← Research

Field note · Public sector verification

Field verification instrument design for donor-funded programmes.

A verification record is not judged on the day it is captured. It is judged years later, by someone who was not there, looking for a reason to doubt it.

The audience is the future auditor

Donor-funded programmes run on verified claims: that an installation exists, that it serves who it claims to serve, that it works. The verification instrument, the structured form a field agent completes at the site, is where those claims become records. Designing one looks like form design and is actually evidence design. The question for every field on the instrument is not whether it is convenient to capture, but whether the record it produces will convince a sceptical reviewer long after the visit, when memory is gone and only the record remains.

That audience reshapes the details. Free-text observations, persuasive in the moment, age poorly and resist aggregation; the instrument prefers closed responses with a bounded escape hatch. Every capture carries its coordinates, its timestamps and its device identity, not because any one of them proves anything alone, but because fabrication has to defeat all of them at once, consistently, across thousands of records.

Offline is the operating condition, integrity is the requirement

Verification happens where the infrastructure is, which is precisely where connectivity is not. The instrument must work fully offline, hold days of capture on the device, and sync when signal returns. That is a solved engineering problem. The harder question is what offline does to integrity: a record that sits editable on a device for a week before upload is a record whose history cannot be defended.

Our answer is a hash chain over the capture sequence. Each record is sealed as it is completed and linked to the one before it, so the chain arriving at the server demonstrates that records were not inserted, deleted or reworked between capture and sync. Corrections remain possible, but they are new entries that reference what they correct, preserving both versions and the reason. The field agent loses nothing except the ability to silently rewrite the past, which is exactly the ability the record's future reader needs them not to have.

Harmonisation is a data quality decision

Programmes accumulate instruments the way projects accumulate spreadsheets: one per component, drafted by different teams, asking almost the same questions in incompatible ways. The cost lands later, when results must be aggregated and the same fact exists in six shapes. Harmonising the instrument set, shared identifiers, shared response scales, shared site and beneficiary references, is unglamorous committee work, and it is the difference between a programme dataset and a pile of forms. It also disciplines scope: a question that cannot be answered consistently by every team that will ask it is a question the instrument set is not ready to carry.

Separating the platform from the mandate

One structural point matters more than any feature. The party that builds and operates the capture platform should not be confused with the party that holds the verification mandate. We build the instruments and the audit machinery; the verification judgement belongs to the independent agent contracted to make it. Keeping that boundary explicit, in the system's roles and in public description of the work, protects the thing the whole apparatus exists to produce: a finding that is independent, and demonstrably so.

Verification systems are part of our public sector practice.