# Decision evidence, version 1 New-format decisions carry a reproducible financial assessment and a frozen source bundle. Model results carry references to application-visible requests, responses and attempt journals kept in restricted storage. Historical records retain their original format; we do not manufacture missing transcripts. These are server-originated records. Their hashes do not independently prove that a model provider returned a response, that a source was truthful, or that an agent reasoned honestly. Publication anchors make later changes detectable. Safe execution still requires human signatures. ## Read a decision Open `/evidence.html?id=PROPOSAL_ID`. The page shows the budget, scenarios, source classifications, claim links and limitations. Download the JSON from `/api/proposal/evidence?id=PROPOSAL_ID` to check it locally: ```text node scripts/decision-evidence.js verify saved-evidence.json node scripts/verify-proposal.js closed-record.json node scripts/decision-evidence.js verify-record cycle-bundle.json ``` An offline pass does not check the chain. The proposal verifier separately supports `--rpc URL --registry ADDRESS`. Authorized reviewers with a restricted copy may additionally use `--evidence-vault PRIVATE_VAULT` with the proposal or cycle verifier, or supply the vault as the final argument to `decision-evidence.js verify-record`. Public receipt checks validate structure and links, not unavailable originals. Restricted verification recomputes artifact hashes, journal chains and selected parser results, and compares applicable published ballot/review/work fields. An unknown provider outcome stays unknown. An expired or missing original is not equivalent to a verified response. Forecast verification does not prove that revenue will materialize or that cash has been reserved. ## Financial rules Version 1 supports ETH (18 decimals), USD (2), and USDC (6). Amounts use exact integer strings, never floating-point monetary arithmetic. A dated rational exchange rate explicitly converts source minor units to target minor units. Funding rounds down; converted costs round up. Scenario revenue is already expressed in the assessment's base currency. Every spending assessment explicitly lists funding, existing commitments, external costs, work-fee allowance and contingency, including explicit zeroes. Funding must have a recorded check, authorization and a unique resource reference. Obligations cannot appear twice. The mandate's work-fee allowance must equal its frozen `budgetWei`; it does not redefine that contract. - Available funding = current funding minus unpaid/reserved commitments. - Required funding = unpaid external costs + unpaid work fees + contingency. - Headroom = available minus required; a negative result is a shortfall. - Scenario net = projected revenue minus economic costs, scenario contingency used and any additional variable cost per unit. - Paid costs remain economic costs but are not deducted from cash a second time. - Break-even units use ceiling division over a positive unit margin. Unknown revenue and zero/negative margins produce an unavailable result. If unit costs are supplied in a scenario, they are additional to the fixed expense lines; do not include the same variable expense in both places. Contingency is reserved capacity, not an incurred expense. Forecasts never become ledger revenue or directly determine fees or commission. Technical incompleteness blocks an evidence-complete freeze. A valid shortfall, negative forecast or disputed source is disclosed; it does not change quorum, majority, ties or create an automatic AI veto. Approvers must recheck current resources and competing commitments before preparing real spending. ## Sources and freshness Source classes have versioned warning thresholds: balances, commitments and exchange rates 15 minutes; prices 7 days; supplier capabilities and market figures 30 days. Accounting documents and delivered work describe historical events and have no automatic age expiry, but explicit document expiry and contradictions still matter. A budget line using an extended freshness limit must state why. These are warning policies, not authorization to spend. Claims are source-supported, estimated, assumed, disputed or missing. A supported claim identifies the recorded checker and basis; this is not an independent truth certification. Public excerpts have their own hashes and copy/redaction limitations. Originals may be restricted or unavailable. A URL alone is not an archived source. Provider-returned search metadata and fetched documents are distinguished from independently acquired originals. Source material is untrusted data. Instructions inside it do not grant tools, authority or permission to disclose private information. The upload command ingests local text; it does not fetch arbitrary URLs or internal services. Corrections create a new bundle naming `supersedes` and `correctionReason`. Frozen decisions and their original sources are not overwritten. ## Attempts and retention The recorder saves each application request before dispatch and saves returned content before selecting a result. It records refusals, rejected schema results, requested/reported fallbacks, errors, retries and continuations. Transport credentials are excluded. Hidden provider reasoning, provider-internal retries and unavailable transport data are outside the capture boundary. Stream events are flushed in batches of at most 256 events or 64 KiB, and on normal/error completion. A hard process crash can lose the last unflushed partial batch. Such an attempt remains unresolved and cannot supply an accepted result. Completed accepted responses must be fully saved. A timeout is not evidence that the provider did no work or billing. Selection means the application selected a parsed result. It does not mean that a holder approved it, that a vote passed, or that the Safe executed it. Business records separately carry the response references and the outcome. The cycle bundle includes an attempt manifest so failures are not hidden by publishing only successful responses. Restricted model transcripts and source originals are retained for 12 months after their related cycle closes. Backups expire within 30 additional days; the configured local backup rotation is 14 days. Public decision records remain. Accounting/legal records requiring longer retention must be held separately. Open cycles require an explicit close before the retention clock begins.