Bind the execution
The production receipt design records modelHash, codeHash, inHash, outHash, attRef, ts and sig. These fields bind the request and answer to approved model and code measurements.
Anchor the record
AttestationVerifier and ModelRegistry on Arc form the proposed anchoring path. The local dashboard exposes the receipt format with unsigned, unanchored preview records.
Disclose by scope
Scoped view keys are intended to enable authorized payment disclosure. Audit exports give reviewers selected hashes and metadata, with payment amounts included only when chosen.
Understand the evidence
Execution provenance does not prove that a model answer is correct. The dashboard’s integrity check checks the local record envelope; it does not verify hardware or a production signature.
