What a decision record proves — and what it does not.
Every governed action produces a decision record. This brief states the fields, shows you how to verify a real one yourself in a browser, and marks exactly where the claim stops. It is written to be forwarded.
The fields
Verify one yourself, without talking to us
A real Gateway staging receipt is pre-loaded in the browser verifier, signed under published key staging-2026-07-06. You can recompute its decision hash, check the signature against the published key, and then alter one byte and watch verification fail. It runs entirely in your browser — nothing is sent to us.
Where the claim stops
A record evidences the decision, not the downstream effect. It states the ruling, the policy metadata, and the response the enforcement point issued. It is not independent proof that a downstream system executed, or refused to execute, anything.
Signing and chaining differ by product. Ed25519 signatures with per-organization hash chaining are the Mission Authorization Gateway staging build. Connected-tier proxy rulings use HMAC receipts; the Chat Firewall writes tamper-evident audit records. The per-product scheme is stated in the Trust status matrix.
Re-evaluation has preconditions. A ruling can be re-evaluated only where the exact recorded input, the context, and the retained policy bundle are all still available. Retention is a deployment decision.
Three questions worth asking us
2 What is the retention window, and who can export the trail?
3 Which paths in our environment are mediated, and which are deliberately left direct?