Skip to content
Assay
Sign inTalk to us

Assay · System documentation

How a decision report works

What a buyer sets up

The journey of a report

Five stages. The middle one is a gate: evidence that does not verify stops here, and the request is recorded as failed rather than answered weakly.

  1. Requested A buyer asks for an assessment of a target. The request records what is being assessed and which bar version applies, so the question the report answers is fixed before any evidence is seen.
  2. Evidence fetched The signed measurement for that target is pulled from the registry. If none is reachable — none exists, or access has not been granted — the request ends here and is recorded as evidence-unavailable. That is a distinct outcome from failing the bar.
  3. Verified Two checks, both of which must pass: the signature is authentic, and the verdict in the evidence reproduces when re-derived independently. Evidence that fails either is refused, and the request is recorded as verification-failed. This is the stage that makes the rest worth anything. Without it, a report would be repeating whatever it was handed.
  4. Built The verified evidence is checked against the bound bar and the report is composed: the verdict, the scores as signed, and the reasoning connecting them.
  5. Delivered The artifact is frozen and stored exactly as issued, along with a record of which evidence it was built from. A report can therefore be re-read, and audited, long after the fact.

When a report is not produced

Two failure outcomes are recorded distinctly, because they mean different things to a buyer:

  • Evidence unavailable — nothing to assess. No measurement exists for the target, or it has not been shared with this buyer.
  • Verification failed — evidence exists but could not be trusted. It is refused rather than reported with a caveat.

Neither is a low score. A buyer who cannot get evidence has a different problem from a buyer whose supplier scored badly, and the system does not blur the two.