Portable evidence needs a public clock
A signature identifies a speaker. Transparency makes the speaker's sequence of statements harder to rewrite in private.
A signed record answers an important question: did the holder of this key endorse these bytes? It can survive copying, move between systems, and be verified without trusting the database that currently stores it. For agent evidence that crosses organizations, this is a powerful foundation.
A signature does not prove when the statement first existed, whether it replaced an earlier statement, whether the signer concealed conflicting records, or whether the verifier is seeing the same history as everyone else. A key holder can sign two incompatible accounts and show each to a different audience. Both signatures can be valid.
The IETF's June 2026 RFC 9943 defines the Supply Chain Integrity, Transparency, and Trust architecture for making signed statements transparent. An issuer submits a signed statement to a transparency service. The service applies a registration policy, records the statement in a verifiable append-only structure, and returns a receipt proving registration.
Registration adds a second witness
The transparency service is not a judge of the underlying claim. A registered statement can still be mistaken or dishonest. Its receipt establishes something narrower: a particular service accepted this signed statement under its registration policy and placed it into its history.
That second witness changes the economics of rewriting. The issuer can publish a correction, but it cannot quietly make the earlier registered statement disappear from an append-only history without creating detectable inconsistency. A relying party can retain the receipt and verify inclusion later, even when the statement has moved away from the system that created it.
RFC 9943 describes registration as analogous to notarization and supports content-agnostic statements about artifacts. Its formal scope begins with digital supply chains, but the architecture's distinction among issuer, signed statement, transparency service, receipt, and relying party is instructive for durable agent evidence. The useful idea is not that every trace belongs on a public ledger. It is that important claims can obtain an independent, portable place in history.
A signature says who spoke. A transparency receipt makes it harder to change when that speech entered the shared record.
This is a public clock in the institutional sense, not necessarily a precise wall-clock oracle. Inclusion establishes sequence within a verifiable history. External time evidence may strengthen temporal claims, but the core value is consistency: relying parties can test whether they are being shown an append-only view.
Policy must travel with the receipt
A receipt is only as interpretable as the service and policy behind it. Registration might require only a valid signature and media type. It might also require an approved issuer, a known statement profile, or additional metadata. Two services can register the same statement under different policies and create receipts with different practical meaning.
RFC 9943 requires transparency services to maintain registration policies and make policy and trust-anchor information available to relying parties. This matters because “present in the log” must not collapse into “approved as true.” The record should identify which policy version applied when the statement was registered and which service identity issued the receipt.
The IETF SCITT working group frames the problem as interoperable verification of supply-chain claims across diverse systems. Agent ecosystems face a similar portability problem: evidence may originate in one vendor's platform, pass through another agent, and be reviewed by a third institution years later. Proprietary log formats make that chain depend on every original operator remaining available.
Content minimization remains essential. Transparent does not mean indiscriminately public. A statement can bind to an artifact by digest, carry limited metadata, or refer to evidence held under access controls. The design should reveal enough for consistency and verification without exposing prompts, personal data, secrets, or protected business content.
Publish corrections as new statements
Durable evidence must accommodate error. An append-only system should not force institutions to defend a false claim forever. It should make correction explicit: issue a new signed statement that identifies what it supersedes, why, and under whose authority. Register the correction so later readers can see both the original assertion and the institution's changed position.
Key compromise needs the same historical honesty. A later revocation can warn relying parties not to trust new statements from a key, but it cannot by itself reveal which earlier statements were legitimate. Issuers should preserve key-validity periods, rotation events, and compromise notices as part of the transparent history. Relying parties then evaluate a receipt against the policy and trust state that applied at registration, plus any later evidence that changes confidence in the issuer.
This supports a healthier form of accountability than silent mutation. The record can show that an agent acted on evidence later found to be wrong, that the organization corrected the source, and that downstream decisions were revisited. A perfect-looking history is less trustworthy than a history whose corrections are legible.
Not every agent event warrants registration. The strongest candidates are boundary claims that must remain portable: a release attestation, a policy approval, a delegated authority statement, a high-consequence action result, or a correction whose existence several parties may later dispute. Internal traces can remain internal while these anchors travel.
Selection itself should be policy-driven. Registering everything creates cost, exposure, and an unusable history; registering only after controversy invites selective memory. Define the statement classes, issuers, and timing in advance, then monitor gaps between eligible events and actual registrations.
Interoperable agents need interoperable evidence because the systems that perform the work will change faster than the obligations the work creates. Signed statements provide authorship. Transparency receipts provide portable inclusion. Together they give future reviewers a way to verify not just a document, but its place in a history the original issuer cannot privately rearrange.
— Dispatches · Summit Cognitive
Continue from here
Turn the argument into a practice.
Get new dispatches, assess how your organization handles consequential decisions, or explore Summit Cognitive.