Build evidence without declaring it to be truth
ENTITY can record signed attestations and evaluate explicit trust policies while preserving a critical boundary: an attestation is evidence, and satisfying a policy is not the same thing as proving objective truth.
1. Hash the evidence you actually observed
evidence_sha256 = sha256(report_bytes).hexdigest()
The evidence can be a lab report, external registry response, sensor bundle, certificate, upstream CI result or another verifiable artifact. Keep the underlying artifact according to its own retention/privacy requirements.
2. Create an attestation
att = fabric.attest(
attestor_entity_id=lab_entity_id,
subject_ref=sample_object_id,
claim_type="QUALITY_TEST",
evidence_sha256=evidence_sha256,
claim={"result":"PASS", "method":"example-v1"},
)The signed record deliberately carries attestation_is_evidence_not_truth=true.
3. Define the trust rule explicitly
policy = fabric.create_trust_policy(
controller_entity_id=owner_id,
claim_type="QUALITY_TEST",
minimum_attestations=2,
required_attestors=[lab_a_id],
allowed_attestors=[lab_a_id, lab_b_id, lab_c_id],
)This means “for our application, this claim class is acceptable when at least two valid, allowed attestations exist and Lab A is one of them.” It does not mean ENTITY has discovered universal truth.
4. Evaluate the policy
result = fabric.evaluate_trust(
policy["policy_id"],
sample_object_id,
)
print(result["policy_satisfied"])The evaluation verifies attestation signatures, filters disallowed/duplicate attestors and reports whether the threshold and required-attestor conditions are satisfied. The result explicitly reports truth_inferred=false.
5. Test the failure modes
- Only one attestation exists when the threshold is two.
- A required attestor is absent.
- An attestor is not in the allowed set.
- An attestation signature or evidence commitment is invalid.