11 — Observability
Summary
The layer that answers a question this site raised in four places and answered in none: a mandate says what an agent may be authorised to do, not what it does — so who is using it? The answer refuses the question. What is capturable is verification, not use, and the two come apart both ways: a party that uses a mandate without verifying generates nothing, and the party that never verifies is the party whose relying process is weakest. So the product is the missing edges — who holds a mandate I issued and has never once checked it — a join the issuer can compute because it holds both halves. Where the log lives decides everything: a central check log accumulates who is evaluating whom across parties that never consented; a check event written into the issuer's own lane is an owner observing their own asset. And revocation latency becomes measurable before anything is ever revoked.
Key concepts
- A verification is not a use — the four places this site says a mandate does not observe behaviour — all still true
- The gap is the finding — the third list of absences in this pack, and again the actionable half
- Where the log lives — C14: rule 1 applied to telemetry resolves C9 rather than contradicting it
- Effective revocation latency — the interval between a party's checks, computable before anything is revoked — and one of the very few decidable mandate clauses
Key ideas
- Without check events, declared mandates produce no evidence — which would make the pack's own justification for building them indefensible.
- The design that protects the positioning is the design that destroys the dataset, and it should be chosen deliberately rather than discovered later.
- Draining the lane is an obligation that fails silently: an issuer who stops draining stops receiving evidence without being told.
- This is where the badge's “last checked” field comes from — the observability layer is the interface's evidence, not a second dashboard.