Koch Laboratory

Records meant to convince someone who does not trust their author

Seven directions on records of research time whose credibility must not rest on the good will of their author: immutability with storno instead of editing, two dates, anchors that corroborate rather than measure, proof surviving the loss of the system, evidence without disclosing content, and records that cut their own hours.

Koch Laboratory — records meant to convince someone who does not trust their author

A record of research working time is a peculiar kind of document: it is written by the party who benefits from it and read by someone who professionally assumes it could have been produced yesterday. The entire technical difficulty flows from that asymmetry — not from counting hours. This direction asks what properties a record must have for its credibility not to depend on the good will of its author, and where the limits of what can be shown at all actually lie.

Method. Problem → hypothesis → falsifiable criterion → result with boundary conditions. Statuses are stated openly; design changes forced by contact with reality appear as changes, not smoothed over after the fact.

1. Direction 1 — a record with nothing to correct

Research question. Can records be kept so that the impossibility of amending an entry is a property of the system rather than a declaration by its user? Why it is hard. From the reader’s point of view, any system that permits editing is the same thing as a spreadsheet — yet people make mistakes and must correct them. A ban on editing without a correction mechanism is untenable in practice; a correction mechanism without a trace defeats the whole purpose. State of the art (published). Immutability requirements in tax law (GoBD, § 146 of the German fiscal code), the accounting principle of storno, WORM media and storage, event-sourced systems. Success criterion. After a week is closed, no path exists to edit or delete an entry; a correction is a new entry pointing at the corrected one, and the original stays visible. Result. Confirmed: closed entries are immutable, corrections are storno entries with a reference, deletion is blocked. Boundary condition: the property belongs to the record, not to the medium — whoever holds administrative access to the database holds access to the database; evidentially that is defended only by direction 4, not by application rules. We say so explicitly, because systems that call themselves “immutable by design” usually do not. Status: implemented.

2. Direction 2 — two dates instead of one

Research question. How do you record work done three months ago without pretending the record was written back then? Why it is hard. Records reconstructed after the fact carry less evidential weight than contemporaneous ones, yet they are unavoidable: laboratories only start documenting systematically at some point, and the earlier work really happened. A system that lets you enter a work date with no trace of when the entry was made turns the whole record into a body of uniformly unverifiable quality. State of the art (published). The separation of event time and recording time in bitemporal databases; the “zeitnah” (contemporaneous) requirement in the research allowance methodology. Success criterion. Work date and recording date are separate fields, the second assigned automatically; the recording regime (contemporaneous / reconstruction) is explicit and survives the import of old material. Result. Confirmed: two date fields and two regimes; the import of an old journal enters as reconstruction and stays marked that way permanently. The side effect proved more important than the intent: openly admitting to reconstruction raises the credibility of the rest of the record instead of lowering it. Status: implemented.

3. Direction 3 — anchors make entries plausible; they do not measure them

Research question. What is the proper role of machine traces (commits, files, metadata) in a record whose subject is intellectual work? Why it is hard. The temptation is obvious: if a commit carries a timestamp, let the commit determine the hours. That produces two falsehoods at once. First, a large part of research work happens away from the computer — analysis, design, reading — and an anchor-driven record simply cannot see it. Second, a system that demands anchors teaches people to produce anchors, spoiling the very material that was supposed to lend credibility. State of the art (published). Tools that infer time from application activity; records built on repository integrations. Success criterion. Anchors are corroborating evidence, never a precondition for an entry; hours remain a declaration by the applicant; work away from the computer gets its own explicit marking instead of being a gap. Result. Confirmed as a design decision: anchors (commits, evidence files) attach automatically where they exist, and an entry without an anchor is fully valid and marked as conceptual work. The competing hypothesis, “anchor as a precondition”, was rejected — at the cost of the more convenient narrative, in favour of a record that does not lie about the nature of research work. Status: implemented (competing hypothesis rejected).

4. Direction 4 — proof that outlives the system it was made in

Research question. Can immutability be demonstrated to someone with no access to the system — and still be demonstrated once the system no longer exists? Why it is hard. An internal proof is worth exactly as much as trust in the operator; and here the operator is also the beneficiary. An external proof, on the other hand, requires that whatever leaves the premises contain no content — because the content of a research record is a trade secret. State of the art (published). RFC 3161 timestamps, OpenTimestamps anchored in Bitcoin, Merkle trees and transparency logs, Ed25519 signatures. Success criterion. A week is closed as a canonical record → SHA-256 → a stamp in at least two channels; verification possible without access to the instance and after its total loss. Result. Confirmed within the criterion: a canonical form of the week’s entries, a hash, a stamp in a signed log with a Merkle tree, and a second, independent OpenTimestamps stamp anchored in Bitcoin; the proofs sit as files beside the system. The caveat and how it is answered. The first channel is our own time service — the operator’s signature alone would therefore settle nothing. The answer is not a reassurance but the construction: that service’s log does not attest to itself, because the root of every closed week is anchored externally — in Bitcoin via OpenTimestamps, and in the reference line of a transfer booked by a bank, with the booking reference published. One boundary remains and deserves saying: a freshly submitted stamp lands in a week that is still open and becomes externally anchored only once that week closes. In that window the entry is carried by the second, direct OpenTimestamps stamp, made by the instance itself. Status: implemented.

5. Direction 5 — proof without disclosing content (a design change)

Research question. How do you attach evidence to an entry when its owner may not show that evidence to anyone? Why it is hard. The original design assumed files uploaded into the instance: scans, instrument printouts, measurement data. The collision with reality was immediate — for some laboratories the very content of those files is a trade secret, and putting them into any system, including their own, is a decision they do not want to take. State of the art (published). Cryptographic commitments, existence proofs resting on hashes alone, computing the hash in the browser. Success criterion. A variant in which the instance never sees the file, yet its hash still goes under the weekly timestamp. Result. Confirmed as a design change: alongside the upload mode there is a hash-only mode — the browser computes SHA-256 locally and only the fingerprint reaches the system. Boundary condition stated openly: such a proof is worthless without the original. Verification means producing the file and comparing the hash; whoever loses the original is left with a number that proves nothing. That is the price knowingly paid for not disclosing content. Status: implemented (both modes, switchable in the instance configuration).

6. Direction 6 — records that cap themselves

Research question. Can a record actively cut its own hours — and does such a cut strengthen its credibility? Why it is hard. A record in which every week ends exactly at the maximum is a warning sign to any reader — and at the same time the natural output of a system that simply refuses to exceed the limit. Work above the limit really happens; pushing it out of the record loses material, while writing it inside the limit is untrue. State of the art (published). The research allowance methodology with a weekly cap per person; time-recording practice with hard validations. Success criterion. Hours above the cap are recorded and visible, but explicitly marked as not claimed; routine work is documented and explicitly demarcated from research; the cap is set per person, because contracted hours differ. Result. Confirmed: three separate markings (claimed research, research above the cap — not claimed, routine work out of scope), a weekly cap per account, anchors attached across all three categories. As a side effect this settles the continuity question: weeks without research work stop being holes in the calendar. Status: implemented.

7. Direction 7 — team work without seeing each other’s hours

Research question. How do you keep a shared project record without showing employees each other’s working time? Why it is hard. The report for the assessing body must be complete — broken down by person and with totals. The employee’s view should not reveal colleagues’ workload, because that is information of a salary nature. Both requirements meet in one dataset and in one export. Success criterion. Completeness of the aggregate report together with masking of hours between people — in the output files as well, not only on screen. Result. Confirmed: a per-person breakdown for the lead, masking between employees in views and exports, authorship recorded on every entry. Boundary condition: masking protects against inspection, not against inference — anyone who knows the size of the team and the aggregate total can reconstruct part of the information arithmetically. Status: implemented.

Status of the direction. All seven directions are implemented and running. The result that seems to reach beyond this field is the observation from directions 2, 3 and 6: the credibility of a record grows where the record openly admits its own limits — the reconstruction, the missing anchor, the hours that must not be counted. Next research step: the read-access journal as evidence in its own right (who viewed which report and when), and encryption of anchors at rest without losing the verifiability of the timestamp.