Job to be done
Share enough evidence to review a workflow claim without publishing private project inputs.
Required inputs
- Private project snapshot
- Proposed public claims
- Consent records
- Evidence manifest
- Redaction decisions
Procedure
- Keep raw prompts, artifacts, employer names, student records, customer data, credentials, and confidential inputs private.
- Write each proposed public claim as one bounded factual statement.
- Attach the measurement, method version, issuer, observation date, source location, and evidence hash for that claim.
- Classify the evidence as independent, jointly verified, or author controlled.
- Run direct-identifier, quasi-identifier, consent, confidentiality, and claim-scope checks.
- Require a reviewer to approve, request changes, reject, or withdraw the exact hashed version.
Outputs
- Sanitized summary
- Claim-to-evidence ledger
- Consent manifest
- Privacy checklist
- Version hash
- Reviewer decision
Publication gate
A result remains private or draft until every applicable gate passes.
- No raw private inputs
- No secrets or credentials
- Every claim has a source
- Evidence independence is labeled
- Consent is explicit
- Exact reviewed version is hash-bound
Limitations
- Hashing supports integrity, not truthfulness.
- Redaction can still leave identifying combinations.
- A proof pack is not independent merely because a reviewer reads it.
Sources and prior-art context
These sources inform the working synthesis. Their inclusion does not imply endorsement.
- NIST AI Risk Management Framework - National Institute of Standards and Technology
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile - National Institute of Standards and Technology
- Artificial Intelligence: An Accountability Framework for Federal Agencies and Other Entities - U.S. Government Accountability Office
Change history
- 2026-08-25 - Published the first privacy-safe submission schema and evidence-tier labels.