SealSample docket
  • Signatureschecking
  • In public logchecking
  • Append-onlychecking
  • Verdictdisabled on sample

Sample reviewer docket

An AI system acted. What was it cleared to do?

Two real decisions signed by Seal in production: one allowed, one blocked. This is what the reviewer receives. Every check below runs in your browser.

Checking in your browser

0of 2 signatures verified

Verifying every signature in this pack.

  • Record 01ALLOWED
    Model requested
    claude-sonnet-4-6
    Policy applied
    budget_guard · loop_guard
    Signed
    13 Aug 2026, 01:27 UTC

    Checking signature

  • Record 02BLOCKED
    Model requested
    gpt-4o
    Policy applied
    pii_scan
    Signed
    09 Aug 2026, 21:45 UTC

    Checking signature

Three layers of evidence

  1. What happened

    The operator’s own logs

    Not in this pack

  2. What was cleared

    These signed records

    Checked on this page

  3. Whether it is enough

    The reviewer

    Decided at the end of this docket

How this was checked

  1. A decision was evaluated, then recorded

    Issuer · Seal gateway

    Policy ran before the call proceeded. 2 receipts were signed with Ed25519 and checked here against Seal’s published key.

    Proves who wrote the record and that nothing in it changed. Not that the model behaved correctly.

  2. Checking inclusion in this browser

    Issuer’s append-only log · RFC 6962

  3. Checking against the live public log

    Public log · one unauthenticated read

What this proves

  • The issuer signed exactly these fields
  • Nobody has altered them since
  • Which policy was in force, and what it decided
  • Which model was requested
  • These records, refusals included, were in the issuer’s public log when its head was signed

What it does not

  • Which model actually executed
  • That every decision was recorded
  • That the records you were not shown were irrelevant

The question put to the reviewer

Did each of these decisions clear under the policy in force when it ran?

Fixed before the evidence was opened, so it cannot be adjusted to fit the answer.

The evidence answers the question, for the purpose it was asked.

Consistent, but it does not reach the question. A real answer, and a different fix.

The evidence does not support an affirmative answer.

Disabled on this published sample. A verdict recorded here would be attributed to someone who never made it, which is the thing the rest of this page exists to prevent.