- Trusted request
- Verified path
- Authorized signer
- Policy passed
Trusted request and path verified.
The three pre-sign questions, the ALLOW / HOLD / REJECT decision, and what changes before versus after SignTrail.
How It Works
05The request, path, and signer must all pass before a transaction is signed.
No trusted path, no signature.
tx_payload_hashprovenance_digestsigner_idpolicy_hashdecision output
SignTrail decides before signer execution — not after the transaction is broadcast.
Trusted request and path verified.
Needs manual review before execution.
Unsafe context or manipulation detected.
Unsafe request may reach signer.
Unsafe request is held before signing.
The difference is not who signs. The difference is whether the path can be trusted.