Research initiative · trust infrastructure

What if trust could be proven?

IRIS Protocol explores a model of digital trust in which what an organization declares stays linked, over time, to verifiable evidence.

The core transition

Research model
  1. Declaration

    “We operate according to this policy.”

  2. Evidence

    What actually happened, captured at the source

  3. Continuity

    Every event extends the history instead of overwriting it

  4. Trust

    The declaration remains provable over time

Evidence firstProvenance over timeNo overwritesContinuous verification
01The trust gap

An organization declares itself compliant.
How do we know it still is?

Organizations continuously generate activities, documents, decisions and controls. The challenge is keeping what they declare connected to what actually happens, over time.

  1. 01

    The policy declares

    A requirement, a commitment or a control is declared.

  2. 02

    Operations happen

    People, software and AI systems act every day.

  3. 03

    Time passes

    Systems, models, dependencies and conditions change.

  4. 04

    The question

    Can the original declaration still be proven?

Declarations are static. Reality isn’t.

Policies describe intent; operational evidence describes execution. IRIS Protocol explores how to keep the two connected. Trust starts with what actually happened.

02What IRIS Protocol is

Infrastructure
for evidence over time.

A research initiative into how operational traces can become verifiable evidence, without replacing the systems that produce them.

Not a certification

It does not award a static badge or a periodic seal.

Not a management system

It does not replace ERP, CRM, GRC or operational software.

A verification layer

It anchors declarations, events and context in a trail whose continuity can be checked.

From event to trust

  1. Stage 01

    Evidence

    Something happened.

    Activities, transactions, executions and decisions (human or agent) captured at the source.

  2. Stage 02

    Context

    We know the conditions.

    Dependencies, governing policies, state and versions frame the event.

  3. Stage 03

    Verification

    Provenance can be checked.

    Cryptographic links and consistency checks preserve continuity.

  4. Stage 04

    Trust

    The declaration becomes verifiable.

    Evidence supports independent verification, not just a periodic attestation.

03Provenance over time

Evidence doesn’t overwrite history.
It extends it.

New events add context to earlier states. The past is never silently replaced: the chain grows over time. Add the events one at a time.

Evidence timeline · illustrative model

  1. T₀Policy and baseline

    Initial declaration

    Formal commitments, policies or contractual constraints set the starting state.

    0x8f2a…c014

  2. T₁Execution

    Awaiting the next event

  3. T₂Provenance and state

    Awaiting the next event

  4. T₃Continuous assurance

    Awaiting the next event

Each link points back to the one before it: the history grows without the past being silently replaced. Cryptographic linking · temporal sequence · no overwrites.

Trust shouldn’t expire between audits.

An audit captures a single moment. In the months that follow, systems, models and conditions change. Compare the two models.

Declaration vs. reality · 24 months

DeclarationOperational realityUnobserved driftAuditNext audittime →

Conceptual model

Traditional · point-in-time snapshot

Static snapshot

  1. 1Audit
  2. 2Snapshot
  3. 3Operational drift
  4. 412–24 months
  5. 5Next audit

Between two audits, whatever changes stays invisible.

04Where trust matters

One protocol.
Many trust problems.

The same principle, continuous and verifiable evidence, applies across very different domains. Choose a domain to see the question it answers.

Model behavior · provenance · decisions

Can we prove which model, which policy and which context produced a decision?

Research direction · not a claim of adoption

Machines will make decisions. We will need their provenance.

People

Decisions

Organizations

Policies and controls

Software

Execution

AI agents

Autonomous actions

Shared verification layer · IRIS Protocol
05The protocol layer

Trust infrastructure
beneath the applications.

Ecosystem applications run on top; existing systems stay underneath. In between sits a layer that preserves evidence, context, verification and history.

Trust infrastructure

IRIS Protocol

EvidenceContextVerificationHistory over time

Existing systems and operational sources

ERPCRMGRCAIDatabasesAPIsAgentsServices

Product relationships indicate architectural direction, not integrations that are all already in production.

06Project status · research and development

Systems have learned to exchange data.
Can they learn to exchange trust?

The research hypothesis: verifiable evidence can become a shared infrastructure layer, independent of the applications that produce or consume it. This is a direction, not an existing standard or adoption already underway.

In active development · progressive disclosure

  • Protocol architecture
  • Verification mechanisms
  • Distributed trust models
  • Temporal provenance
  • Interoperability
  • Governance

Architecture and capabilities should be read in light of their stated maturity level.

Trust shouldn’t depend on memory. Nor on screenshots, attestations or periodic snapshots.

What happens should leave evidence. Evidence should preserve context. Context should preserve history. And history should remain verifiable.

From declarations to evidence. From evidence to continuous trust.