VERIFIER

Review and signature within the grant

The verifier portal (/portal) is grant-scoped: the accredited verifier downloads and reviews the sealed evidence packages the installation operator has opened. No write access to the ledger is given.

REVIEW QUEUE/portal

Installation

Sample Plant

PeriodMarch 2027
Sealed at1 October 2027
Seal rootbee6d1…937d
AccessWhile the grant lasts

Only packages under a live grant stay in the queue; when the grant ends the row leaves it.

The portal publishes in Turkish and English; the language preference belongs to the person.

GRANT SCOPE

Access per package

Access extends as far as the installation operator has opened it. A grant is per package; it expires and it can be revoked.

WHAT THE GRANT GIVES

  • The sealed package's chain: claim, sources, method, lineage.
  • Download of the sealed package as JSON; the download is written to the audit log.
  • Signing an attestation, and the history of signed attestations.

WHAT THE GRANT DOES NOT GIVE

  • Writing to the ledger: changing a measurement or a calculation.
  • Records the grant does not cover.
  • Access to an expired or revoked package.

TRACEABILITY

The chain from claim to seal

Each stage binds to the next; the chain ends in a single seal root.

  1. 01claimed

    Claim

    The declared output value and unit in the sealed calculation.

  2. 02sources

    Sources

    The measurement records and declaration references carried in the package.

  3. 03methodologyPack

    Method

    The full methodology pack body, in place of a registry alias.

  4. 04seal

    Seal

    The seal root binding the leaves stored at the moment of sealing.

LEAVES IN THE SEAL

The leaves that make up the seal

The four leaves and the seal root can be recomputed from the package's embedded content.

DOWNLOADED FORMATdahlia-verification-1

A digest field with no document bytes does not count as L1 for supplier, invoice, calibration or monitoring types.

THE SAMPLE PACKAGE'S LEAVESSHA-256
Methodology pack056d84…1a41
Input set313143…e9c9
Lineage4f29e3…c84a
Source records9d336d…4aad

SEAL ROOT

sha256:bee6d1edb484827bc0df35f81ea271bd30fc033537d8c9a9e04e4863482e937d

The panel is rebuilt for this page; its values are read from the synthetic sample package.

DECISIONS

Download, signature and opinion

Download

The sealed package is downloaded as JSON; the download is written to the audit log.

dahlia-verification-1

Signature

The private key stays on the device; the server verifies the signature.

Ed25519

Opinion fields

The opinion is signed in one envelope; the envelope carries the package's seal root. An envelope with one character changed is rejected.

merkleRoot

OPINION VALUESNo adverse findingsunqualifiedQualifiedqualifiedAdverseadverse

The final verification decision is made in the product interface, with its own confirmation step.

The download is written to the audit log; the signed opinion is stored in the database.

THE LANGUAGE OF EVIDENCE GAPS

Evidence gaps and default values

Without a supplier declaration the calculation falls back to the default value with its mark-up; the mark-up's legal basis is written into the lineage as a note.

  • A field that fell back is a methodology default, not a source record.
  • A correction arriving after the knowledge time is a separate record; no silent update is made.

IN THE SAMPLE PACKAGE

cbam/aluminium-extrusion

Unsourced inputNone

SEALED INPUTS

  • Doğal gaz tüketimi (biyet ısıtma + yaşlandırma fırını)18.400 Sm³

    ledger

  • Girdi alüminyum biyet kütlesi24,1 t

    erp

  • Üretilen profil kütlesi22,4 t

    erp

The interface is in English. Labels read from the sealed package remain in Turkish: those bytes are part of the evidence a customer verifies, and translating them would change the seal.

THE LIMIT OF THE SIGNING KEY

A signing key that stays with the person and never touches the server

A verifier's attestation private key is bound to the person: it stays on the verifier's own device, never reaches the network and is never written to browser storage. The server only verifies the signature.

WHAT SITS ON THE SERVER

The public key, and verification of the signature

WHAT SITS WITH THE PERSON

The private key, and the signing itself

At signing time the key file is chosen from the device and imported in the browser; only the signature itself is written into the form.

Holding the key on the server would mean DAHLIA could sign on anyone's behalf. That option was considered and rejected.

The verifier portal

The verifier reads the packages covered by the grant and signs the opinion with their own key, which never touches the server.