T1

Provenance & Intent

A submission has always been read as the words of the person who sent it. Now a user can file through an agent that drafts for them, and an agency can read through an agent of its own. Nothing in the text shows how a submission was produced, or whether anyone holds the view it contains.

So two things have to be established from outside the text. The first is origin: where the submission came from and under whose authority. The second is intent: whether the words are a position the sender holds, or one an agent generated and forwarded in their name. Both have to be recorded when the submission arrives, because neither can be recovered from the text afterward. Where the agency reads through an agent of its own, it takes on a second record to keep: what that agent did with the submission it was given.

01

Policy challenge

A government channel that accepts open digital input must keep acting on what it receives, yet cannot authenticate where any submission came from, by what means, or on whose behalf.

As agent-mediated drafting and filing become ordinary, unverifiable origin shifts from an edge case to the channel's default condition. Detecting machine authorship after the fact is a losing arms race, which leaves the agency holding a duty to consider submissions it has no dependable way to trace to a person or an intent.

02

Design challenge

Capture signals about who produced a submission, how, on whose behalf, and under what authority.

Distinguish a personally held position from a forwarded one.

Make capture effective anywhere along a spectrum from pure self-attestation ("I declare") to cryptographic verification ("I can prove"), without inspecting content.

Keep the path open for anyone who can't produce the stronger signal, so capture never becomes the exclusion mechanism.

Patterns in this territory

7 shown
1.1 Frontier

Cryptographic content provenance

Binding a tamper-evident record of origin and edit history to a digital file at the point of intake. An agency can settle a question about a submission's origin from the record itself, without contacting anyone who handled the file.

1.2 Frontier

Verifiable credentials and decentralized identity

Letting a submitter prove who they are, what they're qualified for, or what authority they hold, using a portable credential an agency can check. An agency gets a claim it can check at intake, without collecting identity documents it then has to protect.

1.3 Emerging

Self-attestation and disclosure

Asking the submitter to state, in a structured way, how their submission was prepared: personally, with help, with AI tools, or on an organization's behalf. The declaration gives reviewers a preparation signal on every submission without adding work that deters honest submitters.

1.4 Frontier

Proof of personhood at submission

Confirming that a human was involved in a submission without necessarily learning who they are. A reviewer deciding what to act on can see whether a human was confirmed, and at what strength.

1.5 Frontier

Structured intake with process metadata

Capturing how a submission was put together (timing, structure, what was typed and what was pasted) as a byproduct of the intake itself, so the preparation signal itself costs the submitter no extra effort to produce. Reviewers get context on how an entry was prepared without asking the submitter for a separate declaration or proof of how they wrote it.

1.6 Frontier

Linking a person's input to the final text

Letting a submitter show how their text was built: which parts they wrote, which came from a tool or a template, and what sources fed it. Reviewers can give a submitter's own account the weight template text can’t claim.

1.7 Frontier

The attestation-verification gap

Giving an unverified declaration real weight instead of asking every submitter to prove it up front. Without something backing the declaration, an agency must either demand proof most submitters can't produce, or treat every declaration as meaningless.

Case studies that touch this territory