Provenance & Intent
Cryptographic content provenance
Because the agency has no way to control what happens to a document before it arrives, the response signs each document where it does control it, at intake, recording the time of receipt and the submitter's identity. It records that the submission arrived and was unaltered after that point, and makes no claim about who originally authored it.
Submission received
Reference FMR-2026-00090.
We’ve signed and timestamped your files.
This records when we received your files and that no one has altered them since. It does not verify who originally wrote them.
Most files that arrive this way never carried a credential. The unsigned file is weighted no lower for lacking one.
Verifiable credentials and decentralized identity
Because a verified credential proves who is submitting but says nothing about how the submission was prepared, the response keeps the two claims plainly apart: an independently attested identity sits beside a preparation-method declaration the submitter makes themselves, cryptographically bound to that identity but not separately verified. The reader can see at a glance which claim is vouched for and which is the submitter's own word.
Strengthen your submission
Both parts below are optional. You can prove who you are, and tell us how you prepared this. Your submission is accepted either way.
From your digital wallet. Only what this consultation needs is shared.
Bound to your verified identity, but not separately checked. It is accepted as stated.
Verified input and self-declared input are shown as two labeled signals. Anonymous input is never discounted without the user being told.
Self-attestation and disclosure
Because a structured account of tool, version, task, and extent tells a decision-maker far more than a yes-or-no checkbox, the response opens with a single default for the common case and reveals the specific fields only once a submitter says they used AI assistance. Most people finish in one tap, and the detail appears only for the submissions where it informs how the entry should be read.
Did you use any tools to prepare your submission?
Proof of personhood at submission
Because personhood is treated as a gradient rather than a single gate, the response attaches a visible assurance signal to each submission (email-verified, phone-verified, or ID-verified) for the analysts who read it, instead of forcing one submit-or-don't checkpoint. A submission that clears only a lower tier still goes through, carrying a signal that tells the analyst how much weight its personhood claim can bear.
Confirm a person is behind this
This consultation asks for at least phone verification. Pick any method that meets or exceeds it, or submit without one.
Your submission will carry the signal “Phone-verified” to the analysts who read it.
Every submission carries its signal, including “not established”, which means accepted and weighted for review, never dropped. The weighting applied to each tier is published, and the signal is never color alone.
Structured intake with process metadata
The response is a guided intake that records timing and paste patterns as the submitter works. When it detects a paste, it offers a prompt ('Looks like you pasted from another source. Want to note where it came from?') the submitter can answer or skip. The information is gathered as a byproduct of building the submission, never as a gate the submitter must clear.
We record how this form is filled in: timing and paste events, not what your words say.
No content is analyzed, only how the submission was built. A free-text submission carries less of this.
Linking a person's input to the final text
Because disclosure works here as a norm rather than as enforcement, the response is a voluntary 'Add a source to this part' control and a provenance note in the submitter's own words, never recorded by the system. The plain declaration ('I wrote this myself, based on my own experience') is the one affirmative act — Submit stays inactive until it is selected — and stays the fastest route to submit. Choosing not to show your working costs no extra steps.
Review and submit
Check your submission below. Showing your working is optional. You can submit as soon as you’re ready.
The proposed levy will fall hardest on long-term residents on fixed incomes. My pension has not moved in two years, and an added charge of this size is not something I can absorb.
I would support the plan if the foreshore path were kept step-free the whole way. As a wheelchair user, the current route is the only one I can take to the shops.
Described by you, not recorded by the system. Included with your submission only if you choose to share it.
The plain declaration sits first, and selecting it is an affirmative act: Submit stays inactive until a declaration is made. Showing your working is never required to submit.
‘Add a source’ and the provenance notes work with a keyboard and a screen reader, and skipping them adds no extra steps. Nothing in the interface suggests that a missing note is suspicious.
The attestation-verification gap
Because an attestation only carries weight when it can be checked later or is backed by consequence, the response makes the declaration binding without verifying it up front. It ties each submission to an identity, where even a pseudonym is enough to catch a pattern of false attestation after the fact, and scales the consequence to what the process decides: informal reputational discounting for an ordinary comment, formal sanction for a royal-commission or planning submission. The request is framed as a norm ('most people tell us how their submission was prepared'), not a penalty under threat, and a verified-identity slot sits ready for the same form to switch on as a verified government digital ID becomes available.
How was this prepared?
Most people tell us how their submission was prepared.
The two ways to sign are drawn as peers: same size, same weight, no badge or check marking the verified path as better.
The verified-identity slot appears only in the formal proceeding, where it is wired but inactive: labeled for a verified government digital ID and marked unavailable. There the binding declaration must be checked before signing. The control above previews that version.
No surfaces match this filter.