Criteria, 9 September 2026
A transparency log's operator can show you any tree head they like. A witness is a second party that signs the head it saw, so that showing two different heads to two different people stops being free. That is the whole mechanism. It is worth exactly as much as the witness is careful and independent, and nothing more.
These six criteria exist because three separate parties ran into the same missing thing inside a week, none of them citing the others, and none of them blocked on cryptography.
| Who | What they said |
|---|---|
| EMILIA Protocol, issue #302, July 2026 | Their reference cosigner ships and no operators run it. Standing up independent operators "costs money and needs partners", named as the lead's gate. A witness layer with no witnesses. |
| A practitioner running daily batch anchoring, on langchain-ai/langgraph#8636 | For SOC 2 and ISO 42001 audits, reviewers asked "who signs this?" before they asked anything about hash chains. A third-party signature carried more audit weight than a longer self-maintained chain. |
| An independent implementer of this project's own format | Built a separate verifier rather than trust the one that shipped with the specification, for the same reason. |
Nobody is short of a signing library. What is missing is any written statement of what an acceptable witness is, so there is no way to tell a useful one from a decorative one, and therefore no way to ask somebody to become one.
Certificate Transparency works because a browser publishes a log policy: how many logs, how independent they must be, what disqualifies one. The infrastructure was built by many parties. The policy was one document. This is that document for authorization and testimony evidence, and it is published free and Creative Commons licensed for the same reason the specification is. A rule only its author can apply is not a rule.
| The question | Why | |
|---|---|---|
| W1 | Is the witness independent of the party whose conduct the log would be evidence about? | The only one that cannot be fixed with better software. A witness run or quietly funded by the log operator produces a signature that verifies perfectly and establishes nothing, because the question a witness answers is whether a second party would notice. |
| W2 | Does it publish what its signature does and does not establish? | A cosignature will be handed to somebody in a dispute by the party it favours. If the only account of what it means comes from that party, the witness has lent its name to a claim it never made. |
| W3 | Does it verify that the head it is signing is consistent with the head it signed before? | The load-bearing one. A witness that signs whatever it is handed is a rubber stamp, and a rubber stamp with a key is worse than no witness because it manufactures the appearance of scrutiny. Refusal has to be the default: a witness that fails open turns an outage into a silent gap in exactly the period somebody later asks about. |
| W4 | Can different witnesses' cosignatures be compared, so a split view is detectable? | One witness cannot detect equivocation; it can only be lied to less cheaply. The property appears when views can be set side by side, which is why gossip exists in CT and why EMILIA built equivocation detection. A cosignature reachable only through the party it is evidence against is independence in name. |
| W5 | Can a third party verify a cosignature years later without the witness's cooperation? | A witness is a long-lived promise made by a short-lived service. If the signature stops being checkable when the service stops, the evidence had a shorter life than the obligation it was collected for, and nobody finds out until the dispute. |
| W6 | Has it said what happens when it stops? | Every witness stops eventually, and one that stops without notice makes every record anchored to it unverifiable, retroactively. Stating the terms is cheap, and the parties most eager to be a witness are the ones least likely to still exist. |
| W7 | Does the cosignature state what the witness OBSERVED, as distinct from what it received? | Added 10 September 2026, the day after these criteria were published. Two parties raised it on the same day in different repositories, neither citing the other: a proposal for bilateral signing, and the answer that a countersignature needs an observation scope, because observing the effect, observing a tool response, and receiving the signing party's assertion are different evidence sources even when one signing scheme covers all three. W2 is the negative half and is not enough: a reader holding one cosignature needs to know which of the three it is, and a policy filed elsewhere does not tell them. |
The reference witness meets W7 by admitting the weakest answer. It is handed a tree head over a network and watches nothing happen, so every cosignature it emits carries observation_scope: received and, in words, that it received the signing party's assertion and nothing more. Claiming to have observed an effect would be exactly the overclaim W7 exists to catch.
This project's own record format has the same hole. A decision entry says whether an effect is confirmed, unconfirmed or not_attempted, and nothing anywhere says on what basis. That is machine-testimony#90 and it is open.
Criteria are cheap to write and easy to write unimplementably, so spec/witness.py implements them in about two hundred lines with no dependencies. It keeps the last head it signed for a log, requires an RFC 9162 consistency proof to sign a new one, and refuses when the proof is missing, malformed, or does not verify. Missing is not treated as a lesser failure than wrong.
The proofs it is tested against are generated rather than written by hand, because a verifier checked only against fixtures its own author produced is checked against its own misreading. All 136 old and new size pairs up to sixteen leaves round-trip, and a forked tree, an absent proof, a proof of a different tree, a mangled node, a shrinking tree and an unchanged size with a changed root are each refused.
It fails W6 completely and on purpose. There is no operator, no notice period, and no undertaking that anything stays verifiable. Every cosignature it emits says so in a field of its own. It is a reference implementation in the sense that OMEM is the reference implementation of the record format: the thing that proves the rule can be followed, not the thing anybody should depend on.
Saying that plainly is the point. A witness that overstates its own durability is the failure W6 exists to name, and publishing one that quietly did so while these criteria said otherwise would discredit the criteria rather than the witness.
It is not an offer to witness anybody's log. W6 is the reason, and it is the honest one.
It is not a certification. Nothing here approves or lists a witness. The criteria are questions with published answers, and anybody may apply them, including to the reference witness above, which is why it is scored here rather than exempted.
It is not finished. W4 in particular is a property of a set of witnesses and not of any one of them, so a single witness cannot meet it however well it is built. That is stated in every cosignature the reference implementation emits.
The criteria are in spec/witness_criteria.py, the implementation in spec/witness.py, and the suite that holds them to each other in tests/tests_witness.py. If a criterion is wrong, or is met by something that should not count, that is cheap to demonstrate and it changes this page and the date on it.