VERIFIER
Review and signature within the grant
The verifier portal (/portal) is grant-scoped: the accredited verifier downloads and reviews the sealed evidence packages the installation operator has opened. No write access to the ledger is given.
Installation
Sample Plant
Only packages under a live grant stay in the queue; when the grant ends the row leaves it.
The portal publishes in Turkish and English; the language preference belongs to the person.
GRANT SCOPE
Access per package
Access extends as far as the installation operator has opened it. A grant is per package; it expires and it can be revoked.
WHAT THE GRANT GIVES
- The sealed package's chain: claim, sources, method, lineage.
- Download of the sealed package as JSON; the download is written to the audit log.
- Signing an attestation, and the history of signed attestations.
WHAT THE GRANT DOES NOT GIVE
- Writing to the ledger: changing a measurement or a calculation.
- Records the grant does not cover.
- Access to an expired or revoked package.
TRACEABILITY
The chain from claim to seal
Each stage binds to the next; the chain ends in a single seal root.
- 01claimed
Claim
The declared output value and unit in the sealed calculation.
- 02sources
Sources
The measurement records and declaration references carried in the package.
- 03methodologyPack
Method
The full methodology pack body, in place of a registry alias.
- 04seal
Seal
The seal root binding the leaves stored at the moment of sealing.
LEAVES IN THE SEAL
The leaves that make up the seal
The four leaves and the seal root can be recomputed from the package's embedded content.
A digest field with no document bytes does not count as L1 for supplier, invoice, calibration or monitoring types.
SEAL ROOT
sha256:bee6d1edb484827bc0df35f81ea271bd30fc033537d8c9a9e04e4863482e937d
The panel is rebuilt for this page; its values are read from the synthetic sample package.
DECISIONS
Download, signature and opinion
Download
The sealed package is downloaded as JSON; the download is written to the audit log.
dahlia-verification-1
Signature
The private key stays on the device; the server verifies the signature.
Ed25519
Opinion fields
The opinion is signed in one envelope; the envelope carries the package's seal root. An envelope with one character changed is rejected.
merkleRoot
The final verification decision is made in the product interface, with its own confirmation step.
The download is written to the audit log; the signed opinion is stored in the database.
THE LANGUAGE OF EVIDENCE GAPS
Evidence gaps and default values
Without a supplier declaration the calculation falls back to the default value with its mark-up; the mark-up's legal basis is written into the lineage as a note.
- A field that fell back is a methodology default, not a source record.
- A correction arriving after the knowledge time is a separate record; no silent update is made.
IN THE SAMPLE PACKAGE
cbam/aluminium-extrusion
SEALED INPUTS
- Doğal gaz tüketimi (biyet ısıtma + yaşlandırma fırını)18.400 Sm³
ledger
- Girdi alüminyum biyet kütlesi24,1 t
erp
- Üretilen profil kütlesi22,4 t
erp
The interface is in English. Labels read from the sealed package remain in Turkish: those bytes are part of the evidence a customer verifies, and translating them would change the seal.
THE LIMIT OF THE SIGNING KEY
A signing key that stays with the person and never touches the server
A verifier's attestation private key is bound to the person: it stays on the verifier's own device, never reaches the network and is never written to browser storage. The server only verifies the signature.
WHAT SITS ON THE SERVER
The public key, and verification of the signature
WHAT SITS WITH THE PERSON
The private key, and the signing itself
At signing time the key file is chosen from the device and imported in the browser; only the signature itself is written into the form.
Holding the key on the server would mean DAHLIA could sign on anyone's behalf. That option was considered and rejected.
The verifier portal
The verifier reads the packages covered by the grant and signs the opinion with their own key, which never touches the server.