Provenance & Intent
Cryptographic content provenance
The agency signs each document at the moment it arrives, so the record proves the submission was unaltered after receipt without claiming who wrote it.
Submission received
Reference FMR-2026-00090.
We’ve signed and timestamped your files.
This records when we received your files and that no one has altered them since. It does not verify who originally wrote them.
Most files that arrive this way never had a credential. The unsigned file is weighted no lower for lacking one.
Verifiable credentials and decentralized identity
An independently attested identity sits beside a preparation-method declaration the submitter makes themselves, so a reader can tell which claim is vouched for.
Strengthen your submission
Both parts below are optional. You can prove who you are, and tell us how you prepared this. Your submission is accepted either way.
From your digital wallet. Only what this consultation needs is shared.
Bound to your verified identity, but not separately checked. It is accepted as stated.
Verified input and self-declared input are shown as two labeled signals. Anonymous input is never discounted without the user being told.
Self-attestation and disclosure
Disclosure opens as a single default for the common case, and asks for the tool, the version, and the extent only from submitters who used AI assistance.
Did you use any tools to prepare your submission?
Proof of personhood at submission
Personhood is treated as a gradient, attaching a visible assurance tier to each submission rather than forcing a single submit-or-don't checkpoint.
Confirm a person is behind this
This consultation asks for at least phone verification. Pick any method that meets or exceeds it, or submit without one.
Your submission will show the signal “Phone-verified” to the analysts who read it.
Every submission shows its signal, including “not established”, which means accepted and weighted for review, never dropped. The weighting applied to each tier is published, and the signal is never color alone.
Structured intake with process metadata
Sectioned intake fields gather how a submission was built as a byproduct of writing it, never as a gate the submitter has to clear.
We record how this form is filled in: timing and paste events, not what your words say.
No content is analyzed, only how the submission was built. A free-text submission has less of this.
Linking a person's input to the final text
Showing your working is offered as a voluntary norm rather than enforced, so a submitter who chooses the plain declaration pays no extra steps.
Review and submit
Check your submission below. Showing your working is optional. You can submit as soon as you’re ready.
The proposed levy will fall hardest on long-term residents on fixed incomes. My pension has not moved in two years, and an added charge of this size is not something I can absorb.
I would support the plan if the foreshore path were kept step-free the whole way. As a wheelchair user, the current route is the only one I can take to the shops.
Described by you, not recorded by the system. Included with your submission only if you choose to share it.
The plain declaration sits first, and selecting it is an affirmative act: Submit stays inactive until a declaration is made. Showing your working is never required to submit.
‘Add a source’ and the provenance notes work with a keyboard and a screen reader, and skipping them adds no extra steps. Nothing in the interface suggests that a missing note is suspicious.
The attestation-verification gap
The declaration is made binding after the fact rather than verified up front, tying each submission to an identity and scaling the consequence to what the process decides.
How was this prepared?
Most people tell us how their submission was prepared.
The two ways to sign are drawn as peers: same size, same weight, no badge or check marking the verified path as better.
The verified-identity slot appears only in the formal proceeding, where it is wired but inactive: labeled for a verified government digital ID and marked unavailable. There the binding declaration must be checked before signing. The control above previews that version.
No surfaces match this filter.