Concrete objects, not vague claims
It is not enough to say that an identity exists: there should be a MAX ID. It is not enough to say that a content was signed: there should be a verifiable signature. It is not enough to say that an IoT manifest was approved: there should be an identifiable signed manifest linked to an approval flow.
For devices, the same logic applies. A node should not be considered correctly configured only because it received a command. Its identity, role, applied manifest section, authorized peers and resulting report should make the state of the node observable.
Technical note
Verification does not replace audit. Verification makes audit possible. A system that produces readable evidence can be checked, tested and improved.