Three Organs, One Subject — a Dispute
Section 5.3 defines standing as the subject's current attestation answer as reported by the named organ — so standing is organ-relative by design. Three organs, one subject, three answers: the protocol reports, it does not arbitrate. Drive each organ below (real HTTP, real state), poll them all, and see what a relying party does when the answers disagree.
The seeded subject contested-vessel starts in
disagreement: forge reports it Radiant, tss measured
drift and put it on Probation, gateway has never formed an opinion
(Ghost). All demo-grade, nothing normative;
consent is required in the browser and enforced again server-side.
forge
tss
gateway
attest forge)
to confirm —
The relying party's problem
When the poll disagrees, what is a client to do? The scheme has a precise answer: nothing, by itself — and that is the point.
- Every answer is attributable: an iqa URI names its organ, so no report is anonymous. Disagreement is never ambiguity about who said what.
- The protocol surface stays read-shaped: organs report standing; the scheme defines no arbitration, no voting, no precedence. Choosing which organs to trust is a policy decision that lives outside the URI (Section 6).
- The disagreement is still actionable data: a cautious client treats the subject as contested and asks more organs, requests an
audit, or walks away — its choice, on the record. - What the scheme does guarantee: reads are read-only (5.3), the safety classes of Table 1 hold per organ, and the closed sets keep the vocabulary finite.