What actually happens between "the agent did something" and "anyone can prove what was allowed" — and why tampering is visible instead of arguable. This is the mechanism behind every receipt on this estate.
The action, the evidence it saw, the policy verdict, and the acting authority are assembled into one record: evidence · policy · replay-hash · actor · verdict. Nothing depends on someone's later recollection.
A SHA-256 digest fixes the record's exact contents; an ed25519 signature binds it to a Summit signing key. Change one byte and the digest — and therefore the signature — no longer matches.
Every receipt carries the previous receipt's hash. Deleting or reordering history breaks every link after the edit — you cannot quietly remove an embarrassing decision from the middle.
Verification needs the receipt, the public key, and arithmetic — not a Summit account, not Summit's cooperation, not Summit staying in business. The Trust Portal and the public chain audit do it in the open.
The record is exactly what was sealed, in the order it was sealed. That doesn't certify the AI was right — it proves what it did, on what evidence, and who allowed it. Correctness stays a human judgment, now made on real evidence.
The chain fails loudly and specifically: which receipt, which link. A failed verification is treated as evidence of tampering or corruption — never silently repaired. Try it yourself: break a record in the simulation or the sample gallery's failure case.