A system reporting its own health is not evidence. It is a claim, and a claim made by the thing under examination. This is a note about what has to change for that claim to become checkable by a stranger — and about an organism of ours that had been dead for twenty days while its heartbeat quietly said so to nobody at all.
An earlier review of our operator design produced a finding we have not been able to un-see. The gate kept an append-only ledger, and the original design witnessed that ledger by pushing it to a git remote with a credential kept on the same machine, under the same operator — a mirror, not a witness.
That is not a subtle flaw. Anything able to write the ledger sat on the same machine as the thing able to write the proof that the ledger was fine. The condition that came out of that review was blunt: the witness must be independent of the credential that writes it.
The shape that satisfied it: the gate computes its ledger head — a sequence number and a hash — and a separate process carries that head off the machine to a canister running on the Internet Computer, using a credential the gate never holds and cannot read. The gate can write its ledger. It cannot write the record of where its ledger stood.
That canister is public. Which means the interesting property is not that we can check it — it is that you can, right now, without asking us and without trusting us. The panel below is reading it from your browser as this page loads.
One precision worth keeping, because it is the difference between a true claim and a flattering one: the machine composes its own beat, so what the canister gives a stranger is non-repudiation of what that machine said the head was at a given time, plus liveness. It cannot vouch for the content of the report. What it makes impossible is quietly rewriting that report afterwards.
If this panel shows "cannot verify", that is the honest state — it means your browser could not reach the canister, which is not the same as the organisms being down.
Most systems stop climbing somewhere on this ladder and describe themselves as if they had reached the top. Select a rung to expand it.
The attestation happens every thirty minutes. The gate chains its own records within seconds, but the independent witness only pins the head on each beat.
So the guarantee is precisely: "the head was X as of the last beat." Not continuous attestation. At any given moment, up to half an hour of ledger writes may exist that no outside party has yet seen.
Two sentences that sound identical in a status report: "the ledger head is witnessed off-box" — true. "the ledger cannot be tampered with undetectably" — false, within that window. We wrote the window into the governing ruling rather than rounding it away, because a condition claimed closed is worse than one honestly open: the first stops anyone looking.
Here is the part that should not be skipped. While building all of this, we ran the same public read you can run above — and found one of our own organisms marked stale for roughly twenty days. A cloud service had scaled to zero. Its nightly backup job had been running the whole time, failing, and logging that failure to a file nobody opened. The most recent backup was six days old on a schedule that claimed to run daily.
The heartbeat had been reporting this accurately since the moment it happened. Nothing was broken about the witness. Nobody was reading it.
The same audit turned up six scheduled tasks on the operator machine whose only failure signal was a result code no process consumed — until a watcher was added and proven by breaking a task on purpose. It also surfaced a latent syntax error that had been masked for days behind a different error that fired first. The watcher now turns any failed task into a ledger record, but the part that mattered was the acceptance test: a watcher that has never caught anything is indistinguishable from a watcher that does not work.
One detail we would repeat. Rather than accept the operator machine's report that its ledger had advanced, the build session on the second machine wrote down a falsifiable prediction in advance — the next beat must carry a sequence number at or above this value — and then polled the public canister until it either happened or didn't. It happened, and the number matched the exact record the other session had described.
The value is not in the confirmation. It is that the disconfirming result had somewhere to go. A prediction only counts if you commit to reporting it when it fails, and the cheapest way to keep yourself honest is to write the threshold down before you look.
You can watch the same signal on the live attestation ledger, including the organisms currently marked stale. We publish those rather than filtering them, for the reason this whole note is about. The governance side of the same evening is Transmission 34.