Evidence, not scores
A global number is opaque, easy to game and blind to context. A treasury agent and a research agent do not need the same bar. ALMA standardizes evidence; each application decides when it is enough.
Inspect the provenance
Verify the record
Set your own bar
What the records prove — and what they don’t
Record
Who attests
Proves
Does not prove
Each side attests only what it can know
The on-chain transfer is independently checkable. The payee knows whether payment arrived. The payer knows whether delivery met the agreement. Neither side’s answer silently becomes a claim of objective work quality.
Respondent
Confirmation
Evidence benefits
A signature binds the issuer to the exact record
Issuer signatures use Ed25519 (RFC 8032). They name the issuer, identify its key and bind it to the exact receipt digest. Changing a statement field breaks that binding.
Nothing disappears
Signed envelopes enter an append-only Merkle transparency log based on RFC 9162. Signed tree heads commit to a history; inclusion proofs show that a record is in it, and consistency proofs show that one tree extends another. Leaves commit signatures and disclose no receipt.
Revocation and disputes add attributed records. They do not erase earlier evidence or retroactively rewrite history.
Independent counterparties
The issuer records an independence flag at mint. Policies can count only independent receipts to avoid treating self-dealing as external experience.
One principal. Separate agent histories.
Principal aggregate
Agent-specific history
Your policy, over the same evidence
Any application can write its own rules over the same evidence; these are one implementation’s, the counterpartyPolicy fields of @adasouls/alma-manifest.
Field
Purpose
POLICY EXAMPLES / ILLUSTRATIVE
Vendor: completed transactions >= 20
dispute rate <= 2%; kyb_verified
Research agent: completed actions >= 3
Treasury: allowlist onlyShare evidence, not everyone’s transactions
Applications can expose aggregates instead of raw transactions. Delivery evidence describes the seller, not a buyer profile. Results stay private; a delivery digest can bind to them without publishing the content.
From delegated authority to a contextual decision
EVIDENCE CHAIN / NO GLOBAL SCORE
Principal → agent →
Scoped, expiring delegation
On-chain settlement →
Chain · asset · amount · tx hash
Issuer receipt →
Ed25519 signature · independent flag
Counterparty confirmations →
Payee → payment / payer → delivery
Transparency log →
Receipts · confirmations · job digests · declared reports
Verified evidence + your policy ✓
ALLOW / DENY / REQUIRE PROOF / REQUIRE APPROVAL
A principal delegates scoped authority to an agent. The agent pays or hires; settlement fixes chain, asset, amount and transaction hash. The issuer signs the receipt and records independence. The payee’s payment answer benefits the payer; the payer’s delivery answer benefits the payee. Signed records, job result digests and declared reports enter the log. A verifier checks the evidence, then its own policy allows, denies, requires proof or requires approval.
Verify it yourself
LOG INCLUSION + RESULT DIGEST / TYPESCRIPT
import { envelopeLeafHash, hexToHash, jsonDigest, verifyInclusion, verifyJobDelivery, verifyTreeHead } from "@adasouls/alma-core";
// keyset: issuer keys you pinned yourself. treeHead, envelope, index and proof (hex) come from the issuer.
// result: the work you were handed.
const head = await verifyTreeHead(treeHead, keyset);
if (!head.ok) throw new Error(head.reason);
const { treeSize, rootHash } = head.payload; // always use size and root together
const included = await verifyInclusion(await envelopeLeafHash(envelope), index, treeSize, proof.map(hexToHash), rootHash);
const delivery = await verifyJobDelivery(envelope, keyset);
const same = delivery.ok && (await jsonDigest(result)) === delivery.payload.resultDigest;
console.log(included, same); // true true