Because "did you look?" is checkable and "are you right?" is not

Why there are verifiers Shipped

A verifier does not re-litigate a finding. It asks whether the specialist covered the ground its own specialty declared — a question with a written answer to check against.

The natural instinct is to add a second reviewer that checks the first one's work. That does not do what it looks like it does: two models disagreeing about whether a finding is real produces a tie that somebody has to break, and whoever breaks it is now the actual reviewer. The question has no ground truth in the room.

Coverage does have ground truth

Every specialty ships Verify criteria — a written statement of what a complete pass over its ground looks like. "Did this reviewer's output engage with each of these?" is answerable by reading the criteria and the findings side by side. It is a weaker question than correctness, and being weaker is the point: it is the strongest question that can actually be settled.

Which is why it is add-only

A failed verification drives a bounded re-review that can find more and cannot retract. If a verifier could delete, the tie-break problem would be right back — with the deletion happening silently, inside a lane, where nothing downstream could see it. Add-only keeps the verifier an instrument rather than a judge.

The trade it makes

This buys coverage and buys nothing at all against a confidently wrong finding. That gap is covered later and by a different actor — the consultant re-scores every finding against a false-positive catalog. Two different failures, two different mechanisms, deliberately not merged into one.