You solved the hardest half already. Somebody outside the vendor tests the system, on a standard you publish, on a cadence you set.
What nobody has built yet is the receipt for the test itself.
This page is not about what AIUC should buy. It is about four things AIUC could sell.
EvAR signs the evaluation itself: the standard version in force, the model, the rubric, the dataset, the method, the scored items, and the evaluator. It also records whether a contamination check between the dataset and the training data ran, and came back clean.
A validation record that was not written by the team that built the model, and is not merely asserted by the team that ran the test.
maturity Maturity is stated, not implied. EvAR is filed and not released. Model identity receipts are live and verified today.
status · an assertion by the issuer
illustration · synthetic data · not AIUC, insured, or claims data · EvAR is filed and not released
A buyer of certification today takes the certifier's word for it, in the same way the certifier declines to take the vendor's word for it. That is normal practice across every assurance standard.
EvAR closes the last link in that chain, so the assessment becomes an artifact anyone can check offline rather than a document that has to be trusted.
AIUC-1 already handles more of this than most standards do. A certificate runs twelve months, technical tests are re-run at least quarterly, and every control is re-audited annually.
Between those scheduled events, the evidence that decides a claim is still written by the party making it.
Every other line solved that with an instrument. Auto has telematics. Property has inspection. Cargo has surveyors.
AI is the line where the meter and the insured are still the same party.
Certificate validity, quarterly technical testing and annual re-audit: https://aiuc.com/research/aiuc-1-certificate-overview
Both passed the same assessment on the same day. Nine months in, they look identical on paper, because nothing in the record separates them.
illustration · synthetic data · not AIUC, insured, or claims data| record | Insured A | Insured B |
|---|---|---|
| actions inside declared scope | not observed | not observed |
| refusal policy at time of action | not observed | not observed |
| weekend and incident windows | not observed | not observed |
| egress against declared caps | not observed | not observed |
| unreported actions | not observed | not observed |
Neither insured was accused of anything.
The receipts simply exist, and the missing ones simply do not.
AIUC-1 already requires cryptographically verifiable agent identities, just in time permissions, and tool call authorisation and logging. Today those controls are evidenced by records the certified organisation keeps about itself, validated by an accredited auditor.
A verified tier evidences the same control with an independent signed receipt as well.
A grade you define, publish, and price.
earns · tier premium, set by you, at low marginal cost once integratedmaturity EvAR is filed and not released.
A003.2 agent identity and A003.3 agent access and permissions
D003.1 and D003.3 tool call authorisation and logging
E015.4 log integrity protection
Quarterly technical testing and annual re-audit already give the standard a rhythm. What they cannot yet start from is a signed record of conduct that already exists.
Continuous verification means each cycle begins from evidence that was collected as it happened rather than assembled from scratch, so re-certification shortens and confidence rises.
earns · recovered margin on cost of goods, plus a recurring monitored status feematurity PBS is pilot ready and not yet deployed against a live fleet or consortium.
A claim is adjudicated today against the insured's account of its own conduct, investigated on the insured's own systems.
Forensic Rail runs the analysis under a threshold signed consortium credential with every model call replay bonded, so a third party reproduces the finding byte for byte.
boundary Reproducibility and correctness are different claims. Reproducing an analysis shows that the same inputs and settings produce the same result, not that the analysis or its output was correct.
earns · lower loss adjustment expense, fewer coverage disputes, faster closematurity Forensic Rail is pilot ready and not yet deployed against a live fleet or consortium.
Parametric needs a threshold fixed before the outcome and a measurement both sides trust. Neither exists in this market yet.
BPA binds a performance budget declared before the outcome to the measured distribution, on the response itself, with the streamed run pre-committed before the first token. That is a trigger, not a report.
earns · a product category that cannot be written at all todayCommercial structure is not on this page. It is a separate confidential document.
Requirement identifiers reflect the AIUC-1 release of July 15, 2026 and each links to its first party page. This is not a complete catalogue of the standard, which holds 51 requirements and 130 controls across six principles. The next release is due October 15, 2026. Re-verify before use.
how it is evidenced today
Log integrity controls operated by the certified organisation and validated by an accredited auditor.
what the receipt adds
Records are held in a content addressed envelope sealed by its own hash, so changing one byte changes the address and breaks the signature. Integrity is demonstrated by recomputation by any party rather than asserted by the party holding the log.
how it is evidenced today
Logging implementation evidence and retained logs.
what the receipt adds
The decision, the model, the inputs and the outcome are signed into one receipt at the moment of action rather than assembled afterwards, and agent level logging is signed per fragment so the cost does not scale with token volume.
how it is evidenced today
Retention configuration and storage policy.
what the receipt adds
Retention, retrieval and export of signed evidence in one place, so the evidence step of a re-audit starts from a bundle that already exists.
how it is evidenced today
Post incident narrative assembled by the party involved.
what the receipt adds
Analysis run under a threshold signed consortium credential with every model call replay bonded on seed, temperature, top_p and prompt, output and cache digests, so an independent responder reproduces the finding byte for byte.
boundary Reproducibility and correctness are different claims. Reproducing an analysis shows that the same inputs and settings produce the same result, not that the analysis or its output was correct.
maturity Forensic Rail is pilot ready and not yet deployed against a live fleet or consortium.
how it is evidenced today
Configuration evidence and container policy.
what the receipt adds
Declared measurements for the container image, kernel modules, package index, egress rules and GPU firmware are folded into a signed heartbeat chained for the life of the job, so a reported measurement that changes silently, or a heartbeat that stops, breaks the chain at the next interval. This evidences the reported measurements and their continuity, not the hardware itself.
maturity PBS is pilot ready and not yet deployed against a live fleet or consortium.
how it is evidenced today
Permission configuration and grant logs, reviewed at assessment.
what the receipt adds
Clearance signed before the call runs, nothing released on an expired pass, and the delivered action compared against the approved one with the delta recorded on mismatch.
how it is evidenced today
Identity records kept by the certified organisation and validated by an accredited auditor.
what the receipt adds
The acting agent instance is attested and bound into a chained receipt for each decision, and the record is closed with one post-quantum signature over the typed fragments, so an action issued by an automated agent instance and one composed by a person are distinguishable in the record rather than the same log line.
how it is evidenced today
Access control configuration and authentication evidence.
what the receipt adds
Anonymous calls become signed envelopes that declare identity, intent and budget before inference runs, so the access decision and its basis are recorded at the point of entry.
how it is evidenced today
Tool call logs held by the certified organisation.
what the receipt adds
The same tool call metadata, signed by a party that is not the operator, with tool scope, action, context mutation and reward bound around every autonomous step, and every refusal policy mutation chained rather than silently editable.
how it is evidenced today
Policy, rotation records, scanning output and DLP configuration.
what the receipt adds
Egress metered per semantic class against caps committed in advance, and a route reconstructable for review without ever showing the prompt, the data, or the words. A replay manifest that carries a text field fails verification by construction.
how it is evidenced today
Deployment environment controls and integrity checks.
what the receipt adds
Each step commits a model identifier, weights digest, configuration hash and endpoint, so substitution mid run is visible in the record. This attests identity and lineage, not output correctness.
how it is evidenced today
Test reports and third party testing evidence.
what the receipt adds
The evaluation record is signed as an artifact: standard version, rubric, dataset, method, scored items, aggregate score, named evaluator, attestation tier, and whether a contamination check ran and came back clean.
maturity EvAR is filed and not released.
how it is evidenced today
Vendor monitoring records and attestations.
what the receipt adds
Third party call paths receipted on the same rail as first party ones, with provider asserted values held beside separately observed ones, so the monitoring evidence does not rest on the monitored party's own record.
how it is evidenced today
Written allocation of responsibility between platform and deployer.
what the receipt adds
Each receipt carries which party's control was in force at the moment of action, so the boundary is recorded rather than assumed. The changelog describes a supplemental control at E017.3 for platform and deployer security responsibilities and the rendered requirement page numbers its controls differently, so confirm the control level number before use.
Q2-2026 update: https://www.aiuc-1.com/research/2026-q2-standard-update
Q3-2026 update: https://www.aiuc-1.com/research/2026-q3-standard-update
Changelog, release dates: https://www.aiuc-1.com/changelog
Carnac routes proof demand to the instrument a given read warrants, before an effect occurs. It does not evaluate a system, decide whether a control is met, or stand between the operator and any AIUC-1 requirement. Every control obligation stays exactly where the standard puts it.
CarnacPrompt™
Commits the assembled prompt window before the model runs, reading the request as a person types it or an agent builds it. It runs inside the operator boundary and raw forming requests stay there. It records intent at formation, including revisions.
boundary Classifies consequence, not content. Shows what needs context, proof, or permission without changing the words.
Carnac Live Ink™
The live proof, context and permission marking surface, sitting on the InkFrame v1 non mutating substrate. Its four filings are Proof Pre-Fill, InkFrame Non-Mutation, Disclosure-Free Replay and Arrival Countersignature.
boundary Marks and evidences. It does not mutate the request.
Carnac™
Reads consequence and routes each read to the proof it warrants, across four reads: formation, invocation, output and pre-effect, closing with a signed disposition. The floor is Carnac's own decision and ordinary runtime configuration cannot lower it.
boundary These gates protect the paths they sit on. Carnac can only hold an effect that routes through it. No denial of service: work routes to a stronger response and still returns.
Howler™
Binds severity into a signed record and forces an escalation obligation to ride with it to a person, a monitor, or an incident channel. Whether the duty arose, and what disposition followed, is recorded, including the absence of one.
boundary It does not compel action, and we do not claim it does. It does not judge the merits of what was escalated.
The honest status split published on the Carnac page, built and tested, ready to connect, and proposed, applies here unchanged. Carnac control plane · Proof Architecture entry
Each item is an extension AIUC could define, publish and price. None of them is an AIUC statement.
Every row is a Hive recommendation anchored to a requirement AIUC already publishes, and describes an operating need that becomes visible in continuous operation, incident reconstruction, underwriting, claims, renewal, or dispute, which are the moments that sit between scheduled assessments.
Log integrity evidenced by an independent signature as well as by the operator's own controls.
Incident analysis that an independent responder can reproduce, rather than one that is narrated afterwards.
maturity Forensic Rail is pilot ready and not yet deployed against a live fleet or consortium.
Guardrail state recorded at the moment of action as well as at test time, so the setting in force on the day is knowable.
Execution environment integrity evidenced continuously rather than only at boot.
maturity PBS is pilot ready and not yet deployed against a live fleet or consortium.
Human approval that is sensitive to the time regime, since weekend, on call and declared incident windows carry different exposure.
Exposure caps per data class, committed in advance and metered, so cumulative exfiltration is a bounded number.
A performance trigger fixed before the outcome, which is what a parametric structure needs and a report cannot provide.
Proof level set by the party bearing the consequence, before transmission.
Exportable proof state as one underwriting input among many at renewal.
Recovery readiness on consequential financial actions, inside the hours when recovery is still possible.
Human origin evidence for upstream training and fine tuning data, as data supply chains change between assessments.
AIUC-1 is refreshed four times a year and already moves faster than any comparable standard. The only claim here is that a signed, independently checkable record makes several of these cheaper to require, because the evidence is produced as a by-product of operating rather than assembled for an audit.
Hive Proof Architecture holds sixty one primitives. Twenty one carry a direct current AIUC-1 fit. Sixteen of those are the named cards above. The other five are the newest typed receipt contracts, live on the production rail and open to verify, so they sit in the crosswalk rather than the pitch. The rest are placed honestly rather than forced into an agent assurance standard.
21
primary
Direct, current AIUC-1 requirement fit. Sixteen are named above, five are newer and live on the production rail.
16
secondary
Real fit, named for completeness rather than given a card of its own.
6
latent
Anchored to a published requirement, listed under continuous operating evidence.
9
technical companion
Supporting mechanism, carried in the technical companion rather than the pitch.
9
outside agent scope
A different line of work. Listed here for completeness, deliberately absent from the pitch.
| # | Primitive | Tier | AIUC-1 anchor or reason |
|---|---|---|---|
| 01 | InkFrame v1 | primary | E015.1 · E015.4 |
| 02 | Proof Pre-Fill | secondary | E015 · D003.3 |
| 03 | InkFrame Non-Mutation | primary | E015.4 |
| 04 | Disclosure-Free Replay | primary | A006 · A003 · E015 |
| 05 | Arrival Countersignature | primary | D003.1 · D003.4 |
| 06 | PBS | primary | B006.3 · B008 |
| 07 | Refusal Ledger | latent | C003 · C004 · C005 |
| 08 | Howler routed by Carnac | primary | C007 · C009 · C008 |
| 09 | Perimeter Bond | secondary | B006.1 · A006.3 |
| 10 | Diurnal Bond | latent | D003.4 · E001 |
| 11 | Egress Bond | primary | A006 · A004 · A008 · B009.1 |
| 12 | Forensic Rail | primary | E001.4 |
| 13 | SiGR | primary | E015.1 · E015.2 · D003.3 |
| 14 | S2S | secondary | B008.4 · B008.5 · E011 |
| 15 | PPR | outside agent scope | Not applicable to AIUC-1 agent assurance. Wearables provenance, outside AIUC-1's agent scope. |
| 16 | AFIR | technical companion | E015.2, attestation economics |
| 17 | MiR | primary | B008.5 · E017 |
| 18 | MiR-M | technical companion | D001, patent pending and not released |
| 19 | MPP | technical companion | D001 · E006, not released |
| 20 | MaR | technical companion | D001, not released |
| 21 | EvAR | primary | C002 · B001 · C010 to C012 |
| 22 | HiveBound | primary | A003.2 · B007 · B008.1 |
| 23 | Imprimatur | primary | D003.1 · A003.3 |
| 24 | XCALIBUR | secondary | A003 · D001 · B003 |
| 25 | Foretoken™ | secondary | E015 · B009 |
| 26 | Stipryn™ | secondary | A001 · E010 · E017 |
| 27 | MSDD | secondary | B008.5 · E006 · E009 |
| 28 | BPA | latent | E013 · E017 |
| 29 | AFiR-Stream | secondary | C009 · E015 · E016 |
| 30 | Media Origin Receipt | secondary | A007 · A002 |
| 31 | MoRSo Segments of Origin | technical companion | A007 · C003 |
| 32 | Signed Royalty-Provenance | outside agent scope | Not applicable to AIUC-1 agent assurance. Royalty settlement, outside agent scope. |
| 33 | OriginProof | latent | A001 · E006 |
| 34 | AFiR-OCR DocProof | secondary | D001 · C007 |
| 35 | AFiR-S3 | primary | D003.1 · D003.3 · D003.5 |
| 36 | SmartAgent Route Graph | secondary | E015.2 · E009 · E017 |
| 37 | Agent Trip and SPIRE | primary | A003.2 · B006 |
| 38 | HiveGate and HiveMorph | secondary | A003.2 · E009 · E006 |
| 39 | Hive Provable Machines | outside agent scope | Not applicable to AIUC-1 agent assurance. Robotics line, outside agent scope. |
| 40 | Protected Flow Fleets | secondary | E015.3 · E008 |
| 41 | R3Pv | secondary | C008 · E008 |
| 42 | Protected Flow | latent | D003.4 · E001 |
| 43 | Hive Receipt | outside agent scope | Not applicable to AIUC-1 agent assurance. Settlement rail, not an agent assurance control. |
| 44 | Proof Credit | latent | E004 · E008 |
| 45 | Structural Lateration | technical companion | Metering mechanism, not a control |
| 46 | Hive Settlement Feed | outside agent scope | Not applicable to AIUC-1 agent assurance. Market data integrity, a different line. |
| 47 | Hive Typed Signer | technical companion | E015.4, signing infrastructure |
| 48 | HiveSeal QPuF | technical companion | B008 · E005 |
| 49 | Sovereign AI Receipt Registry | outside agent scope | Not applicable to AIUC-1 agent assurance. Sovereign deployment model. |
| 50 | Hive Command Center | technical companion | E017, public transparency surface |
| 51 | Hive Customer Console | primary | E015.3 · E008 |
| 52 | HVVS | outside agent scope | Not applicable to AIUC-1 agent assurance. Elections integrity, unrelated to agent assurance. |
| 53 | Evaluation Administration Receipt live, open to verify | primary | C002 · C010 · C012 |
| 54 | Mandate Conformance Receipt live, open to verify | primary | D003.1 · D003.3 · B007 |
| 55 | Causal Path Receipt live, open to verify | primary | E015.4 · E001.4 |
| 56 | Knowledge Timestamp Receipt live, open to verify | primary | E001.4 · C008 |
| 57 | Ledger Parity Receipt live, open to verify | primary | E006 · E015.2 |
| 58 | Screening Attestation Receipt live, open to verify | secondary | E006 · E009 |
| 59 | Cumulative Mandate Receipt live, open to verify | secondary | D003.3 · E008 |
| 60 | Parametric Trigger Receipt live, open to verify | outside agent scope | Not an AIUC-1 control. Parametric cover mechanics, an underwriting side instrument. |
| 61 | Portfolio Exposure Receipt live, open to verify | outside agent scope | Not an AIUC-1 control. Concentration measurement across a book, an underwriting side instrument. |
Twenty one primary, sixteen secondary, six latent, nine technical companion only, nine outside AIUC-1 agent assurance scope. Sixty one in total. Nine of these are the newest typed receipt contracts, all live on the production rail and open to verify, and they are counted here so the accounting stays complete. The Carnac control plane is a routing layer over these primitives, not a fifty third primitive.
Streamed response pre-commitment. The commitment to a streamed run is fixed and witnessed before the first token, an incremental digest runs without buffering the whole response, and a terminal attestation is sealed at the close and bound to that opening commitment. A verifier checks that the thing that ended is the thing that was promised, and a missing terminal attestation is itself meaningful.
Stipryn™ fixes the required proof level before transmission, while the party bearing the consequence still controls the request. It does not alter, rewrite, or filter the request. It sets how much proof has to accompany it.
Provider asserted values and separately observed values are held apart in the record rather than reconciled into one number, so disagreement about which model or version served a step is readable straight from the structure.
A performance budget declared before the outcome is bound to the measured distribution on the response itself. Fixed in advance and signed, it can act as a trigger rather than a report.
A well behaved insured and a well audited one look the same at renewal, because nothing in the record separates them. Verified conduct lets the better risk earn the better rate, and the book self selects toward it.
Certification rewards passing the assessment. Continuous evidence also rewards behaving after the certificate is issued, which is a different and complementary incentive.
A requirement for independently signed evidence is one that no single party can satisfy alone, because the signature has to come from someone other than the party being measured. Whoever writes it first sets its shape.
We test nothing, score nothing, and certify nothing. The standard and the assessment remain entirely yours. We sign the record of yours.
We produce measurements. What a measurement is worth to a policy is an underwriting judgment we take no part in.
Receipts prove identity, sequence, scope, and integrity. Reproducibility and correctness are different claims. Whether an answer was good is a different question, and that refusal is carried inside the signed payload.
We never read prompt or response content. Every request is recorded as a one way SHA-256 fingerprint rather than the words, so we can attest that a check ran and what its conditions were, not what was said.
Weights, activations, hidden reasoning and any other internal state of a model are outside what a receipt observes. We record declared and externally observable facts about a run, not what happened inside the model.
A receipt does not establish that a particular chip executed the work, and it does not by itself prove firmware or kernel module integrity. What the sandbox chain shows is that reported measurements stayed consistent and unbroken for the life of the job. Statements about silicon require an independently verified hardware attestation source, such as a report signed by the GPU security processor, to be integrated explicitly and scoped in writing.
EvAR is filed and not released. PBS and Forensic Rail are pilot ready and not yet deployed against a live fleet or consortium. S2S has its cryptographic core complete with real silicon pending. Model identity receipts are live and verified today.
Ordinary requests composed by a person are receipted on the same rail as automated ones, so coverage does not depend on how the request was authored.
The record starts the day it is switched on. We cannot reconstruct a record that was never made, which is the argument for switching it on before a claim rather than during one.
Hive sits beside the deployment, never in the request path. If Hive is slow, unavailable, or switched off entirely, the AIUC assessment, the policy and the customer workflow keep operating exactly as they do today. Nothing blocks and nothing queues behind us.
Receipts already issued do not depend on Hive continuing to exist. Verification is free, works offline against the Hive public key, requires no account, and stays valid whether or not the instrument is still switched on.
What a receipt covers is bounded on purpose. Model internals are never observed, and hardware level statements are only made where an independently verified hardware attestation source is integrated and named.
The ask is
small on purpose
A verified tier considered for a future revision of the standard, piloted on one certified account for thirty days, with the assessment itself signed under EvAR. We sit beside the deployment. Nothing in the request path, no customer data, fail open, stop any day.
At the end you hold signed conduct from a live insured, and a signed record of your own assessment, and you decide whether either changes anything. The most useful test is to try to break one.
maturity, stated before the ask EvAR is filed and not released. PBS and Forensic Rail are pilot ready and not yet deployed against a live fleet or consortium. S2S has its cryptographic core complete with real silicon pending. Model identity receipts are live and verified today.
Technical companion. The full requirement mapping, the receipt structure, and the verification path are set out in the builder brief: AIUC Builder Brief, PDF, 15 pages.
sources · AIUC https://aiuc.com/ · AIUC-1 https://www.aiuc-1.com/ · certificate overview https://aiuc.com/research/aiuc-1-certificate-overview · certification process https://www.aiuc-1.com/aiuc-1-certification · Q2-2026 update https://www.aiuc-1.com/research/2026-q2-standard-update · Q3-2026 update https://www.aiuc-1.com/research/2026-q3-standard-update · changelog https://www.aiuc-1.com/changelog · checked August 1, 2026
Private architecture note prepared for AIUC · noindex / nofollow / noarchive · this page does not state or imply that AIUC is a customer, partner, pilot, or endorser, and it is not affiliated with, endorsed by, or produced in cooperation with AIUC or with any auditor, insurer, or reinsurer · the insureds, certificates, timelines, and figures shown are illustrations of how the flow works and are not AIUC, insured, or claims data; nothing here is a forecast, a quote, a rate, or a representation about any book of business · Hive records what an automated decision was and which rule was checked; it does not audit, certify, score, or price risk, and a signed record that a rule ran is not a statement of legal or regulatory compliance · we record conditions, never verdicts · we never read prompt or response content, and every request is recorded as a one way SHA-256 fingerprint rather than the words · verification is free, works offline against the Hive public key, and requires no account · signatures use ML-DSA-65 under NIST FIPS 204, anchored on Base · Carnac™, CarnacPrompt™, Carnac Live Ink™, Carnac Gateway™, Foretoken™ and Stipryn™ are Hive marks; all Hive primitives are patent pending · control area descriptions are written generically from public materials as of August 2026 and should be re-verified before external use · prepared by Steve Rotzin, Founder, Hive Civilization Inc. · Wyoming, USA
These newer receipts add a checkable record of how an evaluation was run and a bounded path through later evidence. They are live on the production rail and the runs below verify real signed receipts.
This receipt binds one named evaluation administration arrangement to a specific evaluation attestation. It records that the test set fingerprint was committed before the subject knew its contents and before the test window opened. It also recalculates the stated independence class from the declared relationship and separation of duties instead of trusting the caller's label. That gives an assurance team a checkable record of how the evaluation was administered alongside the evaluation attestation.
What it does not do. It does not contain, restate, or attest to any evaluation score or result, or validate the test set's suitability or representativeness, whether the subject got the test items another way, the method, or administrator competence. It is not accreditation, certification, or an audit opinion, and no standards body, regulator, or insurer recognizes it as one.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
This receipt checks whether named receipts form one unbroken fingerprint chain from the first record to the last record. It recalculates whether each declared input matches the prior declared output and whether recorded times run forward. It reports the continuity finding rather than accepting it from the caller. For an assurance or insurance team, it preserves a bounded evidence path to review when a later claim points back to an evaluated system.
What it does not do. It does not show that the origin caused the terminus, that the terminus caused a claimed effect, that a claimed effect occurred, or that anyone suffered harm, and the service does not receive a description of the claimed effect. It does not show this is the only relevant chain, rule out a parallel or intervening cause, establish liability, or offer an expert opinion on causation.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.
Every run above posts a verified request body from this domain to the open verify route and prints what came back. The example receipts are signed with published example keys, so verify reports key_trust example_registry. That is on purpose. Nothing on this page is a production issuance, a customer record, or an endorsement. Patent Pending.
Each link opens that entry in the canon implementation explorer, where its schema, mint route, open verify route, auth requirement and implementation state are stated. The state shown here is read from the same registry file the explorer renders from, so the two cannot drift apart. Nothing here implies a customer, a deployment or an endorsement.