud service, no account. A valid receipt shows a green check. Tampering shows a clear failure.","trc-keep-check-share.babd6e4792":"Check it yourself","trc-keep-check-share.dda6ac27b9":"Verify","trc-merkle-tree.836722b952":"Trace, Technical","trc-merkle-tree.3926d89ba7":"The trace is not a flat list of events. It is a Merkle DAG where every node commits to its\n          children, and the signed root commits to them all.","trc-merkle-tree.3f5d66c46d":"You can verify a single leaf without recomputing the whole tree. The trace includes a\n                Merkle proof path of sibling hashes from a leaf up to the root, so checking one leaf\n                costs a hash per level of depth.","trc-merkle-tree.1ed2e9025f":"Sparse proofs","trc-merkle-tree.8e63844d1c":"Tree roles","trc-merkle-tree.00fe42c277":"Leaf","trc-merkle-tree.fc9225a169":"Internal","trc-merkle-tree.e96857c58f":"Root","trc-merkle-tree.c09c4c91de":"Merkle DAG","trc-merkle-tree.ab9f84b2c3":"same input, same root","trc-merkle-tree.f34d46da03":"canonical, hash-chained","trc-merkle-tree.0882493abf":"The root is the single value that commits to every leaf. It is signed with Ed25519 using the issuing node private key. Given the same computation, any two verifiers build the exact same tree shape and the exact same root, so a matching root is proof the whole structure is intact.","trc-merkle-tree.609e807e7a":"Signed root","trc-merkle-tree.796cfe9aa4":"Internal nodes pairwise-compress two child hashes into one parent hash, built bottom-up in canonical left-to-right order. For odd child counts the last child is promoted unchanged. There is no canonicalisation ambiguity because the HEDL schema defines field order, string encoding, and optional-field presence bits explicitly.","trc-merkle-tree.743cd396a6":"Internal nodes","trc-merkle-tree.de2173ef5b":"Every input byte sequence is normalised to canonical form (UTF-8 NFC, sorted map keys, explicit nil markers) and hashed. Every output is hashed raw. The leaf set is ordered by topological dependency, not chronology, so the tree shape is deterministic even when operations execute in parallel.","trc-merkle-tree.e133254771":"Leaf nodes","trc-receipt-anatomy.0bbbef9c9b":"Trace, Consumer","trc-receipt-anatomy.fc3e7543d8":"Right now showing","trc-receipt-anatomy.c6415ff12f":"Anyone can check it. It never expires.","trc-receipt-anatomy.f5b7e7b282":"Signed and sealed.","trc-receipt-anatomy.60987bc676":"Receipt for your answer","trc-receipt-anatomy.6832eca096":"When a machine decides something about you, you deserve to see how it decided. The\n              receipt shows exactly what went into the answer. No hidden steps. No black box.","trc-receipt-anatomy.6165ee112a":"Three things on every receipt.","trc-receipt-anatomy.4ef10ec222":"What the trace shows","trc-receipt-anatomy.8b6d08ba21":"Every safety rule that fired","trc-receipt-anatomy.71b6ab6571":"Every safety check, every policy boundary, every refusal to answer something harmful: the trace shows which rules fired and when. You see not just what the AI said, but what it was not allowed to say.","trc-receipt-anatomy.3985a06b7e":"The guardrails it followed","trc-receipt-anatomy.03b34e8afe":"The rules","trc-receipt-anatomy.3bdc79cc1f":"Every file and page it read","trc-receipt-anatomy.e82bbe5617":"If the AI looked at a file, a web page, or a policy document to build your answer, the trace lists them. You can see which sources influenced the result and whether they were the ones you expected.","trc-receipt-anatomy.ad83c7cb2f":"Every document it checked","trc-receipt-anatomy.bb7a289d4a":"The sources","trc-receipt-anatomy.f1f9623c83":"Your question, word for word","trc-receipt-anatomy.924be39426":"The trace records your question exactly as you wrote it. If the answer changes because someone reworded the question, the trace shows that. You are never left guessing whether the system heard you correctly.","trc-receipt-anatomy.8a178fad90":"Your exact words matter","trc-receipt-anatomy.d79cce547d":"The question","trc-replay-pipeline.836722b952":"Trace, Technical","trc-replay-pipeline.bcddb97038":"The AION verifier runs four stages in sequence and aborts with a non-zero exit code at the\n          first failure.","trc-replay-pipeline.ca6d0e3aaa":"Stage","trc-replay-pipeline.d780c3dd39":"non-zero exit aborts","trc-replay-pipeline.7410555a67":"4 stages, fail closed on first error","trc-replay-pipeline.799ee3cf0c":"aion verify --strict","trc-replay-pipeline.938403da94":"identical booleans","trc-replay-pipeline.03f923bd0d":"Lattice","trc-replay-pipeline.5db8dd157b":"Lattice re-evaluates every policy gate recorded in the trace: export controls, redaction spans, safety boundaries, access permissions. Each gate must produce the identical boolean result. A bypass is flagged with the gate name and the divergent span.","trc-replay-pipeline.a66b078dc6":"Lattice re-evaluates every gate","trc-replay-pipeline.6aae835274":"Policy gate replay","trc-replay-pipeline.fa33a05407":"no drift","trc-replay-pipeline.7b2b0439f8":"Numerus exact","trc-replay-pipeline.c23f315412":"exact match","trc-replay-pipeline.1985429ad2":"Replay each operation with its recorded inputs and compare the output hash to the stored value. An exact match is required. In hard-determinism mode, arithmetic is routed through Numerus exact math to eliminate platform-dependent floating-point drift.","trc-replay-pipeline.b0cd7da0d2":"replay each op, compare output hashes","trc-replay-pipeline.7384288a87":"Kernel replay","trc-replay-pipeline.3e4edeca51":"fail closed","trc-replay-pipeline.6e9a040bd1":"canonical tree","trc-replay-pipeline.66216241e0":"Recombine the recorded leaf hashes using the canonical tree construction defined in the spec, then compare the recomputed root byte for byte against the signed root in the header. Any single-bit mutation anywhere in the trace invalidates the root.","trc-replay-pipeline.5f724da7d6":"recombine leaf hashes to the canonical root","trc-replay-pipeline.387f919ac9":"Merkle root recompute","trc-replay-pipeline.e4657127cf":"header schema","trc-replay-pipeline.210c36149a":"HEDL parse","trc-replay-pipeline.5b65b3eacd":"Parse the HEDL-encoded trace blob, validate the header against the published schema, and verify the Ed25519 signature over the Merkle root back to the issuing node. Single-binary implementation with no external dependencies in offline mode.","trc-replay-pipeline.868655da90":"HEDL parse, header check, Ed25519 verify","trc-replay-pipeline.494f0409fe":"Parse and authenticate","trc-trace-anatomy.19bc45c40b":"Trace, Business","trc-trace-anatomy.b771b198c6":"A trace is not a log. A log is written by the application. A trace is written by the\n          runtime, and every field contributes to the final root hash.","trc-trace-anatomy.74ff4ddd80":"Explicitly optional, typed in the public spec","trc-trace-anatomy.41f8ea6fb9":"Mandatory, typed in the public spec","trc-trace-anatomy.3e5076575a":"Field detail","trc-trace-anatomy.a10c3f25c8":"OPTIONAL","trc-trace-anatomy.65f67f6135":"REQUIRED","trc-trace-anatomy.dee8711bff":"every field hashes into the root","trc-trace-anatomy.51a09ddc63":"6 fields, root committed","trc-trace-anatomy.a80e45eb78":"An Ed25519 signature over the Merkle root, issued by the node that generated the trace. The verifier checks the signature back to the issuing node identity before anything else.","trc-trace-anatomy.2f32be1dc7":"Signature","trc-trace-anatomy.5e00847b8c":"Model version hash, policy set hash, determinism mode (hard, seeded, or creative), timestamp range, issuer identity. The header commits the trace to a fixed configuration.","trc-trace-anatomy.7d290f134f":"Proof header","trc-trace-anatomy.74a237954d":"The final answer, the action taken, any secondary outputs (confidence, fallback, refusal). Each is hashed and linked to the operation that produced it.","trc-trace-anatomy.1b1905d4b7":"Outputs and decisions","trc-trace-anatomy.14ed5476dc":"Domain-specialist selections, attention masks, retrieval hits, policy gates. Stored by reference (hash) with optional full-value inclusion for replay-without-inputs scenarios.","trc-trace-anatomy.5792f2490e":"Intermediate values","trc-trace-anatomy.0bd57d6cb5":"Each compute operation records its identifier, version hash, input hashes, and output hash. The call graph is a directed acyclic graph rooted at the final output.","trc-trace-anatomy.df8af525f2":"Operation calls","trc-trace-anatomy.a77fadaf77":"Every byte of every input, normalised to a canonical on-wire form and hashed individually. User prompt, tool arguments, retrieved documents, policy context. Nothing implicit.","trc-trace-anatomy.d7293ecffc":"Canonicalised inputs","trc-use-case-ledger.4ea48cac41":"Replay the exact decision, years later.","trc-use-case-ledger.7ad5ce81e8":"Compare traces from current and prior model versions on the same benchmark set. Every delta is attributable to a specific operation or policy change.","trc-use-case-ledger.230fd716e7":"Model drift detection","trc-use-case-ledger.3bc2a71b5a":"ML engineers","trc-use-case-ledger.193863d086":"When a customer claims the AI gave bad advice, replay the exact session against the exact model version. Disagreement becomes a matter of record, not interpretation.","trc-use-case-ledger.496b899eb3":"Customer dispute","trc-use-case-ledger.c21329c56a":"Legal teams","trc-use-case-ledger.8510acdf0d":"Attach traces as Annex IV technical-documentation evidence for the EU AI Act, as GxP records for medical-device submissions, as DORA ICT third-party evidence.","trc-use-case-ledger.bce3647f95":"Regulatory submission","trc-use-case-ledger.12f76bdf35":"Compliance officers","trc-use-case-ledger.fa492d6d47":"Attach the trace to a paper or dataset. Reviewers and future readers replay the exact experiment without cloud access, without chasing a deprecated endpoint.","trc-use-case-ledger.fd9cee7cef":"Academic reproducibility","trc-use-case-ledger.8ebe2d9157":"Researchers","trc-use-case-ledger.760e3bcbd9":"When a bad decision is discovered, the trace tells you exactly which inputs, which retrieved documents, and which policy path produced it. Root-cause analysis in minutes, not weeks.","trc-use-case-ledger.6e590d9512":"Incident response","trc-use-case-ledger.588674f191":"Ops teams","trc-use-case-ledger.bbd65cdb7b":"Internal auditors sample decisions, replay them, and verify the model behaved the way policy said it should. No need to freeze the production model during the audit window.","trc-use-case-ledger.a4d9b106e1":"Internal audit","trc-use-case-ledger.fcbecbfd11":"Auditors","trc-verifier-surfaces.7257679ed3":"Command-line verifier","trc-verifier-surfaces.dccf5ec193":"Apache 2.0 single static binary. Exits with success if the trace replays bit-identically, non-zero otherwise. Offline-mode support and machine-readable JSON output for automated pipelines.","trc-verifier-surfaces.b592f36418":"$ aion verify decision.trace","trc-verifier-surfaces.f2b6c903b7":"load + signature ... ok","trc-verifier-surfaces.441b899832":"merkle root ........ ok","trc-verifier-surfaces.afe6936475":"replay 10 ops ...... ok","trc-verifier-surfaces.c541168246":"VERIFIED  exit 0","trc-verifier-surfaces.fde1bd3318":"Multi-language SDKs","trc-verifier-surfaces.87d3123bb7":"Bindings for common languages around the same core verifier. Verify in-process, gate decisions on a successful replay, and embed verification directly in your audit pipelines.","trc-verifier-surfaces.266cbc344c":"const ok = await aion.verify(trace)","trc-verifier-surfaces.a3bcb91f39":"// gate the action on a clean replay","trc-verifier-surfaces.d003f1ed8d":"if (!ok) reject(\"trace mismatch\")","trc-verifier-surfaces.ee6a152d16":"ok === true","trc-verifier-surfaces.a2671fb6a9":"In-browser verifier","trc-verifier-surfaces.f7c4b44736":"Drag-and-drop a trace file onto a page. Verification runs entirely client-side, with no network calls and no analytics. Used in the Fabric UI next to every decision card.","trc-verifier-surfaces.371efb2366":"drop  decision.trace","trc-verifier-surfaces.386690398b":"verifying client-side ...","trc-verifier-surfaces.cc1aa9bc11":"no network calls made","trc-verifier-surfaces.9c9a97f59b":"Verified, on your machine","trc-verifier-surfaces.18043b6991":"Replay workbench","trc-verifier-surfaces.f99d84fb32":"A forensic view in Fabric: load a trace, inspect the proof graph, compare it with another trace, step through operation calls, isolate a retrieved document, and export a reduced trace for sharing.","trc-verifier-surfaces.cbeef92a99":"load trace.A   load trace.B","trc-verifier-surfaces.29b34bb6f2":"diff: 1 op differs at step 7","trc-verifier-surfaces.4c81506a89":"isolate: doc#4 changed output","trc-verifier-surfaces.13611a32e9":"export reduced.trace","trc-verifier-surfaces.10bfe5d5c2":"four surfaces, one proof format","trc-verifier-surfaces.b3ee7f4db0":"Verification surfaces","trc-verifier-surfaces.a1b2f0f26c":"Pick the surface that matches how your team works. One proof format underneath all four.","trc-verifier-surfaces.19bc45c40b":"Trace, Business","trc-verify-pipeline.ddcb77ff76":"Load","trc-verify-pipeline.3fe0bb5c07":"Load and validate","trc-verify-pipeline.e8e922a2c6":"Parse the trace file, validate the header against the published specification, confirm the digital signature from the issuing node, and check the serialised structure has the expected node count and field types.","trc-verify-pipeline.d71095c651":"Recompute","trc-verify-pipeline.5b48d364e8":"Recompute the root hash","trc-verify-pipeline.31156e0de6":"Rebuild the Merkle tree from the recorded leaf hashes and confirm the computed root matches the hash stored in the header. A single flipped bit anywhere makes the roots diverge and halts verification.","trc-verify-pipeline.7b4792b9f1":"Re-execute","trc-verify-pipeline.f8c4fffb5f":"Re-execute operations","trc-verify-pipeline.8dc4fff23a":"Replay every recorded operation against its stored inputs. Each output hash is checked for a bit-identical match. If any operation produces a different result, the verifier reports which step failed and why.","trc-verify-pipeline.bb9cf14180":"Policy","trc-verify-pipeline.82458b325d":"Replay policy gates","trc-verify-pipeline.04f77bd5c6":"Re-run the policy checks: export controls, personal-data redaction, access permissions, safety boundaries. Each gate must produce the same result as recorded. A policy bypass is caught and flagged.","trc-verify-pipeline.c06e691f30":"aion verify","trc-verify-pipeline.8e87292d97":"fail-closed, deterministic","trc-verify-pipeline.8cc70b939a":"runs inline in the browser","trc-verify-pipeline.2f983c0f09":"Pass to continue","trc-verify-pipeline.35f926b111":"Offline verification works the same way.","trc-verify-pipeline.ad951d773d":"All four stages run without network access. The verifier validates the signature against\n            a local trust anchor, then proceeds through load, Merkle recompute, operation replay, and\n            policy replay exactly as online. Sovereign verification produces the same VERIFIED output\n            with the same bit-identical guarantee.","trc-verify-pipeline.fe6168e59f":"No network","trc-verify-pipeline.56a9de1055":"The verifier does four things, in order, and fails closed at any step.","trc-verify-pipeline.19bc45c40b":"Trace, Business"}
