ORBIS.ID
You are on Anyone PUBorbis.id

TRUST · OPERATIONS · PHASE 2

An instrument tells you what is true. A console tells you what looks fine.

This page does not read a live feed of its own — that build is still phase 2. What follows is not an absence notice, though: it is what the platform's own operations instrument shows today, fact by fact, some of it measured directly against the cell for this page and some of it carried from the instrument's own account of itself. Every number below says which.

Why this is not a status page with the lights turned green.

A page that can only ever say "operational" has not measured anything — it has decorated a claim nobody checked. The instrument this section describes is built the other way around: every panel is a real network call or a real computation a browser can run for itself against the cell, and a panel that cannot measure something says so in place, including the one that reports the cell could not, until recently, name the source it was running.

A console that only renders green is not an instrument — it is a screensaver.

Checks a stranger's own browser can run.

The trust chain is not a diagram here — it is a sequence: fetch the signed status list, inflate it and count the bits, fetch the trust anchor, recompute its key's thumbprint against RFC 7638, and verify the signature with the algorithm the token itself names. None of the five steps asks the reader to trust an operator's word; each is arithmetic anyone can redo.

The revocation field, measured this session
answers with a signed status-list token. Decoded 2026-08-27 the list inflates to 8,192 bytes carrying 65,536 single-bit entries, none of them set. The cell’s own register still records this path as unanswered; it answers.
The trust anchor behind it
The same status list is signed by a key named in this platform's own did:web document, which carries two verification methods as of this session — fetched directly, not assumed.

Decoded directly from /status/1 this session — not carried from the harvest.

The audit chain, and what "tamper-evident" actually buys you.

Every privileged action on the platform is described as appended to a per-tenant hash chain: each link's digest covers the previous link's digest plus the event itself, so altering any record breaks every record after it. Change one link and the chain does not hide the change — it goes red from that point forward, and the check can name where, never what.

That is what tamper-evident means, and it is a weaker and more honest claim than tamper-proof. A weaker claim that is actually true outranks a stronger one that only sounds checked.

The version a stranger could verify — a periodic, redacted anchor carrying only an id, the previous hash and the hash, published on the public plane with no personal data attached — is a described design, harvested from the instrument's own account of itself, not something this page has seen running. The full chain is operator-authenticated by design, because the underlying record can carry personal data; the redacted anchor is what would let a stranger verify integrity without exposing anyone, and it is not built yet.

A finding that stopped being true between one fetch and the next.

Every other panel on this instrument checks the cell against itself; naming which source is running needs the deploy pipeline to speak, and the harvested account of this page reported that it did not: {"commit":null,"builtAt":null,"attested":false}, called out as "the finding this page would rather report than hide."

Re-measured directly against the cell for this page, that is no longer the answer. The endpoint now names a real commit and a real build time, attested. Whether that happened because the pipeline was fixed or because this page caught it mid-repair is not something one measurement can settle — only that the honest answer changed, and the honest thing to do with an old finding that stopped being true is say so, not quietly drop it.

The operator plane, counted from the wire.

The back office is not one screen; it is a set of desks, each a group of routes with an authentication class on every one. The count below was run directly against this cell's own /openapi.json this session — this page holds no copy of the routes it describes, so it cannot quietly drift from them.

Every operation this cell publishes
374 operations across 342 distinct paths.
Needing no credential at all
118 of them — the public plane, countable by anyone, the same way the register's own free-verification claim is countable.
Behind an operator identity
143 on the role-gated back-office plane and 52 on an older operator-bearer plane — 195 together, the largest surface this platform has.
Behind the Entra gate, and the one break-glass operation
10 routes carry the sign-in ceremony and the console shells; 1 is marked owner-only — a break-glass surface should be countable on one hand, and loud when it is used.
The rest
14 partner-session, 14 wallet-facing Entra, 12 holder-JWT, 5 wallet-session and 4 wire-signed operations — each its own authentication plane, none of them the public one.

Measured directly this session from the cell's own auth-plane classification, not carried from the harvest. The back-office and operator-bearer split (143 / 52 = 195) matches what the harvested account of this instrument reported the same day — some evidence the shape of the back office has not drifted, not proof that nothing has.

Why the console door does not open yet.

Harvested from the platform's own account of its operator plane, not independently re-run this session: sign-in for a human operator delegates entirely to Microsoft Entra, with PKCE, so the platform never holds an operator password. The callback that receives the token back is reported as refusing before it reads a single claim, because verifying that token's signature against the tenant's own published keys is not implemented yet — and the code's answer to a check it cannot yet perform is to refuse, not to trust the token and proceed.

A platform holding people's identities should be judged on which way it fails. Failing closed on an unverifiable token, and saying so on this page rather than leaving a reader to discover it by clicking, is the direction we would rather it kept failing.

Before you go any further.

No operations feed is read by this build, and the operator console has no interface a reader can reach on this cell today. What you can check yourself is one fetch away, on the standards page and the two endpoints measured above — named here rather than papered over with a placeholder chart.

  • PLANNED A wallet a person installs from an app store. wallet-native You cannot hold a credential on a phone you own. Everything a person would do with a proof waits behind this.

The register holds 17 live · 2 partial · 2 planned · 5 not yet.

2 of the 3 capabilities this page depends on have no row in the register yet, so this page will not print a state for them. They are named rather than dropped, because a slice that silently shortens itself is the same defect as a claim with no receipt.

  • revocation
  • did-web-anchor

The register route serves, but it carries no row for these yet. List what it does carry:

curl -s https://id.orbis.id/api/site/register | jq -r '.entries[].slug'

Straight answers.

Is there a live status page today?
No. This is it, and it says so.
Does this page read a live feed itself?
No. Everything numbered above was fetched once, directly, while writing this page. A reader who wants their own answer should not take this page's word for it either — the standards page names every endpoint that would let you.
Can I check whether an endpoint is up right now?
Yes — fetch it yourself. The standards page names every one.
Can I sign in as an operator and see the console for myself?
No. The door refuses everyone on this cell today, for the reason named above, not because of who is asking.

A console that renders green is not evidence, it is decoration. This page prints what an instrument actually returned, including a finding that stopped being true between one fetch and the next — because the honest thing to do with a correction is publish it, not quietly delete the row it replaced.

Do not trust us. Check us.