Summary
- An individual Internet-Draft posted on 28 September proposes a SCITT-carried receipt for
NotDemonstrated(reason=underdetermined): two admissible possible worlds fit the same closed evidence set but give different values for one frozen claim. - The result is verifiable only under the declared profile and checkpoint. It does not identify the real world, exclude evidence outside the admitted set or show that a downstream decision respected the result.
There is a tempting shortcut in audit language: if a system cannot establish an answer, call the question unknowable. The shortcut hides the more consequential choice. Who decided which documents, observations and possible explanations counted before the test began? A rigorous proof can show that two explanations survive the rules it was given. It cannot, by itself, show that those rules captured the dispute people actually need to resolve.
Ivan Nestorov's P10 Underdetermination Profile, revision -00, makes that distinction unusually explicit. Dated 28 September 2026, the individual Informational Internet-Draft describes a third-party-verifiable form of NotDemonstrated(reason=underdetermined) for the Supply Chain Integrity, Transparency, and Trust architecture, or SCITT. The IETF Datatracker lists it as an existing Internet-Draft, not an RFC or a SCITT working-group adoption. No reported deployment or contested real-world case follows from publication of the proposal.
The proposed test has a definite shape. A claim is fixed; a profile defines the possible worlds, admissible evidence, the rule for saying a world fits that evidence and the interpretation of the claim. The receipt then carries two canonically encoded witness worlds. The frozen verifier must find both compatible with the same closed evidence set while assigning different values to the claim. The draft binds the result into an in-toto Statement v1 predicate carried in a SCITT Transparent Statement. The COSE receipt and SCITT architecture are existing published RFC mechanisms; P10's use of them remains only a proposal. The author expressly says the two-world mathematical idea is not new. The proposed contribution is the profile and binding that let another party check this particular claim under declared rules.
That declaration has to precede the evidence, not follow an inconvenient outcome. The draft calls for the world class, claim semantics, evidence-admission rules, coverage scope, log identity, authorized admitters, canonicalization and verifier artifacts to be committed before the first admission for the identified instance. It then uses a closure and a checkpoint-bounded coverage proof to bind the valid, registered, in-scope evidence admitted by those actors through that checkpoint. A verifier replays the relevant transparency-log prefix.
Without the required closure or artifacts it halts without an epistemic verdict; a conflicting commitment or defective coverage can be rejected. Those are verification failures, not alternative names for “the claim is underdetermined.”
The demanding machinery matters because a bare signature on “we cannot tell” would permit a claimant to pick a narrow evidence set after seeing its contents. But the machinery also reveals its own perimeter. Closure concerns valid entries in the selected log, from selected admitters, for one identified request, within the frozen scope and only through a particular checkpoint. The draft's mandatory limitations state that it does not rule out unregistered or excluded evidence, another log, a semantically equivalent request opened under another ID, or later entries.
It cannot prove that the issuer did not create sibling instances for the same claim under different profiles and present the most convenient one.
One subtle failure remains even if every recorded byte is honest. A profile can formally allow a decisive item of evidence while the deployed acquisition process makes that item practically unobtainable. The draft says its formal preflight does not establish that determining evidence is representative or likely to arrive; a formally valid profile can therefore be biased toward abstention. It also distinguishes a checker proving what follows from its encoded semantics from the much harder question of whether those semantics faithfully describe a natural-language claim or the real world. This is not a flaw discovered in a deployed system.
It is a limitation the author has chosen to put in the proposed receipt.
The governance consequence is concrete. Anyone offered a future P10 result should ask for the claim and profile as they stood before admission, the log and checkpoint, the coverage and closure record, the two witness worlds and the mandatory limitations. A purchaser or auditor should also ask whether alternative instances for the same substantive question are visible and who decided which evidence channels qualified. Those are Daniel Kade's proposed review questions, not new IETF requirements. A valid formal abstention can be useful evidence about the selected test; it is not a warrant to stop looking outside it.
Sources
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance

