Legal
Credential Verification Policy
This policy explains how a Competency Passport is issued, how a third party can verify it, and how credentials are revoked, superseded, or expired over time.
Last updated 16 July 2026
What a Competency Passport represents
A Competency Passport is a signed attestation that a specific candidate demonstrated a specific set of competencies against a specific rubric version, on a specific date, under identity-verified conditions, and that a named human reviewer approved the underlying assessment attempt.
It is not a professional licence, a regulatory approval, or an offer of employment. It is a portable statement of demonstrated competence that employers can use as part of their own due-diligence process.
Issuance criteria
A credential is issued only when every one of the following is true:
- The underlying attempt is on the verified track (not AI Practice) — see the Assessment Policy.
- Identity verification for the candidate is complete.
- A human reviewer has approved the reviewer-adjusted score.
- The reviewer has recorded an integrity disposition of clear.
- The attempt is flagged
passport_eligible = trueand has not been withdrawn.
Issuance is idempotent: repeated issue requests for the same attempt return the existing credential rather than creating duplicates.
Public verification
Any third party — typically an employer, a training provider, or a regulator — can verify a credential at verify.competencylabs.com by opening the verification link on the candidate's Passport. The verification page shows:
- The credential identifier and current lifecycle state (verified, expired, revoked, superseded);
- The framework and rubric version;
- The competency-layer and entrustability-layer results;
- Issue date and expiry date;
- Reviewer's name or reviewer team, without personal contact details.
The verification page does not show the candidate's email, home address, raw response text, private notes, or admin notes. Employers who need additional detail may request it from the candidate directly.
Lifecycle states
- Verified — currently valid. The default state at issuance.
- Expired — the credential has reached its expiry date. Employers should treat expired credentials as historical evidence, not current attestation.
- Revoked — the credential has been withdrawn because we determined, on evidence, that the underlying attempt does not meet our standards or that identity was misrepresented. Revocation is recorded on the audit trail with a reason code.
- Superseded — a newer credential has replaced this one for the same candidate and framework. Supersession never crosses candidates.
State transitions are recorded to a credential_events audit log. The verification page always reflects the current state; there is no “silent” withdrawal.
Revocation criteria
A credential may be revoked when:
- The reviewer decision is overturned on appeal or on further investigation;
- The candidate's identity was materially misrepresented at the time of the attempt;
- The attempt was completed with prohibited assistance and this was not caught at review;
- Framework requirements have changed such that the underlying evidence no longer meets the standard, and transitioning to an expiry rather than a revocation would materially mislead employers.
We notify the credential holder before revocation takes effect (except where fraud requires immediate action) and record the reason on the audit trail.
Rubric and framework versioning
Every credential is bound to a specific credential_version that captures the rubric, framework mapping, and document packet in force at the time the attempt was scored. Later changes to the rubric do not retroactively alter an existing credential; instead, superseded credentials point forward to the newer credential for the same candidate.
How employers should use the portal
We recommend that employers verify every candidate-supplied credential through the public portal, treat the state field as authoritative (do not rely on the candidate's downloaded PDF alone), and record the verification event in their own hiring audit trail. The portal is stable at verify.competencylabs.com and does not require an employer account for individual look-ups. Employer-scale verification features (bulk lookup, audit exports) are on our roadmap and will be introduced with their own commercial terms.
Disputes
Candidates can dispute a revocation or supersession by emailing appeals@competencylabs.com within 30 days. Employers who believe a candidate has presented a credential fraudulently can report it to fraud@competencylabs.com.
Contact
For questions about this policy, contact legal@competencylabs.com. See also our Credential Verification trust page for the operational details.
Maintained by Competency Labs. Contact support@competencylabs.com for corrections or questions.
Trust Center