What a membership organisation can prove about its own words

Brief

One page, for someone deciding whether the longer piece is worth their time.

The claim

An organisation that speaks in public through many people can, with ordinary published mechanisms, put its own record of what it approved and when beyond the reach of both its opponents and its supplier’s convenience — partly. This brief is mostly about the word “partly”, because that is the part product copy tends to lose.

What is settled by the mechanism

Question in dispute Settled by How far
Has this text changed since approval? SHA-256 over canonical bytes Fully, for anyone holding the bytes
Was this record made before that event? RFC 3161 timestamp from an outside authority Strongly — the authority had no stake and its own signature is checkable
Did this platform attest to these bytes? Ed25519 signature Fully, and verifiable without the platform’s cooperation
Did the organisation sign this? Not settled. The key is the supplier’s
Was the approver entitled to approve? Not settled, and deliberately so. That is the organisation’s own rule

The three components

Whose signature it is, and where it goes next

The signing key belongs to the supplier. What a third party verifies without the supplier’s help is a supplier’s signature — evidence that a platform attested to particular bytes at a particular time — and, where the outside authority was reachable when the record was saved, a timestamp from a party with no stake in the argument. Together they retire the story that actually gets used in a dispute: we wrote that last week and back-dated it. Signing is unconditional; dating is obtained across the network, so signed and dated are two facts worth reading separately.

The step beyond is the organisation holding its own key, and it is governance before it is engineering: who holds it, under what mandate, what happens when they leave, and what the constitution says about a key that can commit the organisation to a position. Those are questions an organisation answers from its own rules.

The timestamp is evidence, not a presumption. Under eIDAS Article 41 a qualified timestamp carries a presumption of accuracy in EU law, and a token from an ordinary authority is not qualified, so that presumption does not arise. eIDAS is EU law; the New Zealand position is a question for a lawyer there. That is a description of the instruments, not legal advice — which no organisation should take from software or from whoever wrote it.

Why this matters more than it sounds

Most governance tooling answers the authority question — who may approve — because the answer has to come from somewhere. It does not. It can be a field the organisation fills in from rules it already has, with the tool declining to have a view. A supplier that decides who may approve is writing a piece of the constitution.

Where to look


The rest of this package

agenticgovernance.digital