Skip to content

MCV-1 / SSX360 methodology

Prove who or what authorized the machine.

MCV-1 is the published criteria version used when machine authorization is in scope. It traces an action from stated intent through delegated authority to the resulting record, then defines the controls and evidence the reviewer must examine.

Non-issued specimen. Every issued mark carries a registry ID, criteria version, and expiry.

What the mark means

MCV-1 is the criteria version, not the mark.

SSX-L3.0 is the record version of the issued mark. MCV-1.0 names the published criteria used when machine authorization is in scope. Each issued mark resolves to its criteria, scope, evidence period, assessor, dates, status, and signed record.

The mark
A rendered view of the signed credential, not the credential itself. The master artwork alone carries no verification status.
Criteria version
Names the exact published method used for the review so a later criteria revision cannot silently change the meaning of an earlier mark.
Registry ID
Resolves to the public entry containing the holder, subject, scope, assessor, dates, status, digests, and signed record.
Expiry date
Verification lasts no more than twelve months. Renewal requires a new review and a newly signed registry record.
Open the MCV-1 registry

The authorization sequence

MCV-1 does not treat a signature as authorization by itself. It checks the full sequence and records the first unsupported link.

  1. 01

    Human intent

    Decision owner, requested outcome, and source record

  2. 02

    Delegated mandate

    Permitted systems, constraints, validity, and revocation

  3. 03

    Machine action

    Observed action, machine identity, target, and result

  4. 04

    Auditable proof

    Source register, checksums, signature results, and gaps

See it in ten seconds

Delete a receipt. Watch what an ordinary log would say.

These are signed action receipts from a payment workflow. Each one is individually valid. Click any receipt to remove it, the way an insider, an intruder, or a crashed process would. Then run verification.

Action ledger · actor SVC-TREASURY-07

Awaiting verification

Remove any receipt, then run the verifier.

An ordinary log shows nothing wrong after a deletion. Every remaining record still looks signed and valid.

That is what an incident looks like: nothing. Terminus numbers every receipt per actor and chains them, so a removed record cannot look complete. We report only what we know: receipts the actor numbered never arrived. We never guess at the cause, and that restraint is why the evidence holds up.

Why authorization evidence needs its own review

The MCV-1 criteria

Each criterion names the test and the report output. A missing record is a finding, not a reason to infer the intended result.

MCV-1.1

Intent and accountable owner

Identify the person or governed system that initiated the request, the intended outcome, and the record that expresses that intent.

Report output

Owner and source record named, or an evidence gap recorded

MCV-1.2

Delegated authority and scope

Identify what authority was delegated, which systems and actions it covered, its constraints, validity period, and revocation path.

Report output

Authority boundary reconstructed and exceptions listed

MCV-1.3

Identity and action binding

Bind the observed machine identity, action, target, and result to the authority record that preceded them. Verify signatures where signed records exist.

Report output

Action linkage supported, contradicted, or not evidenced

MCV-1.4

Timing, freshness, and revocation

Check that the authority was valid when the action occurred and that expiry, replay protection, and revocation evidence are available where the system claims them.

Report output

Time and validity findings with source timestamps

MCV-1.5

Log completeness and gap detection

Reconstruct the sequence across human, service, and machine identities, then identify missing, ambiguous, overwritten, or shared records.

Report output

Sequence map and ranked evidence gaps

MCV-1.6

Reviewable evidence export

Export the method version, source register, files, checksums, signature results, findings, and stated limits so another reviewer can repeat the checks.

Report output

Signed report and offline-reviewable evidence package

Supported
The named evidence supports the criterion.
Gap
A required link or control is missing or contradictory.
Not evidenced
The available records cannot support a conclusion.
Out of scope
The agreed system boundary excludes the criterion.

Deliverables and engagement

  • Signed MCV-1 baseline report
  • Custom SSX Terminus control specification
  • Evidence-window definition for the named actions
  • Machine-verifiable authorization record
  • Acceptance test and offline-verification handoff
  • Upkeep cadence and change-review schedule when the mark is in scope

Framework evidence mapping

These mappings identify control evidence that may support a separate review. They are evidence mapping, not a certification claim. Certification under any scheme named here comes from that scheme's own accredited assessors.

PCI DSS
Identity, least-privilege, access-review, and audit-log evidence where the reviewed system is in the cardholder data environment.
SOC 2
Evidence relevant to selected security, availability, processing-integrity, confidentiality, or privacy criteria.
ISAE 3402
Service-organization control evidence where the service is relevant to user entities' financial reporting.
NIST AI RMF
Govern, Map, Measure, and Manage evidence for identity, oversight, traceability, and response.
EU AI Act
Technical-documentation, logging, risk-management, and human-oversight evidence where applicable.
DORA
ICT risk, change, logging, incident, and third-party oversight evidence for applicable financial entities.
CRI Profile
Financial-services cybersecurity control evidence, subject to the selected profile scope and version.

Assessment boundary

  • A valid signature establishes control of a key and the integrity of signed bytes. Authorization and correctness require separate evidence.
  • Model quality, safety, legal sufficiency, business judgment, and automated-decision fitness remain outside MCV-1 scope.
  • Source gaps remain visible in the report. Reviewers receive the missing-record finding rather than reconstructed evidence.
  • A pass applies to the systems, period, evidence, and criteria named in the report.

Return to the full service list or scope an SSX Terminus solution.

Request an MCV-1 scope