A digital signature can answer an important question: has this signed record remained intact since it was created? It cannot answer the next question on its own: who is standing behind the claims in that record, and in what capacity?
That distinction matters in digital art. An artist may describe the creation of a work. A gallery may record intake and exhibition details. A software service may generate and sign a provenance manifest. A collector may later add a transfer or custody record. These parties can contribute to the same history without making the same kinds of assertions.
If a verification page reduces all of them to one reassuring symbol, the technology may be working while the explanation fails. Professional trust requires the signer to be as legible as the signature.
A valid signature is not a universal endorsement
C2PA's current specification uses digital signatures to bind assertions into a tamper-evident manifest. Its trust model is explicit that trust decisions begin with the identity associated with the signing credential. A consumer then considers that signer, together with other signals, when deciding whether to rely on the assertions.
This is careful architecture. It does not say that a technically valid manifest proves every statement inside it is complete, accurate or artist-authored. It shows that particular assertions were signed through a particular credential and that the associated record can be validated against the asset and the relevant trust model.
For galleries and collectors, the difference is practical. A service may validly sign a record saying that it processed a file at a certain time. That does not automatically mean the service created the artwork, interviewed the artist, cleared every right or witnessed the whole creative process. A gallery may supply a description that is gathered into the record rather than originated by the software signer. An artist's identity may be represented separately from the product or device that generated the manifest.
The signature is valuable precisely because it can preserve these distinctions. The interface should not erase them.
Three identities are often collapsed into one
The first identity is the creator or authorised submitting party. This is the person or organisation associated with the work and the account of its origin. Their role is cultural and professional before it is technical.
The second is the signer. In C2PA, this is the entity associated with the credential used to sign a claim. The signer may be a software product, device or service acting through a claim generator. C2PA's Human and Organizational Identity Recommendation explains why a claim generator acting on behalf of a person or organisation may also need a separate way to represent that human or organisational identity.
The third is the publisher or custodian presenting the record. A gallery, marketplace, archive or collection may display the work and its provenance without having originated every assertion in the chain.
These identities can coincide, but a trustworthy system should not assume that they do. “Signed” should never become shorthand for “signed personally by the artist” unless that is what the evidence actually establishes.
Created and gathered assertions need different language
C2PA distinguishes between assertions created by the claim signer and assertions gathered from another source. Its implementation guidance asks relying parties to consider that distinction because acceptance depends partly on who made the assertion.
For digital-art infrastructure, this suggests a simple editorial rule: show provenance as attributed statements, not as anonymous facts.
A useful public record might say that a service generated the manifest and bound it to a particular asset state. It might separately identify a creator statement supplied by the artist, an intake record supplied by a gallery, or a later event supplied by a custodian. Where the source cannot be established beyond a submitted account, the interface should say so.
This does not require exposing personal details that the artist has chosen to keep private. Legibility is about roles, sources and evidence levels, not unnecessary identity disclosure. A professional verification surface can distinguish an identified organisation, a creator-asserted statement and a system-generated event without publishing private studio information.
What a gallery-grade verification surface should show
Four questions make a signed record usable outside a technical team.
Who or what signed this manifest? The viewer should be able to identify the signing product or organisation and see whether the credential validated, without being asked to interpret raw certificate output.
Which claims came from that signer? System-generated processing events should be separated from statements gathered from an artist, gallery or other source.
How is the work's creator represented? The creator's relationship to the record should be clear without implying that the platform, gallery or credential provider is the author of the artwork.
What remains outside the signature? Curatorial judgement, legal rights, artistic merit and the completeness of the wider history are not produced by cryptographic validation. The interface should say what was checked and leave room for the appropriate human or documentary evidence.
These questions also make due diligence more efficient. A gallery can see which statements it must verify at intake. An institution can preserve the provenance chain without confusing software identity with authorship. A collector can understand why a record is credible and where a further question belongs. An investor can judge whether an art-tech product has built a repeatable trust workflow rather than merely added a badge.
Where Miharana fits
Urticad's current public material describes Miharana as a protection path combining invisible watermarking, signed C2PA provenance and public verification. The live Miharana site presents a curated gallery backed by provenance and public verification, while keeping the artwork first.
Those capabilities create the right architecture for signer legibility: a durable route back to a record, a signed provenance layer and a public surface where the evidence can be translated. They do not, by themselves, justify claiming that every creator identity or assertion has been independently verified.
The product discipline is therefore to preserve attribution at each layer. A Miharana verification view should make clear what the system signed, what an artist or authorised publisher supplied, what validation has passed and which questions remain for gallery review or other documentation. That is a design principle for the public evidence experience, not a claim that cryptography can replace professional judgement.
This restraint strengthens the proposition. Artists are not absorbed into the identity of the platform. Galleries can understand the source of a claim. Collectors can distinguish a valid record from a universal guarantee. Institutions receive evidence that can be interpreted and preserved rather than a decorative seal.
Trust becomes useful when its source is visible
Digital provenance is not weakened by showing who made each claim. It becomes more credible.
A signature can protect the integrity of a record. A trust chain can help a validator assess the signing credential. A public interface still has to explain the signer, the source of the assertions and the boundary of the result. Without that translation, a valid credential may remain technically impressive but professionally ambiguous.
The next generation of art-tech products should not ask audiences to trust a symbol. They should make the source of trust inspectable.
If you work with digital art as an artist, gallery, institution, researcher or collector, Urticad would value hearing which signer and source details you need before a provenance record becomes usable in practice.
