The training record for the audit that the auditor verifies themselves
In the audit meeting, the auditors do not ask who was in the room but who completed which content, when, and with what result. An attendance list delivers half of that. The strongest evidence is the one the person auditing verifies themselves, without an account and without checking back with you. That is exactly how a KALYX training record is built: Open Badges 3.0, a checksum over the content, a public Verify number, and a frozen snapshot of what applied on the day of issue.

- An attendance list proves who was in the room, not who understood something. But that is exactly what an audit wants to know.
- Four details carry a record. Who, when, which content, with what result. If one is missing, the meeting gets uncomfortable.
- The strongest evidence is the one the person auditing verifies themselves. Without an account, without checking back with us, via a public Verify number.
- Tamper-proof does not mean laborious. In KALYX, every passed course automatically becomes a record with its own checksum.
Why a participant list rarely suffices in an audit
The moment is always the same. The auditor sits at the table, leafs through the binder, and asks who exactly was trained on which topic and when. You hold up a signature list. On it are names, a date, and a tick in the "present" column.
The list proves that people were in a room. It does not prove that these people learned anything, and certainly not what. But an audit asks about the result, not about attendance. And it asks for evidence it can trace itself, not for your word.
That is where the searching begins. In binders, in mailboxes, in last year's slides, which have since been revised twice. Every minute of searching in the audit meeting is a minute in which the person auditing doubts that you have an overview.
What the person auditing actually wants to see
Four details. Who was trained, when, which content was covered, and with what result the exam was passed. A participant list delivers two of these, the who and the when. The content is, at best, in the file name of a presentation, and there is no result at all.
Which details a piece of evidence really has to carry so that it holds up when it matters is covered in How do I prove that my staff are trained?.
What this looks like in KALYX

In KALYX, the record does not arise alongside the training but out of it. Whoever passes a course receives a record that carries all four details, automatically, not entered by hand.
Every record runs on Open Badges 3.0, a digitally signed credential. It carries a checksum over its content (SHA-256) and a Verify number. Using this number, a third party opens the record on a public page, without an account and without any detour through us. They see who passed the course, when, which content the course had at the time of examination (it is frozen as a snapshot), and with what result. The public issuer key is openly available, and any verifying software can recompute the signature itself.
The difference from a binder is not the look. It is who verifies. With a binder, you verify, and the person auditing has to take your word. With a record, they verify themselves. What tamper-proof means here exactly, entirely without a third-party watermark and without any detection promise, is covered in What a tamper-proof training record means.
What this changes in the audit meeting
Instead of a binder, you hand over a number. The person auditing opens the Verify page, sees the record, sees the content at the time of examination, sees the result. No searching, no submitting things later, no discussion about whether the list is complete.
The frozen snapshot is the point many underestimate. A record is only worth something if, years later, it still shows the same thing as on the day of issue. A piece of evidence that can be changed after the fact is not evidence. That is why, in KALYX, an issued record stays untouched, even if the course develops further afterwards. Whether such a record is really tamper-proof, we tested on ourselves. The result is in We forged our own certificate.
Where our responsibility ends. A KALYX record is a self-issued training record, not an officially recognised qualification. It shows that a person worked through a specific course content and passed the exam. It is not an officially recognised industry qualification and not an official confirmation from any authority that your obligations are met. Whether a training suffices in a given case is decided by your supervisory body, not by the record.
This post describes how a verifiable training record is built and how a third party verifies it. The technical details (Open Badges 3.0, SHA-256, public Verify page, frozen content snapshot) refer to the current state of the KALYX app. This post is no substitute for examination regulations or legal advice.
As of 17 September 2026.
Geprüft und freigegeben von Fabian Kreher, Gründer von KALYX am September 17, 2026. Formuliert mit KI-Unterstützung.


