Report classes
6planting, restoration, biodiversity, water, soil, climate
Evidence Collection Network
Mobile evidence is captured locally, hashed before upload, synchronized idempotently, and routed through community verification before it can support a public proof record.
Evidence Workbench
AHIN event contract
ASSERT - REASON - DELEGATE - FULFILL - CHALLENGE
Report classes
6planting, restoration, biodiversity, water, soil, climate
Required signals
8photo, GPS, timestamp, device, EXIF, sync, scan, community
Offline mode
idempotentsync by evidence ID and media hash
Final authority
humanAI never finalizes evidence
Capture photos, GPS, timestamp, device fingerprint, EXIF metadata, and local notes while offline.
Uploads are content-addressed, scan-gated, and replay-safe; conflicts become review tasks instead of overwrites.
Community observations can support proof, but they remain bounded until accredited review completes.
Workflow Control
CanopyProof actions use Dropin identity, agents, trust, governance, memory, and AHIN events. AI can observe and recommend, but accredited human review remains final authority for proof records.
Evidence envelope is created before network availability.
Contributor device
offline
Media and GPS commitments are calculated before upload.
Evidence Agent
local
Batch sync is replay-safe and conflict-aware.
Dropin Memory
idempotent
Community support or challenge is appended without final authority.
Community
non-final
Validation, AI, TerraProof, and review work items preserve dependency order.
Verification Layer
backpressure aware
Accepted status requires accredited human review.
Verifier
human gated
Evidence Schema
Stable evidence identifier used for offline sync and audit lineage.
Verification
Generated once, replay-safe, and tied to the append-only audit event.
Latitude, longitude, accuracy, and privacy mode for environmental context.
Verification
Compared against GPS hash, EXIF coordinates, and TerraProof geospatial expectations.
Observed time for photos, field reports, sensor readings, or community attestations.
Verification
Checked against device time, EXIF time, sync time, and satellite acquisition windows.
Dropin identity subject for human, organization, agent, or device.
Verification
Settlement-grade evidence requires authenticated identity and reputation context.
Content-addressed photo, video, document, or sensor artifact.
Verification
Duplicate detection, object storage integrity, and proof-root construction.
Privacy-preserving commitment to raw device location signals.
Verification
GPS spoofing detection without exposing unnecessary personal data publicly.
Current state from submitted through challenged, accepted, revoked, or superseded.
Verification
State transitions require policy checks and audit entries.
Bounded confidence estimate from deterministic and AI-assisted checks.
Verification
Advisory only; cannot replace human review.
Accredited humans and organizations responsible for final review.
Verification
RBAC, accreditation, conflict disclosure, and governance approval checks.
Append-only mutation trail for evidence, review, certificate, and challenge actions.
Verification
Hash-chained audit events with request IDs and policy decisions.
Replay-safe identifier for evidence captured without network access.
Verification
Synced through idempotent batches; conflicting ID reuse is challenged rather than overwritten.
Privacy-preserving commitment to the collection device or field terminal.
Verification
Used for duplicate, compromised-device, and GPS-spoofing review without exposing raw device identifiers.
Commitment to raw EXIF metadata extracted from field photos or media.
Verification
Compared with timestamp, location, and satellite windows during human review.
Local support, challenge, or needs-review context from accountable community actors.
Verification
Can challenge evidence and inform reviewers, but cannot finalize proof.
Confirmed object-storage media bound to upload intent, content hash, encryption mode, and malware scan state.
Verification
Pending, quarantined, or duplicate media objects remain non-final until accredited review resolves them.
Privacy-preserving receipts for field evidence collection, geolocation, media upload, and research-sharing consent.
Verification
Active consent is required before device-bound EXIF/GPS metadata can enter proof lineage.
Hash-bound device integrity statements for secure enclave, WebAuthn, platform key, field kit, or sensor gateway capture.
Verification
Risk flags and low reputation force metadata extraction into human review.
EXIF/GPS extraction records bound to clean media objects, active consent receipts, and active device attestations.
Verification
Metadata hashes, GPS accuracy, privacy mode, and clock skew are evaluated before use in proof records.
Human moderation queue for quarantined media, duplicate media, pending scans, and metadata extraction risks.
Verification
Open, assigned, resolved, and escalated tasks keep non-final evidence blocked until accountable review.
Append-only consent-retention, revocation, minimization, tombstone, and legal-hold decisions.
Verification
Retention automation records decisions without silently deleting or mutating evidence lineage.
Backpressure-aware work queue for validation, advisory AI, TerraProof, human review, and proof issuance.
Verification
Dependencies are explicit, AI remains advisory, and proof issuance requires human review before public records.
CanopyProof records are environmental accountability records. They are not certified carbon credits, financial assets, carbon-tax offsets, guaranteed yield instruments, or automatic CANOPY distribution claims. Public admin routes must remain blocked and every mutation must be audit logged.