This is separate from both ticket authorization and handoff consent. The wording below is the complete contract represented by nhs-provider-controlled-intent-disclosure-consent-v1. It is optional: declining it does not block the observed handoff or free direct provider access. A new meaning requires a new version label.
nhs-provider-controlled-intent-disclosure-consent-v1
The caller attests all of the following:
The caller attests that the human or company principal authorizes Not Human Search, after NHS observes this exact provider handoff, to disclose to the DNS-verified provider controlling the ticket’s provider claim only the controlled demand topic, optional region code, USD budget band, urgency, and allowlisted requirement flags already stored in this ticket, together with the opaque ticket and offer identifiers and action type needed to bind those values. The principal understands that the provider may read that same bounded bundle during the shorter of the ticket authorization window and NHS’s 30-day controlled-intent retention period; that NHS will not disclose the search query or query hash, prompt, free-form text, name, contact data, agent or principal identity, IP or network identifier, user agent, referrer, cookie, search-receipt identifier, credentials, or payment data; and that this consent does not authorize provider outreach, verify identity or agency, prove uniqueness or an outcome, change organic rank, or charge either party. Declining this disclosure does not block the handoff or free direct provider access.
Consent is recorded only in the append-only handoff receipt and cannot be added later by replay. The provider presents the exact signed attribution bearer to the REST resolver with its active claim-scoped key. NHS returns nhs-provider-controlled-intent-resolver-v1 only while the claim, ticket, bearer, authorization, consent, and retention checks all remain valid. NHS exposes no provider resolver MCP tool.