These Rules explain how Proof Records are created, controlled, locked, shared, used, published, corrected and preserved.
They are designed around one principle:
Record what happened. Preserve what is known. Keep control of how it can be used.
A Proof Record can be detailed or incomplete.
It can begin at any point.
It can grow as more information becomes available.
What is missing stays missing.
What happened later does not silently rewrite what was recorded before.
1. What is a Proof Record?
A Proof Record is a structured record of an agricultural event, observation, decision, action, evidence, outcome or related history.
A record may include:
- farm and field context;
- cropping history;
- soil information;
- weather;
- observations;
- decisions;
- field operations;
- products and inputs;
- machinery data;
- photographs;
- maps;
- laboratory information;
- measurements;
- yield;
- economic information;
- environmental information;
- provenance;
- permissions;
- addenda.
Not every record contains every category.
A Proof Record preserves what is available rather than requiring a perfect record before anything can be recorded.
2. The record chain
Proof uses a common structure to separate different parts of what happened.
A record may contain:
The conditions around the event.
What was seen, noticed or measured.
What was decided and why.
What was intended.
What actually happened.
What, if anything, the event is being compared with.
What supports the record.
What happened afterwards and what was measured.
What was later corrected, clarified or added.
A record does not have to contain every stage.
3. Record states
Proof separates record preservation from record use.
Draft
A Draft Record is:
- private;
- editable by authorised users;
- capable of receiving new information;
- not publicly available.
Locked
A Locked Record is a preserved version.
Locking:
- creates a dated version;
- preserves its content and provenance;
- prevents silent overwriting of that version;
- does not publish the record;
- does not automatically give another organisation access;
- does not automatically permit group use.
A later version may be created where necessary.
The earlier locked version remains part of the audit history.
Named access
A record or part of a record may be made available to a specifically authorised person or organisation for a defined purpose.
The permission determines:
- recipient;
- purpose;
- information available;
- duration;
- restrictions.
Group-use permission
A record may be authorised to contribute specified information to a defined comparison, programme or group evidence output.
Group use does not automatically disclose the individual private Proof Record to the person or organisation receiving the group evidence.
Public redacted view
A separate public view may be created where public publication has been explicitly authorised.
The private source record remains separate.
Addendum
An Addendum adds:
- a correction;
- clarification;
- new evidence;
- later outcome;
- new context;
- other relevant information;
without silently replacing the existing published history.
Removed-content state
Where public content has been removed for an exceptional lawful reason, the Proof Record ID remains visible with an appropriate removal notice where the law permits.
4. Locking and publication are separate
Creating a Proof Record does not publish it.
Locking a Proof Record does not publish it.
Giving named access does not publish it.
Giving group-use permission does not publish it.
Public publication requires a separate, deliberate permission.
Proof must not design an interface in which:
- locking;
- accepting contributor terms;
- joining a programme;
- agreeing to group use;
quietly acts as agreement to public publication.
5. Who controls the private record?
The farm controls the use permissions attached to its private Proof Record.
For these Rules, “farm” means the person or organisation with the appropriate authority to control use of the relevant farm information.
Depending on the situation, that may be:
- the farm business;
- tenant;
- operator;
- land manager;
- authorised representative;
- another lawful authority.
Farm control does not mean that the farm necessarily owns every piece of information contained in the record.
Different rights may exist in:
- laboratory results;
- photographs;
- machinery files;
- research material;
- agronomist observations;
- third-party datasets;
- software-generated information;
- documents supplied by another organisation.
Those existing rights remain subject to applicable law and contract.
6. What farm control means
The relevant farm authority controls:
- who may receive named access;
- which purposes may use the record;
- whether it may contribute to specified group uses;
- whether it may participate in specified programmes;
- whether a public redacted view may be created;
- future changes to those permissions.
Farm control does not give the farm the right to:
- alter another contributor’s historical observation without attribution;
- rewrite an existing locked version;
- remove an inconvenient outcome merely because it is unfavourable;
- require Proof to change a group output already lawfully produced;
- require another contributor to state something they do not believe is accurate.
Where the farm disputes part of the factual record, the dispute is handled through correction, addendum or the record-enquiry process.
7. Proof’s rights and responsibilities
Proof does not claim ownership of the farm’s underlying private source data merely because it is stored in Proof.
Proof owns or controls, subject to third-party rights:
- the Proof software;
- interfaces;
- platform infrastructure;
- taxonomy;
- schemas;
- identifiers;
- system logic;
- permission architecture;
- validation logic;
- audit infrastructure;
- Proof trademarks and status marks.
The farm and other source-rights holders grant Proof only the rights reasonably necessary to:
- host authorised material;
- structure it;
- preserve it;
- create record versions;
- process permitted uses;
- enforce permissions;
- protect the service;
- create authorised outputs;
- maintain provenance and audit history;
- create a public redacted view where publication is authorised.
A permission for one use does not create a general licence for unrelated uses.
11. Historic records
Proof permits historic records.
A historic record may be created from information that existed before Proof.
Historic records may include:
- historic farm files;
- field notebooks;
- machinery records;
- research material;
- trial records;
- photographs;
- laboratory results;
- invoices;
- public archives;
- other surviving evidence.
The record must state that it is historic or retrospectively entered where relevant.
Historic records do not need to contain the information that would be expected from a newly created contemporary record.
13. Incomplete records
A Proof Record does not need to be complete.
A record may exist even where it is missing:
- soil data;
- pH;
- organic matter;
- exact dates;
- weather;
- machinery logs;
- calibration;
- previous crops;
- product details;
- photographs;
- measurements;
- outcome data.
Missing information remains missing.
Contributors must not invent missing information simply to make the record appear complete.
Missing information should be represented as:
- not recorded;
- unavailable;
- unknown;
- not applicable;
- estimated;
- reconstructed;
as appropriate.
14. Honest recording
A contributor must take reasonable care to distinguish between:
- what was observed;
- what was declared;
- what was measured;
- what was imported;
- what was calculated;
- what was estimated;
- what was inferred;
- what is unknown.
A contributor must not knowingly:
- fabricate evidence;
- invent a measurement;
- manufacture an observation;
- falsify an authority;
- alter a source file to misrepresent what occurred;
- present an assumption as a recorded fact.
Proof does not require certainty where certainty does not exist.
15. Provenance
Proof should preserve enough provenance to understand where information came from.
Depending on the information, this may include:
- source;
- contributor;
- author;
- machine;
- laboratory;
- software system;
- original file;
- capture date;
- import date;
- transformation;
- calculation;
- version;
- funding source;
- relevant affiliation.
Imported information must not silently lose its source identity.
16. What Proof verifies
Proof may verify:
- contributor identity;
- contributor role;
- contributor status;
- authority;
- timestamps;
- provenance references;
- record versions;
- locking integrity;
- permissions;
- access history;
- evidence references;
- addenda;
- application of defined comparison rules;
- application of privacy rules.
Where Proof uses the word verified, the relevant interface or output should identify what was verified.
17. What Proof does not automatically verify
A Proof Record does not automatically mean that Proof has established:
- that every observation is objectively true;
- that every source file is error-free;
- that an adviser’s decision was correct;
- that a product worked;
- that an outcome was caused by the recorded action;
- that the record is scientifically complete;
- that the outcome will repeat elsewhere;
- that the record represents all farms;
- that an agricultural claim is proven.
Proof verifies the record process and the aspects it can check.
It does not manufacture certainty around the underlying agronomy.
18. Permission is purpose-specific
Proof permissions must identify the intended use.
Where relevant, the permission records:
- Proof Record or records;
- person granting permission;
- purpose;
- recipient or recipient class;
- permitted information;
- permitted output;
- programme;
- geography;
- duration;
- onward-sharing restrictions;
- date granted;
- later changes;
- withdrawal.
A general “share my data” permission should not replace this structure.
19. Named access
A named permission can give specified access to:
- an agronomist;
- researcher;
- adviser;
- farm employee;
- organisation;
- another authorised party.
The recipient receives only the access covered by the permission.
Named access must not be silently widened because:
- the organisation becomes a customer;
- the organisation pays Proof;
- the recipient changes role;
- a new project begins.
A new purpose requires an appropriate permission.
20. Programme use
A farm may authorise specified records or information to participate in a defined Proof programme.
Programme permission should identify:
- programme;
- purpose;
- relevant records;
- information required;
- outputs;
- duration;
- programme participants where relevant.
Participation does not automatically give the programme sponsor access to the private source records.
21. Group-use permission
A farm may permit a record to contribute to a defined group comparison or evidence output.
Proof may use authorised contextual information to determine which records are relevant to the specified question.
The private record remains separate.
The receiving organisation does not automatically receive:
- farm identity;
- field identity;
- exact coordinates;
- private raw files;
- full record history;
- individual row-level data.
22. Suitability is question-specific
Proof does not declare a record “good” or “bad” merely because information is missing.
When records are considered for a particular question, Proof considers whether they contain the information required for that use.
For example, one comparison may require:
- crop;
- drilling date;
- soil context;
- outcome measurement.
Another may require:
- pH;
- organic matter;
- previous crop;
- application rate;
- calibrated yield data.
The record remains valid.
A record may therefore:
- contribute to one comparison;
- not contribute to another.
Failure to meet a comparison criterion does not invalidate the underlying Proof Record.
23. How comparison groups are formed
Where a permitted comparison is requested, Proof applies the criteria defined for that comparison.
Criteria may include:
- crop;
- enterprise;
- variety;
- soil;
- pH;
- organic matter;
- rotation;
- previous crop;
- geography;
- weather;
- timing;
- establishment;
- treatment or practice;
- machinery;
- measurement method;
- outcome method.
Proof should make visible:
- criteria used;
- eligible records;
- records included;
- records excluded;
- reasons for material exclusion;
- missing information;
- important differences;
- limitations.
Records that are not used remain Proof Records.
24. Group evidence
Once a permitted comparison group has been formed, Proof may produce group evidence from the authorised information.
A group output may include:
- counts;
- distributions;
- ranges;
- medians;
- means where appropriate;
- frequencies;
- descriptive comparisons;
- coverage;
- context;
- limitations;
- missing information.
Proof provides the evidence and data needed to interpret the question.
Proof does not make the agronomic decision on behalf of the user.
25. Privacy thresholds
A group output must not be produced simply because several records exist.
Proof applies privacy controls appropriate to the context.
The absolute minimum group size for an aggregate output is:
Five distinct holdings.
Five is a floor, not an automatic pass.
Proof may require a larger group.
Other controls may include:
- dominance checks;
- rarity checks;
- geography controls;
- time-window controls;
- suppression;
- filter restrictions;
- repeated-query controls;
- differencing controls;
- manual review.
Proof may refuse to produce group evidence where the privacy risk remains too high.
26. Suppression
Where information cannot safely be shown, Proof may suppress it.
A suppressed output should normally show:
- that information was withheld;
- the general reason;
without exposing the protected value.
Suppression is not evidence that the underlying record is defective.
27. When Proof does not produce group evidence
Proof may decline to produce a particular group output where:
- required permissions are absent;
- privacy thresholds are not met;
- re-identification risk is unacceptable;
- the requested records are not sufficiently comparable for the stated use;
- required information for that particular question is unavailable;
- the requested use is prohibited;
- the proposed output would misrepresent what the records can support.
The underlying records remain in Proof subject to their normal permissions.
Proof refuses the use, not the existence of the record.
28. No retrospective method shopping
Where an organisation funds a defined evidence programme, the primary rules should be declared before the relevant outcomes are inspected.
This may include:
- question;
- primary outcome;
- principal inclusion criteria;
- principal exclusions;
- comparison approach.
Later exploratory analysis is permitted where it is clearly identified as exploratory.
A customer may not repeatedly redefine the primary method until a commercially preferred output appears.
29. Funding and conflicts
A record or programme may be funded by:
- a farm;
- manufacturer;
- researcher;
- retailer;
- public body;
- industry body;
- Proof;
- another organisation.
Funding does not make evidence invalid.
Material funding and relevant professional interests should remain visible at the appropriate disclosure level.
Where relevant, Proof may record:
- who funded the work;
- who supplied a product;
- whether a contributor was paid;
- relevant employment;
- commission;
- sponsorship;
- ownership;
- advisory relationship.
30. Payment cannot change the record rules
An organisation may pay for:
- infrastructure;
- a programme;
- an authorised workspace;
- group evidence;
- monitoring;
- an attestation;
- integration;
- another permitted service.
Payment cannot buy:
- a favourable outcome;
- a predetermined conclusion;
- access outside permission;
- private farm rows;
- weaker privacy rules;
- weaker inclusion rules;
- deletion of an unfavourable record;
- suppression of a valid null result;
- retrospective cohort manipulation;
- favourable ranking;
- Proof endorsement.
31. No selective history
Proof Records may contain:
- positive outcomes;
- negative outcomes;
- null outcomes;
- mixed outcomes;
- incomplete outcomes;
- inconclusive outcomes.
The direction of an outcome does not determine whether it is allowed to remain.
A sponsor or customer cannot require an authorised record to disappear because its outcome is inconvenient.
32. Public publication
A farm may expressly authorise creation of a public redacted view.
Before publication, the farm must be able to understand what will be:
- public;
- generalised;
- redacted;
- kept private.
Public publication is separate from:
- record creation;
- locking;
- named sharing;
- group use;
- programme participation.
33. The public redacted view
A public view may include permitted information such as:
- Proof Record ID;
- crop or enterprise;
- season;
- generalised geographic context;
- relevant soil context;
- observation;
- action;
- method;
- outcome;
- evidence metadata;
- funding disclosure;
- relevant conflicts;
- limitations;
- addenda.
Information that may remain private includes:
- farm name;
- field name;
- exact boundaries;
- exact GPS;
- personal contact information;
- private raw evidence;
- invoices;
- contracts;
- full access history;
- commercially sensitive detail.
Publication of a public view does not publish the full private record.
34. Contributor attribution
A public view may identify a contributor where:
- the applicable record rules allow it;
- the contributor has been appropriately informed;
- there is an appropriate legal basis;
- publication does not create an unacceptable privacy or safety risk.
Where attribution is not appropriate, Proof may use:
- role;
- contributor status;
- pseudonymous identifier;
- another permitted representation.
35. Published records are intended to remain citable
A public Proof Record is designed to preserve a stable history.
Its Proof Record ID should remain stable.
A public record should not disappear merely because:
- ownership changes;
- a contributor leaves;
- the customer stops paying;
- a sponsor dislikes the outcome;
- a commercial relationship ends.
This permanence is subject to legal rights and obligations.
36. Corrections before publication
A Draft Record can be edited.
Where a Locked Record has not been publicly published and a correction is required:
- the existing locked version remains preserved;
- a later corrected version may be created;
- the relationship between the versions is recorded.
Proof must not silently replace the earlier locked version.
37. Corrections after publication
Once a record has been published, it may only be substantively corrected through an Addendum.
An Addendum should identify:
- what was added or corrected;
- why;
- date;
- contributor;
- affected section;
- relationship to the original information.
The original history remains visible.
38. Addenda
An Addendum may contain:
- correction;
- clarification;
- additional context;
- additional evidence;
- later outcome;
- measurement correction;
- provenance correction;
- conflict disclosure;
- legal note.
An Addendum becomes part of the permanent record history.
39. Sensitive-information removal
Sensitive information may be removed, further restricted or generalised from a public view where reasonably necessary.
Examples may include:
- personal information;
- precise location;
- confidential farm identity;
- private contractual information;
- information accidentally published outside permission;
- information presenting a material security risk.
Where appropriate, Proof records:
- what category was changed;
- when;
- why;
- who authorised the change.
The public page should not disclose enough information about the redaction to recreate the sensitive information.
40. Exceptional legal removal
In exceptional circumstances, published content may need to be removed because of:
- law;
- court order;
- regulatory requirement;
- valid data-protection right;
- intellectual-property right;
- confidentiality obligation;
- serious safety or security concern;
- another compelling legal obligation.
Where lawful and safe, Proof retains the Proof Record ID and displays:
Content removed
together with:
- removal date;
- a neutral explanation.
Where the legal requirement prevents Proof from displaying the ID or explanation publicly, Proof complies with that requirement.
41. Publication permission is not ordinary deletion control
Once a public redacted view has been lawfully published, changing a future-use permission does not automatically delete the published history.
A published record can be:
- corrected by Addendum;
- further redacted where necessary;
- removed where a legal or exceptional rule requires it.
It cannot normally be removed solely because the result later becomes inconvenient.
42. Withdrawing future permissions
A farm may withdraw:
- future named access;
- future group use;
- future programme use;
where the relevant permission allows withdrawal.
Withdrawal may be limited to one purpose without changing another permission.
For example:
43. Effect of withdrawal
Withdrawal stops future use from the effective time recorded by Proof.
It does not automatically undo:
- previous lawful access;
- audit history;
- group evidence already lawfully produced;
- reports already lawfully issued;
- previous lawful processing;
- historical references.
Proof records:
- what was withdrawn;
- who withdrew it;
- when;
- affected purpose.
Separate legal rights under data-protection or other law continue to apply.
44. Group evidence already produced
A lawfully produced group output does not automatically become invalid because a record later stops participating in future group use.
The historic output should preserve:
- output date;
- methodology;
- records included at that time;
- applicable permission state;
- version.
Future outputs must respect the changed permission.
45. Record enquiries
Anyone with a legitimate concern about a Proof Record may raise a Record Enquiry.
Possible concerns include:
- contributor authority;
- factual error;
- provenance;
- incorrect attribution;
- missing funding disclosure;
- undisclosed conflict;
- sensitive information;
- public redaction;
- misuse;
- evidence authenticity;
- incorrect addendum;
- public-view removal.
46. How to raise a Record Enquiry
Email ct@proof.ag with the subjectProof Record enquiry, or use the form below.
Include where possible:
- Proof Record ID;
- issue;
- relevant section;
- why you believe it should be reviewed;
- evidence supporting the concern;
- relationship to the record.
Proof may request further information.
Do not publish private or sensitive evidence merely to prove the concern publicly.
Your Record Enquiry has been received. It will be reviewed by a person, and Proof may contact you for further information.
47. What happens after an enquiry
Proof may:
- acknowledge the enquiry;
- request information;
- restrict access temporarily;
- ask relevant parties for a response;
- review authority;
- review provenance;
- review evidence;
- add a visible query state;
- issue an Addendum;
- correct attribution;
- apply redaction;
- reject the enquiry with reasons;
- escalate a legal or privacy issue.
A Record Enquiry does not automatically mean the challenged record is false.
48. Disputed records
Where a material dispute cannot immediately be resolved, Proof may display an appropriate status such as:
Queried or Disputed
The existence of a dispute should not be hidden where it materially affects interpretation of the public record.
The challenge and response become part of the record history where appropriate.
49. Privacy requests remain separate
A Record Enquiry is not a substitute for an individual data-protection right.
Where an issue concerns personal information, a person may also use/legal/privacy-platform#exercise-your-rightsor /legal/data-protection-complaints.
Proof will apply the relevant legal right independently of these Record Rules.
50. Prohibited uses
Proof Records and Proof evidence must not be used through Proof to:
- create farm rankings;
- create adviser rankings;
- rank agricultural products;
- generate a trust score;
- issue agronomic recommendations on Proof’s behalf;
- create lending or credit scores;
- automatically determine insurance decisions;
- make automated scheme-compliance decisions;
- carry out enforcement targeting through identified farm drill-down;
- defeat Proof privacy controls;
- re-identify protected farms;
- manufacture evidence that did not exist.
A farm may separately choose to share its own information with a regulator, insurer, lender or other organisation.
That does not turn Proof into an enforcement or decision-making system.
51. Artificial intelligence
AI may assist Proof with:
- extraction;
- classification;
- mapping;
- evidence matching;
- duplicate detection;
- redaction;
- quality checks;
- identifying missing information;
- drafting summaries for review.
AI may not:
- invent missing observations;
- invent measurements;
- invent authority;
- silently infer a missing fact;
- rewrite source meaning;
- create an agronomic verdict;
- override permissions;
- decide that a product works;
- produce an evidence score.
Machine-generated or modelled values must be distinguishable from recorded source information.
52. Portability
Proof should not trap farm records merely because they were created using Proof.
An authorised farm or contributor should be able to export records they are entitled to receive in a documented format.
Exports may include:
- record content;
- relevant metadata;
- evidence references;
- provenance;
- versions;
- applicable permission information.
Export rights remain subject to:
- rights of other people;
- third-party intellectual property;
- confidentiality;
- privacy;
- contractual restrictions that are lawful and proportionate.
53. Stable identifiers
A Proof Record receives a stable Proof Record ID.
Internal events, evidence files and versions may have their own identifiers.
The primary human-facing Record ID should remain stable through:
- addenda;
- later versions;
- public redaction;
- status changes.
Where published content is lawfully removed, the ID remains visible where the law permits.
54. Record versions
Proof should preserve:
- schema version;
- taxonomy version;
- record version;
- relevant method version;
- relevant permission version.
A later change to the Proof recording standard must not silently reinterpret an earlier record as though the new rule had existed at the time.
Where a record is migrated to a new structure, Proof should preserve the relationship between:
- source version;
- transformed representation;
- transformation method.
55. Commercial relationships ending
If a commercial customer stops paying:
The customer may lose:
- paid workspace access;
- monitoring;
- paid API access;
- commercial licences;
- support;
- other paid functionality.
The end of payment does not automatically delete:
- valid Proof Records;
- public views;
- addenda;
- citations;
- historical outputs;
- farm export rights.
Payment must not become a ransom for record permanence.
56. Changes to these Rules
Proof may update these Rules where necessary to reflect:
- changes in law;
- changes in technology;
- evidence from operating the platform;
- new privacy risks;
- development of the Proof recording standard;
- new record types.
Every published version must show:
- version number;
- effective date;
- material changes.
Previous versions will remain available at /legal/archive.
A later version does not silently rewrite the meaning of an earlier locked record.
57. Rule precedence
Applicable law always takes priority.
These Rules are incorporated into the relevant Proof service terms and commercial agreements where stated.
A signed agreement may change a service-specific operational matter where these Rules allow it.
The rules in these Rules concerning record integrity, authority, permissions, privacy, truthful recording, no pay-to-influence and preservation of inconvenient outcomes are protected rules.
A contract cannot be used to:
- widen a farm permission without valid authority;
- alter an already locked historical version;
- purchase a favourable output;
- override privacy safeguards;
- remove a valid unfavourable record for commercial convenience;
- defeat a legal right.
Where there is a genuine conflict, Proof will determine the applicable rule in accordance with:
- applicable law;
- the valid permission and authority applying to the record;
- the applicable Proof Record Rules;
- the relevant service agreement.
58. Contact
Questions about these Rules:
Grosvenor House
11 St Pauls Square
Birmingham
England
B3 1RB