WorkMonitor · Verified Work
Proof your client can check without an account.
An invoice asks to be believed. A certificate does not: signed with your own key, timestamped, anchored beyond editing — ours included — and open on a public link that still resolves next year.
The verifier is a public page on its own origin. There is nothing to sign into and nothing to install.
What the check actually proves
- Signature. Ed25519, resolved against the issuer’s published JWKS
- Timestamp. RFC-3161 token from an authority outside WorkMonitor
- Anchor. Write-once: the record cannot be edited afterwards, by anyone
Verified Work Certificate
This work was completed as recorded.
- Deliverable
- Northlight redesign — phase 2
- Completed
- 4 September 2026, 16:42 UTC
- Hours certified
- 118.5
- Issued by
- Northlight Studio

Proof Ledger
The record, the signature, and the link
Pick one and the screen it lives on opens beside it, so you judge Proof Ledger on what it puts in front of a manager rather than on a list of nouns.
How it works
From finished work to a link a client can open
- 1
Record what shipped
Outcomes capture the deliverable itself, and work-edges record the shape of the work with zero pixels captured. A record exists even for teams that will never accept a screenshot.
- 2
Sign it with your own key
Ed25519 signing with published JWKS, and bring your own key where your security team requires it. The signature is yours, which is what makes it worth something after the relationship ends.
- 3
Anchor it and timestamp it
Write-once anchoring and RFC-3161 timestamps put the record beyond editing, ours included, over a hash-chained trail where any later alteration shows.
- 4
Hand over the link
A public verifier on an isolated origin: no login, no download, and selective disclosure so the client sees the claim they asked about rather than the account it sits in.
A PDF that asks to be trusted vs. a record that proves itself
workmonitor.vsA PDF and a status call
What the client receives
With WorkMonitor
A signed certificate on a public link they verify themselves, without an account and without taking our word for it.
A PDF and a status call
An export whose numbers were typed by the party being paid.
Who can alter it later
With WorkMonitor
Nobody, us included. WORM anchoring and RFC-3161 timestamps over a hash-chained trail where an alteration is visible.
A PDF and a status call
Anyone holding the file, invisibly.
Whose signature is on it
With WorkMonitor
Yours. Ed25519 with published JWKS, and bring-your-own-key when the record has to outlive the vendor.
A PDF and a status call
The vendor’s, if anyone’s.
How much you have to disclose
With WorkMonitor
Selective disclosure: the one claim in question, without the account behind it.
A PDF and a status call
The whole export, because there is no way to show a single line.
Proof without surveillance
With WorkMonitor
Work-edges record what was worked on with no pixels captured, so a record still exists where screenshot monitoring was never going to be accepted.
A PDF and a status call
Screenshots, or nothing at all.
The same question next year
With WorkMonitor
The same link, still resolving, still verifying, on your own domain.
A PDF and a status call
A folder of PDFs whose numbers nobody can reproduce.
Every capability in Proof Ledger, and exactly where each one stands
- Zero-screenshot work-edge record
- Shipped-work outcome verification
- URL/active-tab work-edges (zero pixel)
Ask AI
Ask AI about your proof
What has been certified, what shipped without a certificate, and what a client actually sees when they check. Every answer cites the record it came from.
Pick a question above and WorkMonitor AI will answer from your team's real numbers.
By team
Who needs the record
Use cases
What it gets used to settle
Each one opens on the page written for that job — the same capabilities, read from the work rather than from the product.
- Prove work with certificatesA finalized invoice mints a signed certificate the client checks for themselves. Selective disclosure proves the work without handing over the work.
- Bill defendable client hoursBudgets that burn down while you can still move somebody, rate-card billing off captured hours, and an invoice the client verifies without asking you for anything.
- Track time automaticallyNo timer to start, no Friday reconstruction. Idle is split out rather than estimated, and approved hours reach payroll and invoicing without a re-key.
Straight answers
The questions we would ask in your position
Every answer here is the one you would get on a call. Open as many as you like; they stay open, so two can be held side by side.
A signed, timestamped record of finished work, seeded when you finalize an invoice. It carries an Ed25519 signature under your own key, an RFC-3161 timestamp, and a WORM anchor that puts it beyond later editing. Your client opens a link and verifies it themselves, without an account and without trusting us as the intermediary.
No, and that is the point. The verifier is a public page on an origin isolated from the app, so there is nothing to sign into and nothing to install. On a custom domain it sits under your name, and nothing on the page identifies us as the vendor behind it.
Yes. Work-edges record what was being worked on — the deliverable, the URL, the active tab — with zero pixels captured. Outcome verification records what actually shipped. For teams whose staff or works council will never accept screenshot monitoring, this is a complete record that does not depend on one.
The anchoring is write-once and the timestamps come from an RFC-3161 authority outside our control, over a hash-chained audit trail where a break is visible. If you sign with your own key, we never hold the material that could produce a valid replacement in the first place.
The link keeps resolving and the signature keeps verifying. That is the reason bring-your-own-key exists: a record whose validity depends on your vendor still being your vendor is not proof, it is a subscription. Selective disclosure and the public verifier are both designed to outlive the account.
Take these with you
The software is the easy part of a rollout
Here is what we would send a manager doing one for the first time: how to read a productivity number, what to say to a remote team before anything is installed, and a policy you can adopt as written.
Point it at one team for a week.
Create the account, put the agent on a handful of desks, and leave it alone. On Friday you read the week instead of reconstructing it: hours against their projects, focus and idle per person, and the timesheets already filled in.
Free for two seats. No card, and no sales call to sit through.