BBARANES
Baranes Atlas/Authority boundaries/03
Authority boundaries · 03

What Evidence Can — and Cannot — Prove

Hashes, signatures, provenance and attestations can make evidence stronger without turning the evidence layer into the owner of semantic truth.

INTEGRITY VERIFIED != SEMANTIC TRUTHEVIDENCE != TRUTH AUTHORITYATTESTATION != CANONICAL ACCEPTANCE
Hashbytes match
Signaturesigning relation
Provenanceorigin + history
Attestationbounded observation
establish bounded properties↓
Bounded property verifiedverifiable evidence
interpreted by↓
Semantic authorityowns the proposition
Separate decision
Canonical acceptancenot implied by verification

Better evidence gives an authority better grounds for a decision. It does not inherit the authority to make every decision itself.

Verifiable ≠ semantically true

Strong evidence proves bounded properties.

Imagine a system receives a statement saying deployment succeeded. The statement has a valid signature. Its bytes match a digest. Its producer is known. Its provenance is traceable.

Those are valuable facts. They still do not automatically establish that the intended durable deployment effect is true.

Different mechanisms answer different questions

A digestcan show that compared bytes match an expected digest.
A signaturecan establish the signing relationship defined by the applicable key rules.
Provenancecan show where material came from, which version was used and how it was transformed.
An observation or attestationcan record that a named observer evaluated a proposition under a stated method and source path.

Each can be strong. None automatically becomes the semantic owner of every proposition described by the evidence.

Why the boundary matters

Evidence systems naturally accumulate convenience labels: verified, passed, trusted. If those labels are allowed to absorb meaning, integrity checks or verifier outputs can quietly become a generic truth oracle.

producer claim → remains a producer claimobservation → remains an observationattestation → remains a bounded verification resultsemantic fact → remains owned by the correct semantic authority

Independence depends on the source path

Passing an executor’s success claim through another component does not make it independent evidence if the second component reads only the same self-claim.

executor says “success”↓projection copies “success”↓verifier reads only that projection↓“success verified”

The label changed. The relevant source did not. A meaningful independent attestation needs a relevant source or observation path independent of the executor claim being evaluated.

Common misconception

“If the signature is valid, the claim is true.”

No. A valid signature establishes the bounded property defined by the signature and key policy. A perfectly signed statement can still describe a semantic proposition that the affected domain must evaluate separately.

Boundary / limit

This page does not claim one final EvidenceEnvelope serialization, one universal evidence store, one universal attestation service or one fixed physical evidence topology.

Technical note: EvidenceEnvelope

Baranes uses an EvidenceEnvelope concept to keep evidence context bound: subject and claim identity, source/version, producer or collector, time/order, references or digests, provenance, verification context, known gaps, sensitivity and correction/supersession context can travel together where useful.

The important rule is not the field list:

Packaging or referencing a source does not transfer the source’s semantic authority to the envelope.

The conceptual baseline is not a promise of one concrete API, storage format or serialization.

Independent attestation can be especially strong because its relevant source path is independent of the executor self-claim. It still supplies a bounded evidence result. The affected semantic domain retains effect-truth authority.

ATTESTATION!=CANONICAL FACT ACCEPTANCE

Maturity: canonical logical architecture. Evidence/provenance authority boundaries are defined conceptually; final physical schema, provider and service topology remain separate decisions.

Bounded example: RepoOps can illustrate structured evidence composition in a repository domain. That does not make its evidence mechanics a universal Baranes service, and it does not by itself prove production-independent attestation.