Five separate questions
- Is the record structurally valid? Format, ID and encodings pass.
- Was it signed by the embedded key? The Ed25519 signature passes.
- Does the origin currently authorize the key and record? GOVP-STATUS-1 evaluates this separately.
- Do I trust that origin or publisher? This is application policy.
- Is the signed claim true? GOVP alone cannot answer this.
Keeping these questions separate prevents a green cryptographic result from being presented as institutional endorsement or factual proof.
Canonical identity
The canonical HTTPS URI binds remote publication to the exact final record URL. It does not create a global certificate authority and it does not replace ordinary domain or organizational due diligence.