Sphere wins 2026 Global Recognition Award
Sphere Partners
One Ledger, Four Readers: Scoping Disclosure to Each Audience

One Ledger, Four Readers: Scoping Disclosure to Each Audience

A complete AI record raises a fair objection: not everyone should see everything. The answer is scoped disclosure — one tamper-evident ledger, four different views, each showing a reader exactly what they're entitled to and no more.

3 min read
In this article

The instinctive worry about recording everything an AI does is over-disclosure: surely the auditor, the regulator, the user, and your own engineer shouldn't all see the same thing. They shouldn't, and they don't have to. One record can serve four readers, because completeness and disclosure are separate decisions — the ledger is complete; what each reader sees is scoped.

Completeness and disclosure are not the same

These two ideas get conflated, and the confusion drives bad choices — teams under-record to avoid over-disclosing, and end up unable to answer anything. The record should be complete, because you can't disclose what you never captured. What each audience sees is a separate control layered on top. Keep everything; show each reader their slice.

The four readers

  • The user sees their own interactions and what was decided about them — the basis for exercising their rights.
  • The regulator sees the evidence relevant to the specific decision or complaint under review, not the whole system.
  • The auditor sees that controls fired and obligations were met, often without needing the raw content behind them.
  • The engineer sees the operational detail needed to debug and improve, within policy.

Four questions, four scopes, one source of truth underneath them all.

Why one source matters

The alternative to scoped views over one record is separate records per audience — a user-facing log, an auditor's report, an engineer's trace — which immediately diverge and quietly contradict each other. Then a discrepancy between two views becomes its own problem. Scoping views over a single tamper-evident ledger means every reader is looking at projections of the same underlying truth, so they can differ in detail but never in substance.

The core idea

Don't keep four records that disagree. Keep one record and show four scoped views of it — so disclosure is controlled without truth being fragmented.

The guarantee holds for everyone

Scoping changes what a reader sees, not whether it's trustworthy. The integrity guarantee — that the record is complete and unaltered — holds regardless of which view you're granted. A regulator's narrow slice is exactly as tamper-evident as the engineer's detailed one, because they're both drawn from the same signed chain. Access is scoped; verifiability is universal.

Disclosure as policy, not access control theater

Scoped disclosure is governed by policy you set, and — like other controls — the fact of a disclosure and its scope can themselves be recorded. So 'who saw what, and why' is answerable too. This is what turns need-to-know from a slogan into a mechanism: the record is whole, the views are principled, and even the act of disclosing is on the record.

Frequently asked questions

No — completeness of the record and access to it are separate. The ledger captures everything; scoped views determine what each reader sees. A regulator sees the evidence for a specific matter, a user sees their own interactions, and neither sees the whole system. You get complete evidence without universal exposure.

Separate logs diverge and contradict each other, and a discrepancy becomes its own liability. Scoped views over one signed record mean every audience sees a projection of the same truth, so they can differ in detail but never conflict in substance.

Yes. The integrity guarantee comes from the underlying hash-chained record, so any slice a reader receives is as tamper-evident as any other. Scoping limits breadth of access, not trustworthiness.

Disclosure is governed by policy, and the fact and scope of a disclosure can themselves be recorded — so 'who saw what, and under what authority' is answerable, turning need-to-know into an enforced, auditable mechanism.

One truth, four principled views. See how scoped disclosure lets a user, regulator, auditor, and engineer each see exactly what they're entitled to — over one tamper-evident record. Book a walkthrough.

We'd love to hear from you!

Please provide your contact details, and our team will get back to you promptly.