← Files OpsTruthARCHIVED FILE

docs/adr/0003-independent-post-execution-verification.md

994 Bytes · Oct 2, 2026 · 00:31 UTC

↓ Download file

# ADR 0003: Independently Verify Execution Outcomes

Status: accepted
Date: 2026-08-27

## Context

A signed execution receipt establishes integrity of a claim. It does not prove authority, safety, correctness, or current deployed state.

## Decision

OpsTruth issues a post-execution verdict only after binding the request, authorization, receipt, and fresh observations to the same exact subject. The allowed verdicts are `VERIFIED`, `PARTIAL`, `CONTRADICTED`, and `UNPROVEN`.

## Consequences

- Receipt success cannot directly map to `VERIFIED`.
- Missing deployment identity remains `UNPROVEN` even if health probes pass.
- Conflicting evidence is preserved and reported.
- Authorizer, executor and verifier identities and keys remain separate, with role-specific trust policy.

## Rejected alternatives

- Trusting a receipt solely because its signature is valid.
- Letting the executor produce the final verification verdict.
- Treating a successful HTTP probe as deployment provenance.

SHA-256: 0c8fcf7efe519f0c880c5f3fa47248b8e2157990fb8ac9471647fd1ecd464718