See the stars

VerifyRights Specification

Home / VerifyRights / VerifyRights Specification

VerifyRights

AI that watches your licenses so you do not have to.


VerifyRights is an open specification for intelligent software license verification, commercial usage monitoring, and enterprise compliance intelligence. The specification defines a standardized framework for tracking commercial license holders, authorized entities, license terms, approved websites and networks, and verifiable evidence of software deployment and usage.

VerifyRights is designed to help specification owners, software vendors, and commercial licensors monitor licensing agreements at scale by combining verifiable records, corporate relationship mapping, and AI-assisted compliance analysis. The specification produces evidence and risk indicators for human review and does not automatically determine legal violations.

Objectives

  • Establish a verifiable registry of commercial license holders.
  • Track authorized corporate entities and affiliates.
  • Monitor approved websites, networks, and deployments.
  • Detect potential discrepancies between license terms and actual usage.
  • Preserve evidence and chain of custody records.
  • Provide AI-assisted compliance intelligence.
  • Support human review and governance.
  • Create interoperable, vendor-neutral licensing records.

Core Principles

  • Open standards
  • Vendor neutrality
  • Human-in-the-loop governance
  • Evidence-based analysis
  • Explainable AI
  • Verifiable records
  • Privacy-first architecture
  • Modular design
  • Federation support
  • Interoperability

Specification Components

License Registry

Stores and manages:

  • License identifiers
  • License type
  • License tier
  • Purchase dates
  • Renewal dates
  • Expiration dates
  • License terms
  • User limits
  • Seat limits
  • Deployment limits
  • Geographic restrictions
  • Product restrictions
  • Custom agreements
  • Contract amendments
  • Authorized websites
  • Authorized domains
  • Authorized networks
  • Authorized organizations
  • Authorized subsidiaries
  • Licensing contacts

Corporate Identity Registry

Maintains records for:

  • Legal entity names
  • Parent corporations
  • Subsidiaries
  • DBA entities
  • Acquired companies
  • Affiliate organizations
  • Brand ownership
  • Corporate hierarchy
  • Shared ownership relationships
  • Shared infrastructure relationships

Authorized Deployment Registry

Tracks:

  • Approved domains
  • Internal networks
  • External websites
  • Product deployments
  • Cloud environments
  • Customer portals
  • Mobile applications
  • API endpoints
  • Enterprise instances
  • Distribution channels

Commercial Usage Intelligence Engine

Collects and correlates evidence from:

  • Public websites
  • Documentation
  • Product pages
  • Marketing materials
  • Corporate reports
  • Technical metadata
  • Public repositories
  • Procurement records
  • Knowledge bases
  • Support portals
  • Domain registrations
  • Public filings
  • Job postings
  • Customer references

AI Compliance Engine

Provides:

  • License term analysis
  • Contract interpretation assistance
  • Deployment pattern recognition
  • Affiliate detection
  • Organizational scale estimation
  • Commercial usage estimation
  • Relationship mapping
  • Risk scoring
  • Compliance recommendations
  • Evidence summarization

AI Compliance Engine Module Specification

Overview

The AI Compliance Engine is a core VerifyRights module responsible for analyzing licensing agreements, evaluating commercial usage patterns, identifying potential compliance risks, and generating explainable recommendations. The module uses multiple specialized AI agents to analyze license terms, corporate relationships, deployment evidence, and organizational usage patterns while maintaining human-in-the-loop governance.

The AI Compliance Engine does not make legal determinations. It provides evidence-based analysis, risk indicators, and compliance recommendations for human review.


Multi-Agent Architecture

Agent 1: License Term Analysis Agent

Purpose

Analyzes licensing agreements and extracts structured licensing requirements.

Responsibilities
  • Parse license agreements and terms of service.
  • Extract user limits and deployment restrictions.
  • Identify authorized entities.
  • Identify geographic restrictions.
  • Identify product and service limitations.
  • Detect renewal and expiration requirements.
  • Convert legal language into structured compliance rules.
  • Maintain machine-readable license profiles.
Inputs
  • License documents
  • Contract terms
  • Amendments
  • Licensing policies
Outputs
  • Structured license rules
  • Entitlement records
  • Compliance requirements
  • License constraint models

Agent 2: Contract Interpretation Assistance Agent

Purpose

Provides AI-assisted interpretation of contractual language.

Responsibilities

  • Identify important contractual clauses.
  • Detect exceptions and exclusions.
  • Analyze amendment impacts.
  • Compare contract versions.
  • Identify ambiguous language.
  • Highlight clauses requiring human review.
  • Explain contract requirements in plain language.

Inputs

  • Contracts
  • Amendments
  • License agreements

Outputs

  • Contract summaries
  • Clause analysis
  • Interpretation notes
  • Review recommendations

Agent 3: Deployment Pattern Recognition Agent

Purpose

Analyzes evidence to identify software deployment patterns.

Responsibilities

  • Detect deployment locations.
  • Identify application instances.
  • Analyze technical fingerprints.
  • Identify cloud and infrastructure usage.
  • Compare observed deployments against authorized deployments.
  • Detect unexpected expansion patterns.

Inputs

  • Deployment metadata
  • Public documentation
  • Infrastructure records
  • Application information

Outputs

  • Deployment maps
  • Usage patterns
  • Deployment risk indicators

Agent 4: Affiliate Detection Agent

Purpose

Identifies related organizations that may be using licensed technology.

Responsibilities

  • Map parent companies and subsidiaries.
  • Detect corporate ownership relationships.
  • Identify shared infrastructure.
  • Analyze shared domains.
  • Detect brand relationships.
  • Identify possible affiliate usage.

Inputs

  • Corporate records
  • Domain information
  • Ownership data
  • Public company information

Outputs

  • Corporate relationship graph
  • Affiliate probability scores
  • Relationship evidence

Agent 5: Organizational Scale Estimation Agent

Purpose

Estimates organizational size and compares it against licensing limits.

Responsibilities

  • Estimate employee counts.
  • Analyze business unit structures.
  • Identify enterprise scale indicators.
  • Compare organization size against purchased license tiers.
  • Detect potential mismatch between license scope and organization size.

Inputs

  • Corporate information
  • Public records
  • Company profiles
  • Employment data

Outputs

  • Organization scale estimates
  • License scope comparison
  • Risk indicators

Agent 6: Commercial Usage Estimation Agent

Purpose

Estimates real-world commercial usage of licensed technology.

Responsibilities

  • Estimate user populations.
  • Identify business departments.
  • Analyze customer-facing usage.
  • Detect enterprise-wide adoption patterns.
  • Evaluate deployment footprint.
  • Compare observed usage against purchased entitlements.

Inputs

  • Usage evidence
  • Deployment records
  • Documentation
  • Public references

Outputs

  • Usage estimates
  • Commercial footprint reports
  • Expansion indicators

Agent 7: Relationship Mapping Agent

Purpose

Creates an intelligence graph connecting licenses, organizations, deployments, and evidence.

Responsibilities

  • Build entity relationship graphs.
  • Connect license holders to subsidiaries.
  • Map authorized and observed deployments.
  • Track ownership changes.
  • Identify indirect relationships.
  • Maintain historical relationship records.

Inputs

  • License registry
  • Corporate records
  • Deployment evidence

Outputs

  • Relationship graphs
  • Entity connections
  • Historical mappings

Agent 8: Risk Scoring Agent

Purpose

Calculates compliance risk indicators.

Responsibilities

  • Analyze collected evidence.
  • Evaluate license discrepancies.
  • Assign confidence levels.
  • Calculate risk scores.
  • Prioritize investigations.
  • Explain contributing factors.

Risk Categories

Informational

Minor inconsistencies requiring monitoring.

Warning

Potential licensing discrepancy requiring review.

High Risk

Strong indicators of expanded usage beyond terms.

Critical

Substantial evidence requiring immediate evaluation.

Outputs

  • Risk score
  • Risk category
  • Evidence summary
  • Recommended actions

Agent 9: Compliance Recommendation Agent

Purpose

Provides actionable recommendations based on evidence.

Responsibilities

  • Recommend review actions.
  • Identify missing information.
  • Suggest additional evidence collection.
  • Recommend licensing discussions.
  • Generate compliance workflows.
  • Support remediation planning.

Outputs

  • Compliance recommendations
  • Review workflows
  • Remediation suggestions

Agent 10: Evidence Summarization Agent

Purpose

Creates human-readable compliance reports.

Responsibilities

  • Summarize findings.
  • Organize evidence.
  • Explain AI conclusions.
  • Link findings to sources.
  • Generate audit documentation.
  • Preserve evidence history.

Outputs

  • Compliance reports
  • Investigation summaries
  • Evidence packages

Shared AI Governance Layer

All agents operate under shared governance requirements:

Explainability

  • Provide reasoning for findings.
  • Identify evidence sources.
  • Display confidence levels.

Human Review

  • No automatic legal conclusions.
  • Human approval required for enforcement actions.
  • Support investigator workflows.

Privacy Protection

  • Minimize unnecessary data collection.
  • Protect sensitive business information.
  • Support access controls.

Auditability

  • Record agent actions.
  • Maintain decision history.
  • Preserve evidence integrity.

Module Outputs

The AI Compliance Engine produces:

  • License compliance assessments
  • Risk scores
  • Corporate relationship graphs
  • Deployment analysis reports
  • Evidence summaries
  • Compliance recommendations
  • Investigation workflows
  • Audit-ready documentation

Integration Points

The AI Compliance Engine integrates with:

  • License Registry
  • Corporate Identity Registry
  • Authorized Deployment Registry
  • Verification and Evidence Layer
  • Reporting Dashboard
  • Governance Framework

Future Extensions

  • Autonomous compliance agents
  • Federated license intelligence networks
  • Machine-readable contract standards
  • Predictive compliance modeling
  • Blockchain-based evidence verification
  • Cross-platform licensing intelligence exchange

Enterprise Relationship Graph

Maps:

  • Parent companies
  • Subsidiaries
  • Mergers
  • Acquisitions
  • Shared services
  • Shared authentication systems
  • Shared infrastructure
  • Brand ownership
  • Operating divisions
  • International entities

Verification and Evidence Layer

Supports:

  • Source attribution
  • Timestamped records
  • Digital signatures
  • Cryptographic hashes
  • Immutable audit history
  • Evidence snapshots
  • Chain of custody records
  • Exportable evidence packages
  • Compliance reports

AI Monitoring Capabilities

License Expansion Detection

Identifies potential situations where:

  • Purchased license tiers appear inconsistent with organizational size.
  • Deployments exceed authorized limits.
  • Usage appears to extend beyond approved entities.
  • Additional business units appear to be using licensed technology.

Affiliate Monitoring

Detects:

  • Subsidiary usage
  • Shared infrastructure usage
  • Cross-brand deployments
  • Shared authentication systems
  • Shared employee environments
  • Shared corporate resources

Commercial Usage Estimation

Estimates:

  • User counts
  • Department counts
  • Geographic distribution
  • Enterprise-wide implementation probability
  • Infrastructure footprint
  • Organizational usage patterns

Risk Classification

Informational

Minor inconsistencies requiring monitoring.

Warning

Potential discrepancy requiring review.

High Risk

Strong indicators of expanded commercial usage.

Critical

Substantial evidence of unauthorized enterprise deployment.


Example Scenario

Purchased License

  • Up to 1,000 users
  • Single corporate entity
  • Two authorized domains

Observed Evidence

  • Employee count exceeds 300,000.
  • Deployment references found across multiple domains.
  • Multiple business units reference the technology.
  • Public documentation suggests enterprise-wide implementation.

AI Assessment

  • Risk classification: High
  • Recommendation: Human review required.

Human-in-the-Loop Governance

VerifyRights provides evidence and recommendations only.

Human reviewers determine:

  • Whether a license violation exists.
  • Whether additional licensing is required.
  • Whether contractual exceptions apply.
  • Whether evidence is sufficient.
  • Whether commercial terms have been exceeded.

Potential Use Cases

  • Open source commercial licensing
  • Enterprise software licensing
  • Specification branding licenses
  • SaaS licensing compliance
  • Multi-tenant licensing verification
  • Affiliate usage monitoring
  • Contract compliance auditing
  • Commercial rights management
  • License entitlement verification
  • Enterprise governance programs

Future Extensions

  • Blockchain evidence anchoring
  • Federated compliance networks
  • Machine-readable license contracts
  • Automated notice generation
  • Third-party verification services
  • Cross-vendor compliance exchanges
  • Standardized licensing APIs
  • Compliance reporting schemas

Specification Branding License (SBL)

Standard

Optional


License & Notice Requirements

VerifyRights is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.

Please note the following:

  • All contributions must comply with the AGPL-3.0+ terms.
  • Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
  • VerifyRights specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
  • The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update notice.md.
  • When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
  • Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.

For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.


Notice – VerifyRights

Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.

Contributors

This file tracks contributors and their specific contributions to the project.

  • Roxanne Ardary, roxanneardary.com – July 15, 2026
    Created the repository for VerifyRights. Authored the open specification for AI-driven software license verification, commercial usage monitoring, and enterprise compliance intelligence.
  • [Add other contributors here] – [Date]
    [Describe contribution in one sentence]

License – VerifyRights

This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).

Key Points

  • You are free to use, modify, and distribute the code.
  • All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
  • The software is provided “as is,” without warranty of any kind.

For the full license text, see GNU AGPL-3.0 License.