Evaluator Driven

Custody

“Who made this?” is the wrong question.

In 2026 the honest answer is an agent did, at my direction — true, unverifiable, and useless. It names a tool and an intention. It does not name a decision, a standard, a check, or a person answerable for any of them.

Two things called provenance

The industry uses one word for two different objects, and keeping them apart is most of the argument.

Content provenance

Answers what made this file? — a signed manifest, capture versus generation, edit history. It describes the artifact. Deployed, useful, and in use today.

Decision provenance

Answers what did we say good would mean, who said it, what came back, who accepted it? It describes the work. This is what a procurement, security or legal review actually asks for, and what this standard specifies.

Provenance is the problem. Custody is the mechanism. Custody is a retained, checkable chain recording the bar declared before the work, the evidence the work produced, and the named person who accepted it.

Why artifact credentials cannot do this job

01

They are strippable

Re-encode the file, screenshot the page, paste the text — the credential does not travel. The artifact survives; the claim about it does not.

02

They are silent on quality

A validly signed file can be bad work. Provenance is not evaluation, and treating it as a substitute for a check is how “we have provenance” becomes “we don’t need to look”.

03

They never covered the decisions

Your commit can be signed. The reason for the commit was never signed by anyone, because the reason lived in a person’s head and was assumed to be recalled on demand.

Claims became cheap. Evidence did not.

Anyone can produce a provenance claim. Generated by a model. Reviewed by a human. Both fit in any field of any manifest, cost nothing, and are indistinguishable from true ones at the point of reading. The cheaper generation gets, the less any of those strings is worth.

Evidence is a claim produced by a procedure whose failure would have been visible. This standard takes a position rather than a preference: a declared dimension that no filed pass observes fails the record outright — evidence not attributable — and the rule underneath is zero is not one.

What custody actually is

  • 01The bar declared, with provenance to its buyer and its specialist. No provenance, no authority.
  • 02The rulebook version pinned, so a later reader knows what was in force.
  • 03The evidence retained with the artifact: instruments, evaluator identity, ground-truth version, control runs.
  • 04An instrument that does not edit its own readings.
  • 05A disposition — given / not_yet_given / declined, recorded as a state, never as an absence — resting on a named person.

The chain does not end in a model, a tool, or a hash. It ends in a human being who said yes, by name.

The signature test

A signature does three things: it identifies who signed, it expresses assent to what was signed, and it binds the signer to the consequences.

An agent’s output does none of the three. A record that ends in a named disposition does all three. That is the answer to delegated work has no signature — not a new kind of signature, but the reconstruction of the conditions under which a signature means anything.

The honest note

Custody makes work answerable. It does not make work correct. Those are different promises, and conflating them is the overclaim that would break everything else we say. A retained record can be misread — ours has been, by readers written to catch exactly that.

Content credentials are not useless: they answer their own question well, and we treat them as the necessary half. This standard covers the other one.