Verifier workspace

Review sealed evidence. Keep independence.

The Verifier portal (/portal) is grant-scoped: you see sealed packages an operator opened for you — download, inspect, and attest. You do not get operator write access to the ledger.

What you see first

A professional review queue — not a green checkmark

  • Ready for review — sealed bundles under your grant.
  • Package integrity — merkle root and document bodies that offline verify can rehash.
  • Findings language — unsourced inputs, post-knowledge corrections, and related disclosures carried in the package.
  • Attestation — opinion + Ed25519 signature with a client-held private key (PEM never uploaded as raw key material).
  • History — prior attestations bound to the sealed root where recorded.

Traceability

Claim → source → calculation → evidence → status

Offline verification recomputes methodology hash, input-set hash, lineage hash, and merkle root from embedded content. A hash field without document bytes is not treated as L1 for supplier, invoice, calibration, or monitoring kinds.

Claim

Declared output value and unit in the sealed calculation.

Sources

Measurement and declaration references carried in the package.

Method

Full methodology pack body — not a registry nickname alone.

Seal

Merkle root binding the leaves the operator stored at seal time.

Decisions

Attestation semantics the product supports

Download verification package

Obtain the offline-verifiable JSON for independent recomputation.

Sign attestation

Browser signing flow: private key stays local; server verifies the signature.

Opinion fields

Structured opinion, statement, and accreditation metadata bound to the merkle root.

Do not invent approve/reject workflows beyond what the portal exposes after login. Final verification decisions that are destructive or irreversible must follow the live UI’s confirmation copy.

Independence is the product

DCI does not ask you to trust a portal badge. It asks you to recompute the sealed package.