← Files OpsTruthARCHIVED FILE
docs/adr/0003-independent-post-execution-verification.md
994 Bytes · Oct 2, 2026 · 00:31 UTC
# ADR 0003: Independently Verify Execution Outcomes Status: accepted Date: 2026-08-27 ## Context A signed execution receipt establishes integrity of a claim. It does not prove authority, safety, correctness, or current deployed state. ## Decision OpsTruth issues a post-execution verdict only after binding the request, authorization, receipt, and fresh observations to the same exact subject. The allowed verdicts are `VERIFIED`, `PARTIAL`, `CONTRADICTED`, and `UNPROVEN`. ## Consequences - Receipt success cannot directly map to `VERIFIED`. - Missing deployment identity remains `UNPROVEN` even if health probes pass. - Conflicting evidence is preserved and reported. - Authorizer, executor and verifier identities and keys remain separate, with role-specific trust policy. ## Rejected alternatives - Trusting a receipt solely because its signature is valid. - Letting the executor produce the final verification verdict. - Treating a successful HTTP probe as deployment provenance.
SHA-256: 0c8fcf7efe519f0c880c5f3fa47248b8e2157990fb8ac9471647fd1ecd464718