Reading a result

The three outcomes, the two places they are shown, and the three states before them.

A result has three possible outcomes. It is shown in two places: as a status chip on the result card and in the header of the asset view, and as a seal on the tile in the library, which the sidebar calls „Library“.

The signed-in product is in German, so its wording is quoted in German here, with the English rendering in italics.

The three outcomes

On the result and in the asset headerOn the tile in the libraryWhat it means
Content Credentials geprüft
Content Credentials verified
Verifiziert
Verified
Valid and the issuer is on the recognised list. Provenance and editing history are cryptographically confirmed
Signiert · Aussteller unbekannt
Signed · issuer unknown
Nicht vertrauenswürdig
Not trustworthy
Valid, but the issuer is not on the list. The details cannot be reliably confirmed — no proof of manipulation, but no confirmation either
Ohne Content Credentials
Without Content Credentials
Ohne Nachweis
Without a record
There is no valid provenance record in the file. Where there is none at all, that is not a defect — most files carry none

The same file that carries „Signiert · Aussteller unbekannt“ on the result card carries „Nicht vertrauenswürdig“ on its tile.

„Nicht vertrauenswürdig“ says the signer is not on the list. About the file itself it says nothing, in either direction.

The three states before a result

Before a result the tile knows three states:

  • „Ausstehend“ (Pending) — uploaded, but not yet checked. The check can be started from the tile menu or from the editor.
  • „Verify läuft …“ (Verification running …) — the check is running in the background and the status updates itself. It finishes even with the tab closed.
  • „Verify fehlgeschlagen“ (Verification failed) — the check could not be completed. Trying again is the right move here.

In the header of the asset view the three collapse into a single chip: „Nicht verifiziert“ (Not verified). No result exists yet. Which of the three states is behind it is what the seal on the tile tells you.

„Nicht verifiziert“ and „Nicht vertrauenswürdig“ are two different things: one says the check is still outstanding, the other is a finished verdict about the issuer.

„Ausstehend“ (Pending) and „Ohne Nachweis“ (Without a record)

„Ausstehend“ means: not yet checked. A result is missing.

„Ohne Nachweis“ means: checked, and the file carries no valid provenance record. That is a settled result; checking again changes nothing.

The tile menu therefore offers the check only for „Ausstehend“ and for „Verify fehlgeschlagen“ — and even there only while the original file is still held. Once it has been deleted at the end of the retention period, the entry is gone as well.

The details below the chip

Below it the result card lists a few fields: „Manifest“ — „vorhanden“ (present) or „nicht vorhanden“ (not present); „Signatur“ (Signature) — „strukturell gültig“ (structurally valid) or „ungültig“ (invalid); the serial number of the certificate where there is one; the content classification under „Quelle“ (Source); the „Größe“ (Size); and the SHA-256 checksum.

The third outcome has two routes into it, and this list is the only thing that separates them. Where „Manifest“ reads „nicht vorhanden“, the file carries no provenance record — the ordinary case. Where „Manifest“ reads „vorhanden“ and „Signatur“ reads „ungültig“, a manifest was found that failed the integrity check: the file’s integrity cannot then be confirmed against its own manifest. Both cases carry the same chip, „Ohne Content Credentials“ — look at the list.

A change is noticed only on a file that keeps its provenance record. Strip the record out while editing — which many tools do in passing — and the file is indistinguishable from one that never had a record at all.

„Strukturell gültig“ (structurally valid)

It means: the signature is intact and the record is well formed. Nothing beyond that. A self-signed manifest is structurally valid — anybody can produce one.

The question of trust is answered by a second pass against the official list of recognised issuers and timestamp authorities. Only an explicitly positive signal leads to „Verifiziert“; without one the file counts as not trustworthy — that includes the case where the pass never ran.

Whatever that second pass has to report stands above the result in the box „Vertrauensprüfung“ (Trust check); the severities and their consequences are in The six notice severities.

„Von verstag signiert“ (Signed by verstag)

A box carrying that heading may stand above the result, and beneath it:

Das aktuelle Manifest dieser Datei wurde von verstag erstellt und signiert.

The current manifest of this file was created and signed by verstag.

The box appears for files from any verstag customer, not only for those in your workspace, and it says only who produced the current manifest. It also requires the signature to be structurally valid.

The „KI-Quelle“ (AI source) chip

A second status chip may stand beside the result: „KI-Quelle“. It appears for exactly two values taken from the file — „Mit generativer KI erzeugt“ (Created with generative AI) and „Mit generativer KI bearbeitet“ (Edited with generative AI).

The value comes from the file itself and is inherited on import; verstag never invents it. Its absence is not a statement about how the file came about — most files do not carry one.