@mikedev No, I don't want to forbid signing of collections. I am concerned about clients, because they can't do that easily. A client would need to re-sign outbox collection after every activity, and somehow send it to the server. If some other collection is modified, the process will be even more complicated.
Therefore, clients should not be required to sign collections, and servers should not be required to verify their integrity.