Limits of a signed verdict
The exact boundary of the primitive: what the signature covers, and the two fields it does not.
A signed verdict proves one thing: the holder of the signing key evaluated this specific request at this specific moment and returned this specific answer. Everything a counterparty concludes beyond that is an inference, and some of those inferences are wrong.
This page exists because a guarantee that is assumed rather than stated is the one that fails in production.
What the signature covers
The claims inside the token, and nothing else:
{
"iss": "https://verdicts.saifuro.com",
"jti": "dec_5b2e",
"iat": 1788424980,
"exp": 1788425280,
"verdict": "allow",
"mandate": "mnd_7f3a",
"policy_version": "pol_2026-08-12.1",
"nonce": "n_9d02c6e4",
"request": {
"agent": "agt_procurement_01",
"amount": 340,
"recipient": "vendor:acme_saas",
"category": "saas"
}
}Two fields that are not in there
Currency is not signed. The echoed request carries agent, amount, recipient and category — and no currency. A verdict for 340 does not distinguish 340 USD from 340 JPY. If you accept verdicts, you must check the currency against your own order and not against the token, and you must treat a mismatch as a refusal.
There is no aud claim. Nothing in the token names who it was issued for. The field that binds a verdict to a counterparty is request.recipient, which is a string your integration agrees with the operator. Compare it exactly. A verdict is not addressed to you merely because it arrived from you.
Both are stated here rather than left to be discovered, and both are candidates for a future version of the token — which would be a versioned change, announced, not a silent addition.
What the verdict does not tell you
It is not a payment. No money moved because a verdict says allow. Settlement happens on your rails, afterwards, and can still fail.
It is not proof of funds. The policy engine evaluates authority, not balances.
It is not an identity assertion. request.agent is an identifier the operator assigned. The signature says Saifuro evaluated a request naming that agent; it does not attest to who or what is behind it.
It does not carry the enforcement mode. Whether the operator's environment was blocking at the time is recorded on the decision, not in the token. A signed deny from an environment in observe mode looks exactly like one from an enforcing environment.
It is not evidence that the rule still holds. It is evidence about one moment. A mandate can be revoked a second later.
Expiry applies to denials too
Every verdict carries exp = iat + 300, five minutes, including refusals. A denial does not become an approval when it expires — an expired token simply stops being a valid statement about anything, and your verifier should reject it rather than reading the verdict field out of an expired envelope.
The rule that follows from all of this
Verify the signature, then check the token against your order: amount, currency, recipient and freshness. The signature tells you the statement is authentic. Only your own record tells you it is the statement you needed.
The mechanics of doing that are on verifying a verdict.

