MIZ OKI 3.5
Menu

What is a ValidationPassport?

PARTIALLast reviewed 2026-09-15 · Review due 2026-12-01 · Owner: MIZ OKI product

Direct answer

A ValidationPassport is the sealed evidence record a governed decision carries: which validation checks ran and passed, the pass rate, how many hypotheses were tried, the consent basis, model and contract versions, and a hash that makes later tampering detectable. Passports chain per tenant so an auditor can verify the series. Capability label: [PARTIAL].

Why decisions need passports

Attribution figures are claims; passports are evidence. The distinction matters more as the money and the automation grow: US internet advertising revenue reached $258.6B in 2024, up 14.9% (IAB / PwC, Apr 2025), and Gartner expects 15% of day-to-day work decisions to be made autonomously through agentic AI by 2028, up from 0% in 2024 (Gartner, Oct 2024). Enterprises adopting that automation already report that trust and risk controls are the sticking point: over 40% of agentic AI projects are forecast to be cancelled by the end of 2027 (Gartner, Jun 2025).

A passport answers the question a finance or compliance reviewer actually asks — not "did the model recommend it?" but "what was checked, what passed, on what data, under what consent, and can I prove none of that was edited afterwards?"

What a passport contains

The passport is one of the platform's closed set of eight decision objects — no ninth object and no private variant may be defined. Its fields:

Around the sealed per-path passport sits the passport package: a read-model that assembles the decision's whole trace — signals used, model versions, refutation results, confidence, consent basis, realised outcome — and reports honestly which fields have no persisted source rather than inventing them. Each persisted package links to the tenant's previous one, and a chain-walk endpoint verifies a tenant's entire series.

What the passport does not claim

What is shipped today — honestly

FAQ

Is a ValidationPassport a blockchain?

No. It is a hash-sealed record in an append-only ledger with a per-tenant hash chain. There is no distributed consensus and no token; the chain exists so an auditor can detect a rewritten history, nothing more.

Who can read a passport?

The tenant it belongs to, through authenticated console and API routes, and the platform's audit-replay service. Raw secrets, personal identifiers and forbidden signal types never enter a passport by schema.

Does a passport prove the ad worked?

No. It proves what was validated before the decision and links to the outcome record afterwards. Whether the ad caused revenue is a separate, holdout-based measurement recorded in the causal credit ledger.