Comparison matrix

Source code or release archive vs Current operation

One-sentence distinction

Source code supports implementation review; current operation requires deployed identity, authorized configuration, time-bounded service observations, state transitions, and attributable actions.

Side-by-side matrix

Source code or release archive and Current operation are related but not interchangeable
DimensionSource code or release archiveCurrent operation
Primary questionWhat evidence establishes the first property for a named purpose?What separate evidence or authority establishes the second property?
EvidencePurpose-specific technical, factual, or institutional records.Independent records appropriate to the second category.
AuthorityMay be descriptive or technical and may not require legal authority.May require a competent legal, constitutional, organizational, or operational decision-maker.
CurrentnessCan be current, stale, disputed, unknown, or unavailable.Must be assessed separately; the first status does not transfer.
Failure conditionEvidence may be authentic but incomplete or unsuitable.Authority may exist but rely on wrong or stale facts.

Why the distinction matters

Source code supports implementation review; current operation requires deployed identity, authorized configuration, time-bounded service observations, state transitions, and attributable actions. Systems and institutions fail when one side is used as a shortcut for the other. The distinction determines what evidence is collected, who may decide, what can be appealed, and which failure modes must be controlled.

Common failure caused by conflation

Presenting a repository, static page, or build artifact as proof that an institution is operating now.

This error can create false confidence, unauthorized status, misattributed liability, silent loss of correction rights, or an operational claim based only on descriptive material.

Implementation consequences

  • Use different fields, identifiers, and claim-status records for each side.
  • Require separate evidence and currentness checks.
  • Do not let a user-interface label silently merge the categories.
  • Preserve correction and supersession history for both.
  • Route decisions to the ecosystem authority that owns the relevant function.

Legal admissibility and weight depend on jurisdiction, procedure, foundation and purpose; technical validity is not a universal admissibility rule.

Technical evidence can inform a legal decision but cannot replace jurisdiction, legal basis, procedural authority, due process, or remedy. Conversely, a lawful decision does not make the underlying technical record accurate if the evidence is stale or defective.

Examples

  1. A valid signature demonstrates control over a key and payload integrity; it does not establish the truth of every signed statement.
  2. A registry can record a citizenship decision; the registry operator does not thereby acquire constitutional power to create citizenship.
  3. A static release can show that software exists; it does not prove the service is currently operating.

Sources

  • PROV-O: The PROV Ontology — W3C; W3C Recommendation 30 April 2013; W3C Recommendation. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
  • RFC 3161: Time-Stamp Protocol — IETF; RFC 3161 with RFC 5816 update; Proposed Standard. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
  • C2PA Technical Specification v2.4 — Coalition for Content Provenance and Authenticity; C2PA Technical Specification 2.4; Published technical specification. Exact claim-support entries: 2. Revalidated 2026-08-14T22:04:09Z.
  • in-toto Attestation Framework — in-toto project; Current project framework; Open standard; CNCF graduated project. Exact claim-support entries: 1. Revalidated 2026-08-14T22:04:09Z.

Comparison claim record

Each proposition has a stable ID, status, scope, owning route, evidence relationship, currentness qualification, correction state, and synchronized JSON record. Record completeness does not make the proposition true.

Source code or release archive versus Current operation

Source code supports implementation review; current operation requires deployed identity, authorized configuration, time-bounded service observations, state transitions, and attributable actions.

Qualification: The matrix prevents category error but does not decide every jurisdiction-specific or system-specific case.

Support relationship