What changed after somebody read this

This project measures what other people's systems can and cannot show. That only means something if the same standard runs in this direction, so this page is the list of what actually moved after somebody read the work, with a link on every line.

Corrections that landed on this project are on the same page as the ones that landed elsewhere, deliberately. A page carrying only the first kind would be a brag sheet, and a reader could not tell the difference between a project that gets checked and one that is never read closely enough to correct.

Independently reproduced

On 6 September 2026, somebody who had never contributed here ran the reference validator against the published conformance corpus at the pinned commit and reported back 52 of 52, with the split of 40 cases carrying a level and 12 carrying none, matching what was published. Then they contested one of the cases, and they were right.

The contested check was the contradiction rule, which refused executed: true alongside outcome: unconfirmed. That combination is what a provider returning 200 with settlement pending actually is, so the rule forced the honest record into executed: false, which is the field a naive retry keys on. It was fixed the same night in both validators, the emitter, the specification text and the corpus. The corpus now stands at 57 cases.

Running the corpus is one step from implementing against it, and it is the closest anybody has come to a second implementation, which is what decides whether this is a specification or a manual. The reproduction is here, in a thread on somebody else's repository.

Changed in somebody else's work

A commit. On 3 September 2026, 50e265d8c4d3, "feat: bind approval to authenticated principal", landed in a repository belonging to somebody this project has never met. It came the day after an argument on pydantic-ai#6452 that an approver name taken from a request body is display metadata rather than authority. A commit rather than a compliment, and the only one of its kind so far.

A product decision. On 9 September 2026, the author of AgentGuard, an execution-bound authorization layer, wrote: "I don't want to position AgentGuard as solving a failure mode that the frameworks have already largely addressed." That followed being shown the measurement that all eight acting systems in the census keep risk classes and tool permissions outside model-controlled state, so the failure mode the product was being positioned against was not the one the frameworks have.

A position held since June, revised in public. On 6 September 2026, a contributor to the same thread corrected their own 27 June comment: they had described a signed receipt as establishing that evidence can be verified outside the operator's infrastructure, and wrote that this "was too broad." A signature authenticates origin and detects change. It does not establish that the reported action happened.

Changed here, because somebody checked

The scope entry in version 0.2 exists because Phill Clapham reported that the validator refused TR-3 to any record containing no decisions, a requirement that appeared nowhere in the specification text. The specification was wrong and the validator was enforcing something unwritten.

The outcome member in -02 exists because a reader on somebody else's issue tracker pointed out that an expired evidence deadline and a failed action are different facts, and the format could express neither: executed was a required boolean, so a system whose acknowledgement never came back had to assert something it did not know.

The clock is an undisclosed attested claim, and it took a stranger to say so. Raised in the exchange on machine-testimony#44 and split out into #49 on 7 September 2026 at the request of the person who raised it: every at in a record is the emitting party's own word, no check says so, and a reader sees TR-4 with thirty-one verified checks and learns nothing about it. Conceded the same day. Three fixes were named and the two that could be built were built: at now sits in the specification's own list of claims a reader cannot settle, and where a record carries an RFC 3161 token the validator reads the authority's genTime and checks that no entry claims a write time after it, reporting the measured difference even when it passes, because it is the only outside reading of the emitter's clock the record contains.

The third fix is the one that cannot be built, and the specification says so rather than leaving it implied. The anchor bounds at from above and nothing bounds it from below, so back-dating stays open: closing it needs a timestamp taken before the fact rather than over the finished record, which no self-contained record can carry. That is the whole argument of this project applied to itself, and it is why the gap is written into the text instead of being fixed with a claim.

A reading of the EU AI Act, corrected by the person who had just reproduced the corpus. On 9 September 2026: Article 12(3)(d) is the one place in the Act where a log must record "the identification of the natural persons involved in the verification of the results," scoped to the remote biometric identification systems in Annex III point 1(a). The correction strengthened the conclusion rather than weakening it, and the pages were rewritten the same day.

And then the fix itself was audited. Three hours later the same reader re-read the published pages live, confirmed three of the four places had been corrected, and named the fourth that had not: a duplicated sentence in public/llms.txt at a named commit and line. That is the standard this project asks of everybody else, applied to it by somebody with no reason to be gentle.

What this page does not claim

  • Not customers, and not users. Nobody named here bought anything, and most of them are building something adjacent of their own.
  • Not endorsement. Every person here acted in public, several of them by disagreeing, and being listed is not agreement with anything on this site.
  • Not adoption. The threshold this project holds itself to is one production user who is not its author and who would be annoyed if it disappeared. That has not happened. Conversations come before that and are not it, and a page like this one is exactly where the distinction gets blurred if nobody states it.

If any of it was useful

Everything above was free to read and stays free: the specification, the validator, the emitter, the five framework adapters, the conformance corpus, the census rubric and the converter. The readings are CC BY, which already asks for attribution, and this is the same request made in plain words rather than in a licence file.

If a reading, a corpus case or a measurement was useful, cite it where you used it. A citation reaches people this project cannot, and it is the only thing asked for anything here. If you ran the corpus against a validator you wrote yourself, the result is worth more than a citation and worth sending either way, including when it disagrees: every correction on this page arrived that way.

https://github.com/troybrandonc-bit/machine-testimony/issues
troy@machinetestimony.com