Most teams can only assert that controls ran. Primust turns a governed run into a signed credential that another party can verify independently.
Most teams can only assert that controls ran. They can show a dashboard, a report, or a log stream that they themselves operated. That is usually enough until the moment another party needs independent evidence.
Primust exists to turn governed runs into signed credentials that another party can verify later without trusting the original runner, the dashboard operator, or the agent that produced the work.
The verifier is Apache-2.0. The format is documented. The point of the evidence is that it remains useful after issuance, not only while a SaaS dashboard is available.