What we can and cannot see
Start with the gaps.
Every figure below carries its data-unit, population, snapshot date, and an evidence pointer. No count-shaped number appears without a unit and provenance. The figures change only when the ledger does — they render immediately, never count up.
Current scope: Missouri dental providers, read against two public authorities — the Missouri Dental Board and CMS NPPES. See how the method works, open a sample result — the stable subject URL, which always resolves to the current head at request time — or read the frozen public evidence package.
Proposition coverage — static figures
The population in two parts, both counted, neither hidden: propositions published in signed records (four states of reliance), and propositions in the population store, never published in a signed record (no state of reliance applies).
Activity: 98,598 verification events across 3 epoch(s) since 2026-09-10 — our own activity, not a state of the propositions.
Declared invariants: published four states sum to published count (V:10 + U:3 + C:0 + S:0 = 13: true); published + unpublished = total (13 + 65,130 = 65,143: true); events ≥ propositions (98,598 ≥ 65,143: true).
The published + unpublished = total check is an arithmetic identity of the projection code — it proves the code that computes the two parts, not an observation about the stored data.
Why propositions are unverifiable — reason-class partition
Reason classes recorded for UNVERIFIABLE verdicts in the verification ledger — our own activity. They are not states of the published subpopulation.
No authority publishes a field for this predicate8,444propositionspopulation: MO dental · snapshot: evaluated 2026-09-21T16:16:53.717Z
The authority holds the fact but does not publish it for verification4,222propositionspopulation: MO dental · snapshot: evaluated 2026-09-21T16:16:53.717Z
Scope boundaries
GeographyMissouri only—population: US states · snapshot: scope definition · evidence: engagement scope
SpecialtyDental—population: healthcare taxonomies · snapshot: scope definition · evidence: beachhead taxonomy set
Authoritiesauthority:nppes, board:mo-dental—population: public registries · snapshot: evaluated 2026-09-21T16:16:54.038Z · evidence: from the ledger
Board licensee propositions34,313propositionspopulation: MO dental licensees · snapshot: evaluated 2026-09-21T16:16:54.038Z · evidence: Missouri Dental Board roster NPPES practitioner propositions30,830propositionspopulation: MO NPPES practitioners · snapshot: evaluated 2026-09-21T16:16:54.038Z · evidence: CMS NPPES registry Decay horizonsUNMEASURED—population: all propositions · snapshot: evaluated 2026-09-21T16:16:54.038Z · evidence: fewer than three monthly cycles
Cross-authority conflict4 detectedcontradictionspopulation: crosswalk epoch · snapshot: from the signed epoch record (computed 2026-09-18T20:07:45Z) · evidence: identifier-equality joins, board↔NPPES Outside this scopeEverything else. We will say so rather than guess.—
What our audit now sees: cross-authority conflict. The board↔NPPES identity resolution is live (identifier equality). The bounded checks performed on the fetched pool are: Tier A identifier-equality joins (NPI↔license number), name-disagreement checks (excluded by the hash check), and cross-field contradiction detection (falsifier f3). Full evidence with reproduction instructions at
the public evidence package. from the signed epoch record (computed 2026-09-18T20:07:45Z)
The two-authority crosswalk — where every board row went
The payer-facing denominator is board rows — the Missouri Dental Board roster, not the NPPES pool (a federal source whose result count we do not control). Every board row goes to exactly one of three classes: joined (Tier A, identifier equality), not joined (each with a stated recorded reason), or a cross-field contradiction finding. The contradiction findings sit OUTSIDE the join/not-join partition — a contradiction row is a finding, never also a not-joined row — and INSIDE the board-rows denominator.
Board rows (the denominator)4,197from the signed epoch record (computed 2026-09-18T20:07:45Z) · the signed epoch record NPPES pool results (federal source — not the denominator)1,801from the signed epoch record (computed 2026-09-18T20:07:45Z) · the signed epoch record Joined — Tier A, identifier equality779from the signed epoch record (computed 2026-09-18T20:07:45Z) · the signed epoch record Not joined — each with a stated recorded reason3,414from the signed epoch record (computed 2026-09-18T20:07:45Z) · the signed epoch record Cross-field contradiction findings (falsifier f3)4from the signed epoch record (computed 2026-09-18T20:07:45Z) · the signed epoch record Reconciles by the stated partition: 779 joined + 3,414 not joined + 4 contradiction findings — equals the 4,197 board rows. from the signed epoch record (computed 2026-09-18T20:07:45Z)
15 name disagreements — candidate-level findings where the two authorities' readings differ for a bound subject, including candidates on rows that joined via another candidate. This count is finding-level, not row-level: it is not part of the join/not-join partition above, and it can differ from the name-disagreement reason rows below — a candidate on a row that joined via another candidate is a finding, but its row is not a not-joined row. from the signed epoch record (computed 2026-09-18T20:07:45Z)
Why rows do not join — all six reason classes, with denominators
The non-join reasons partition the not-joined rows — one reason per row, so the non-join reason counts sum to the not-joined row count. The denominator for the five non-join classes is the not-joined row count in the disposition above. The contradiction class counts finding rows — a finding class, never also a not-joined row.
no NPPES record in the fetched pool3,341denominator: the 3,414 not-joined rows above · unit: rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record fetched, but no licence published for the state3denominator: the 3,414 not-joined rows above · unit: rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record names disagree between the two authorities11denominator: the 3,414 not-joined rows above · unit: rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record ORG RECORD — CMS NPPES publishes the license at organization level; a named limit of the federal source56denominator: the 3,414 not-joined rows above · unit: rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record names disagree AND the NPPES record is an organization-level license — a named limit of the federal source3denominator: the 3,414 not-joined rows above · unit: rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record cross-field contradiction finding (falsifier check)4a finding class — denominator: the contradiction findings above, never a not-joined row · unit: finding rows · epoch: 2026-09-18T20:07:45Z · the signed epoch record Method supersession — method change on fixed evidence, never an improvement claim
Ruleset changes are method effects — the same snapshot evidence, processed differently. A changed ruleset joins the SAME board roster and NPPES pool the prior one joined. The observable diff between two epochs is the method effect, not an accuracy improvement. No epoch can claim to be “better” — only different by a stated method change.
supersededruleset v2 · 752 of 4,197 board rows joined · 4 cross-field contradictions · 42 name disagreementsfrom the signed epoch record (computed 2026-09-10T22:57:03Z)
supersededruleset v1 · 747 of 4,197 board rows joined · 5 cross-field contradictions · 160 name disagreementsfrom the signed epoch record (computed 2026-09-10T20:26:07Z)
Our own error rate
We re-draw a random sample of 50 recorded verification rows from the verification ledger — our own recorded verification events, not the propositions published in signed records — and re-derive each drawn verdict independently from its cited observations, not from the code that produced the verdict. Read what the number measures before the number: the result is a bound on our own reproduction of our own verdicts. It is not a provider score, not a measure of source correctness, adjudication quality, or any plan's directory accuracy. An auditor who also sells you the answer is not an auditor.
Drawn sample — the frameA server-side random sample of 50 verification rows was drawn, deduplicated by id; all drawn ids are retained in the cited run receiptdrawspopulation: the recorded verification ledger · snapshot: run cutoff 2026-09-07 · evidence: from the signed self-audit record (WoC's own procedure)
Error definitionThe estimand is the proportion of recorded verification rows whose stored verdict disagrees with the verdict re-derived under the sampler’s independent support rule, among re-derivable rows, at the cutoff; procedure faults are recorded and excluded from the rate, and provider aggregation is descriptive only, with no boundre-derived vs recordedpopulation: the re-derivable drawn rows · snapshot: self-audit procedure · evidence: from the signed self-audit record (WoC's own procedure)
Procedure faults1 procedure fault: re-derivation could not be performed for the cited drawn row — recorded, excluded from the rate denominator, never counted as agreerows not re-derivablepopulation: the drawn rows · snapshot: run cutoff 2026-09-07 · evidence: recorded, excluded from the rate, never agree
0/49 → 5.9%Exact binomial, from the run: 0 errors in 49 re-derived rows (of 50 drawn; 1 procedure fault excluded) → one-sided 95% confidence bound on the true error rate ≤ 5.9%.
Population: the recorded verification ledger · cutoff: 2026-09-07T04:36:37.637Z · draw: server-side random, deduplicated by verification id · error unit: the verification row — a stored verdict differing from its independent re-derivation · procedure faults: recorded, excluded from the rate, never agree · provider aggregation: descriptive only, no bound · the exact artifact:
signed self-audit record (WoC's own procedure)