Home / VerifyRights / VerifyRights Specification
VerifyRights
AI that watches your licenses so you do not have to.
VerifyRights is an open specification for intelligent software license verification, commercial usage monitoring, and enterprise compliance intelligence. The specification defines a standardized framework for tracking commercial license holders, authorized entities, license terms, approved websites and networks, and verifiable evidence of software deployment and usage.
VerifyRights is designed to help specification owners, software vendors, and commercial licensors monitor licensing agreements at scale by combining verifiable records, corporate relationship mapping, and AI-assisted compliance analysis. The specification produces evidence and risk indicators for human review and does not automatically determine legal violations.
Objectives
- Establish a verifiable registry of commercial license holders.
- Track authorized corporate entities and affiliates.
- Monitor approved websites, networks, and deployments.
- Detect potential discrepancies between license terms and actual usage.
- Preserve evidence and chain of custody records.
- Provide AI-assisted compliance intelligence.
- Support human review and governance.
- Create interoperable, vendor-neutral licensing records.
Core Principles
- Open standards
- Vendor neutrality
- Human-in-the-loop governance
- Evidence-based analysis
- Explainable AI
- Verifiable records
- Privacy-first architecture
- Modular design
- Federation support
- Interoperability
Specification Components
License Registry
Stores and manages:
- License identifiers
- License type
- License tier
- Purchase dates
- Renewal dates
- Expiration dates
- License terms
- User limits
- Seat limits
- Deployment limits
- Geographic restrictions
- Product restrictions
- Custom agreements
- Contract amendments
- Authorized websites
- Authorized domains
- Authorized networks
- Authorized organizations
- Authorized subsidiaries
- Licensing contacts
Corporate Identity Registry
Maintains records for:
- Legal entity names
- Parent corporations
- Subsidiaries
- DBA entities
- Acquired companies
- Affiliate organizations
- Brand ownership
- Corporate hierarchy
- Shared ownership relationships
- Shared infrastructure relationships
Authorized Deployment Registry
Tracks:
- Approved domains
- Internal networks
- External websites
- Product deployments
- Cloud environments
- Customer portals
- Mobile applications
- API endpoints
- Enterprise instances
- Distribution channels
Commercial Usage Intelligence Engine
Collects and correlates evidence from:
- Public websites
- Documentation
- Product pages
- Marketing materials
- Corporate reports
- Technical metadata
- Public repositories
- Procurement records
- Knowledge bases
- Support portals
- Domain registrations
- Public filings
- Job postings
- Customer references
AI Compliance Engine
Provides:
- License term analysis
- Contract interpretation assistance
- Deployment pattern recognition
- Affiliate detection
- Organizational scale estimation
- Commercial usage estimation
- Relationship mapping
- Risk scoring
- Compliance recommendations
- Evidence summarization
AI Compliance Engine Module Specification
Overview
The AI Compliance Engine is a core VerifyRights module responsible for analyzing licensing agreements, evaluating commercial usage patterns, identifying potential compliance risks, and generating explainable recommendations. The module uses multiple specialized AI agents to analyze license terms, corporate relationships, deployment evidence, and organizational usage patterns while maintaining human-in-the-loop governance.
The AI Compliance Engine does not make legal determinations. It provides evidence-based analysis, risk indicators, and compliance recommendations for human review.
Multi-Agent Architecture
Agent 1: License Term Analysis Agent
Purpose
Analyzes licensing agreements and extracts structured licensing requirements.
Responsibilities
- Parse license agreements and terms of service.
- Extract user limits and deployment restrictions.
- Identify authorized entities.
- Identify geographic restrictions.
- Identify product and service limitations.
- Detect renewal and expiration requirements.
- Convert legal language into structured compliance rules.
- Maintain machine-readable license profiles.
Inputs
- License documents
- Contract terms
- Amendments
- Licensing policies
Outputs
- Structured license rules
- Entitlement records
- Compliance requirements
- License constraint models
Agent 2: Contract Interpretation Assistance Agent
Purpose
Provides AI-assisted interpretation of contractual language.
Responsibilities
- Identify important contractual clauses.
- Detect exceptions and exclusions.
- Analyze amendment impacts.
- Compare contract versions.
- Identify ambiguous language.
- Highlight clauses requiring human review.
- Explain contract requirements in plain language.
Inputs
- Contracts
- Amendments
- License agreements
Outputs
- Contract summaries
- Clause analysis
- Interpretation notes
- Review recommendations
Agent 3: Deployment Pattern Recognition Agent
Purpose
Analyzes evidence to identify software deployment patterns.
Responsibilities
- Detect deployment locations.
- Identify application instances.
- Analyze technical fingerprints.
- Identify cloud and infrastructure usage.
- Compare observed deployments against authorized deployments.
- Detect unexpected expansion patterns.
Inputs
- Deployment metadata
- Public documentation
- Infrastructure records
- Application information
Outputs
- Deployment maps
- Usage patterns
- Deployment risk indicators
Agent 4: Affiliate Detection Agent
Purpose
Identifies related organizations that may be using licensed technology.
Responsibilities
- Map parent companies and subsidiaries.
- Detect corporate ownership relationships.
- Identify shared infrastructure.
- Analyze shared domains.
- Detect brand relationships.
- Identify possible affiliate usage.
Inputs
- Corporate records
- Domain information
- Ownership data
- Public company information
Outputs
- Corporate relationship graph
- Affiliate probability scores
- Relationship evidence
Agent 5: Organizational Scale Estimation Agent
Purpose
Estimates organizational size and compares it against licensing limits.
Responsibilities
- Estimate employee counts.
- Analyze business unit structures.
- Identify enterprise scale indicators.
- Compare organization size against purchased license tiers.
- Detect potential mismatch between license scope and organization size.
Inputs
- Corporate information
- Public records
- Company profiles
- Employment data
Outputs
- Organization scale estimates
- License scope comparison
- Risk indicators
Agent 6: Commercial Usage Estimation Agent
Purpose
Estimates real-world commercial usage of licensed technology.
Responsibilities
- Estimate user populations.
- Identify business departments.
- Analyze customer-facing usage.
- Detect enterprise-wide adoption patterns.
- Evaluate deployment footprint.
- Compare observed usage against purchased entitlements.
Inputs
- Usage evidence
- Deployment records
- Documentation
- Public references
Outputs
- Usage estimates
- Commercial footprint reports
- Expansion indicators
Agent 7: Relationship Mapping Agent
Purpose
Creates an intelligence graph connecting licenses, organizations, deployments, and evidence.
Responsibilities
- Build entity relationship graphs.
- Connect license holders to subsidiaries.
- Map authorized and observed deployments.
- Track ownership changes.
- Identify indirect relationships.
- Maintain historical relationship records.
Inputs
- License registry
- Corporate records
- Deployment evidence
Outputs
- Relationship graphs
- Entity connections
- Historical mappings
Agent 8: Risk Scoring Agent
Purpose
Calculates compliance risk indicators.
Responsibilities
- Analyze collected evidence.
- Evaluate license discrepancies.
- Assign confidence levels.
- Calculate risk scores.
- Prioritize investigations.
- Explain contributing factors.
Risk Categories
Informational
Minor inconsistencies requiring monitoring.
Warning
Potential licensing discrepancy requiring review.
High Risk
Strong indicators of expanded usage beyond terms.
Critical
Substantial evidence requiring immediate evaluation.
Outputs
- Risk score
- Risk category
- Evidence summary
- Recommended actions
Agent 9: Compliance Recommendation Agent
Purpose
Provides actionable recommendations based on evidence.
Responsibilities
- Recommend review actions.
- Identify missing information.
- Suggest additional evidence collection.
- Recommend licensing discussions.
- Generate compliance workflows.
- Support remediation planning.
Outputs
- Compliance recommendations
- Review workflows
- Remediation suggestions
Agent 10: Evidence Summarization Agent
Purpose
Creates human-readable compliance reports.
Responsibilities
- Summarize findings.
- Organize evidence.
- Explain AI conclusions.
- Link findings to sources.
- Generate audit documentation.
- Preserve evidence history.
Outputs
- Compliance reports
- Investigation summaries
- Evidence packages
Shared AI Governance Layer
All agents operate under shared governance requirements:
Explainability
- Provide reasoning for findings.
- Identify evidence sources.
- Display confidence levels.
Human Review
- No automatic legal conclusions.
- Human approval required for enforcement actions.
- Support investigator workflows.
Privacy Protection
- Minimize unnecessary data collection.
- Protect sensitive business information.
- Support access controls.
Auditability
- Record agent actions.
- Maintain decision history.
- Preserve evidence integrity.
Module Outputs
The AI Compliance Engine produces:
- License compliance assessments
- Risk scores
- Corporate relationship graphs
- Deployment analysis reports
- Evidence summaries
- Compliance recommendations
- Investigation workflows
- Audit-ready documentation
Integration Points
The AI Compliance Engine integrates with:
- License Registry
- Corporate Identity Registry
- Authorized Deployment Registry
- Verification and Evidence Layer
- Reporting Dashboard
- Governance Framework
Future Extensions
- Autonomous compliance agents
- Federated license intelligence networks
- Machine-readable contract standards
- Predictive compliance modeling
- Blockchain-based evidence verification
- Cross-platform licensing intelligence exchange
Enterprise Relationship Graph
Maps:
- Parent companies
- Subsidiaries
- Mergers
- Acquisitions
- Shared services
- Shared authentication systems
- Shared infrastructure
- Brand ownership
- Operating divisions
- International entities
Verification and Evidence Layer
Supports:
- Source attribution
- Timestamped records
- Digital signatures
- Cryptographic hashes
- Immutable audit history
- Evidence snapshots
- Chain of custody records
- Exportable evidence packages
- Compliance reports
AI Monitoring Capabilities
License Expansion Detection
Identifies potential situations where:
- Purchased license tiers appear inconsistent with organizational size.
- Deployments exceed authorized limits.
- Usage appears to extend beyond approved entities.
- Additional business units appear to be using licensed technology.
Affiliate Monitoring
Detects:
- Subsidiary usage
- Shared infrastructure usage
- Cross-brand deployments
- Shared authentication systems
- Shared employee environments
- Shared corporate resources
Commercial Usage Estimation
Estimates:
- User counts
- Department counts
- Geographic distribution
- Enterprise-wide implementation probability
- Infrastructure footprint
- Organizational usage patterns
Risk Classification
Informational
Minor inconsistencies requiring monitoring.
Warning
Potential discrepancy requiring review.
High Risk
Strong indicators of expanded commercial usage.
Critical
Substantial evidence of unauthorized enterprise deployment.
Example Scenario
Purchased License
- Up to 1,000 users
- Single corporate entity
- Two authorized domains
Observed Evidence
- Employee count exceeds 300,000.
- Deployment references found across multiple domains.
- Multiple business units reference the technology.
- Public documentation suggests enterprise-wide implementation.
AI Assessment
- Risk classification: High
- Recommendation: Human review required.
Human-in-the-Loop Governance
VerifyRights provides evidence and recommendations only.
Human reviewers determine:
- Whether a license violation exists.
- Whether additional licensing is required.
- Whether contractual exceptions apply.
- Whether evidence is sufficient.
- Whether commercial terms have been exceeded.
Potential Use Cases
- Open source commercial licensing
- Enterprise software licensing
- Specification branding licenses
- SaaS licensing compliance
- Multi-tenant licensing verification
- Affiliate usage monitoring
- Contract compliance auditing
- Commercial rights management
- License entitlement verification
- Enterprise governance programs
Future Extensions
- Blockchain evidence anchoring
- Federated compliance networks
- Machine-readable license contracts
- Automated notice generation
- Third-party verification services
- Cross-vendor compliance exchanges
- Standardized licensing APIs
- Compliance reporting schemas
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/verifyrights/
License & Notice Requirements
VerifyRights is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to any Open Arsenal project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to: Roxanne Ardary and roxanneardary.com.
- VerifyRights specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – VerifyRights
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – July 15, 2026
Created the repository for VerifyRights. Authored the open specification for AI-driven software license verification, commercial usage monitoring, and enterprise compliance intelligence. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – VerifyRights
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
