Evidence & Records · agenticgovernance.digital

The supplier's signature

How a membership organisation proves what it said, and when

An organisation that speaks through many people has two problems

Coordination is the one everyone names. Proof is the one that only appears at the worst moment.

A record, an integrity check, and an attestation are three different things

Most products stop at the first and describe it as though it were the third.

Three components, none of them novel

The lack of novelty is the point — each is publicly specified, with implementations nobody here controls.

The timestamp is the interesting part

A signature made by the party holding the record proves less than it appears to — they control both the record and the clock.

Whose signature it is, and where it goes next

What a third party verifies without us is a supplier's signature and — where the outside authority was reachable when the record was saved — a timestamp from a party with no stake in the argument. Together they retire the story that actually gets used: we wrote that last week and back-dated it.

Evidence, not a presumption

Under eIDAS Article 41 a qualified timestamp carries a presumption in EU law. These tokens are not qualified, so that presumption does not arise — and what a New Zealand tribunal would make of one is a lawyer’s question, not ours.

Who may approve is not a question for the software

Most governance tooling answers it because the answer has to come from somewhere. It does not have to come from the supplier.

What the demonstration runs

The coordination half is real code working on the visitor's own text. The attestation half is described rather than performed, because the page talks to no database.

Where to look

The signing key is ours. What you can check without us is a supplier’s signature, not your own — and closing that gap is a question for your rules, not our software.