Authorization evidence and independent witnesses
Luvion produces evidence for the complete authorization decision, not only a signature result. A reviewer should be able to determine what operation was requested, which policy applied, who approved it, which threshold authorized it, and whether the final execution matched the approved intent.
Authorization certificate
The certificate binds at least:
- the canonical intent and request identifier;
- the policy version and policy decision;
- separated approvals and eligible roles;
- the participant set, threshold, key identifier, and key epoch;
- the session transcript digest and final backend output;
- the validity window and replay boundary; and
- the target execution adapter or module.
Evidence bundle
The evidence bundle can include policy reasons, approvals and rejections, authorization transcripts, execution or validation receipts, aborted attempts, retry and reconciliation records, and the final intent-execution comparison.
An adapter must distinguish provider acceptance, transaction broadcast, and confirmed finality. A signature or PKP receipt must never be represented as an executed onchain operation.
Independent witness
An independently administered witness can sign and retain terminal receipts. Hash-linked records and witness reconciliation make silent local deletion or rollback detectable.
Controlled validation currently covers deterministic evidence export, signed witness receipts, retry behavior, restart recovery, and rollback detection. Production evidence requires separately administered retention-locked or WORM storage, documented retention policy, monitoring, recovery drills, and partner acceptance.