The Layover Audit Standard

Every Layover credential is built from document-verified employment and manager-attested milestones — sealed at mint, tamper-evident after.

Last reviewed · June 10, 2026

01

The Credential Classes

Layover mints two credential classes. Both require a verified HR Confirmation as the mandatory floor. The class reflects one fact — whether an identity-verified former manager has gone on record — not a quality grade.

Employment + Manager Reference

HR Confirmation + an attributed reference from an identity-verified manager.

Everything in Employment Verified, plus a named former manager who verified their identity, confirmed the working relationship, attested the candidate’s milestones item by item, and answered the one question every reference call is really asking: would you hire this person again.

Employment Verified

HR Confirmation + document verification.

A complete, shareable credential on its own: who the candidate is, where they worked, the titles they held, the dates they held them, and how the employment ended — every claim verified against documents. Not a lesser record; a record without a reference attached.

The Floor — HR Confirmation

HR Confirmation is non-negotiable. The Flight Inspector blocks any mint without one. Every claimed title and every claimed employment date is verified against this document before mint, and the verification is stamped into the audit ledger as a server-clock attestation.

Acceptable forms of HR Confirmation

  • HR Letter of Employment Verificationformal letter on company letterhead, often used for mortgages or visas
  • Most recent (or final) pay stubshows your title and the dates you were employed
  • W-2 or 1099proves yearly employment for the relevant tax year
  • Separation packettermination paperwork with HR-signed dates and title
02

Two-Key Verification

No claim on a Layover record rests on the candidate’s say-so. Every published fact is turned by two independent keys: the documents, and a named human who is accountable for what they attest.

Key One — The Documents

The candidate’s titles, employment dates, and exit status are verified against HR documentation before mint. Each document is hashed at upload; the hash outlives the document itself (see Delete-After-Verify below).

Key Two — The Manager

The reference layer is never anonymous. The manager verifies their identity through LinkedIn or verified-email authentication, confirms the working relationship, and attests the record element by element. Their name, title, and verified identity are bound into the credential — a real person, on record, accountable for what they signed.

Milestone Attestation

The candidate authors up to three milestones — short, specific, falsifiable claims about what they actually did. The manager rules on each one individually: verify as written, verify with an edit(the manager’s corrected wording publishes, marked as edited), or decline (the milestone never publishes). At least one milestone must be verified for the reference to mint.

Alongside the milestones, the manager answers the rehire question, can confirm the candidate’s tool proficiencies, and may add a short note in their own words. Read the full attestation protocol →

No Score

Layover does not publish a performance score. A single uncalibrated rater cannot produce a number that means the same thing across two records, and a decimal dressed in audit language is false precision. What publishes is evidence — verified facts and an attributed attestation — and the recruiter’s own judgment does the rest.

03

The Inspector Protocol

Every Layover record passes through a Flight Inspector before mint. The Inspector’s role is not to evaluate the candidate. It is to verify that the evidence supports every claim, that the documents are authentic, and that the audit ledger is sealed against future tampering.

Delete-After-Verify

Source documents are purged from storage immediately upon mint. Layover does not retain copies of HR letters, pay stubs, or separation packets after the credential is sealed. The mint is the moment the original documents leave our infrastructure.

What is preserved is the audit ledger: a SHA-256 hash of each verified document, the extracted structured data (titles, dates, attested milestones), the verified manager’s identity, and the Inspector’s verbatim attestation. Every timestamp in the ledger is written by the server, not the client browser — so the audit trail is monotonic and tamper-resistant against any clock drift on the uploading device.

The Record Signature

At mint, the record is sealed with a SHA-256 signature computed over the attested content itself: the credential class, every published milestone, the rehire assessment, the manager-confirmed tools, the manager’s verified identity, the verified promotion set, and the source-document hashes. The signature is what makes the credential tamper-evident — change any attested fact and the seal no longer matches.

Mandatory Attestation at Mint

Before mint, the Inspector affirms — through a signed ignition switch — the following literal statement, which is then recorded verbatim into the audit ledger:

Inspector — at mint

I have verified the claimed title(s) and employment dates against the uploaded HR Confirmation.

lib/admin/attestations.ts · CLAIMS_VERIFICATION_ATTESTATION

The SHA-256 Collision Check

Every uploaded document is hashed at upload. Before mint, the Inspector reviews any prior records whose document hash matches — catching reused HR letters across multiple candidate accounts before they enter the credential ledger.

PDF Metadata Heuristics

Producer, Creator, CreationDate, and ModificationDate are extracted from every uploaded PDF and surfaced in the Inspector’s review. Anachronism patterns — for example, a 2019-dated HR letter whose Producer string reads “iLovePDF 2024” — are flagged for closer scrutiny.

04

What You Sign Off On

Three parties affirm a record before mint. Each affirmation is preserved verbatim in the audit ledger and surfaced — by name — in the record the recruiter unlocks.

Candidate — at submission

The uploaded HR documentation supports every title and employment date on this record. SSN, salary, and home address are redacted.

lib/audit/copy.ts · CANDIDATE_CLAIMS_ATTESTATION

Manager — at vouch

The manager verifies their identity through LinkedIn or verified-email authentication, rules on each milestone individually, answers the rehire question, and affirms — through a signed ignition switch — the following literal statement:

Manager — at vouch

The milestones, rehire assessment, and any commentary on this clearance reflect this candidate's actual work under my direct supervision.

lib/audit/copy.ts · MANAGER_VOUCH_ATTESTATION

Inspector — at mint

I have verified the claimed title(s) and employment dates against the uploaded HR Confirmation.

lib/admin/attestations.ts · CLAIMS_VERIFICATION_ATTESTATION

The Credential of Record

The Layover Link URL is the credential of record. Any downloadable asset — Clearance Keys, share cards — is a visual display of that record, not the record itself. Verification always resolves to the link.

Why these literals matter

Once a record is minted, the literal text of every attestation is part of the credential. UI copy can evolve; the affirmation stamped into the ledger cannot retroactively change. The record a recruiter unlocks today reflects the standard that was in force on the day it was sealed.

Return to Layover →