Policy of record
Provenance tiers
Every published revision carries a tier derived from evidence, never assigned by hand and never influenced by payment. A tier applies to an exact revision.
A provenance tier is derived, not granted. It attaches to one exact content-addressed revision: change a fact and the new revision earns its own standing, inheriting no attestation and no verification.
- observed
- Supporting evidence covers every material path of the revision. The vendor's own published source was captured, and each fact is bound to the exact bytes that support it.
- signed
- A principal holding current claim authority for the vendor attested to this exact revision. Signed means that and only that: no scanner, operator, or release signer can create it.
- verified
- A passing verification run covered the required paths for this exact revision, with the run recorded as a public event.
The highest applicable tier renders, and every underlying event and coverage basis remains public. Expired verification falls back to signed while a valid attestation covers the same revision, otherwise to observed. A revoked or lapsed claim authority remains in history but no longer grants a current signed tier.
An offer may exist on a current declaration alone. When a vendor holding current claim authority attests an exact offer revision, the attestation itself is the evidence: no public page is required, and every material path is covered by the signature rather than an observation. Declared coverage ages on its own freshness budget and must be re-affirmed; if the claim authority or attestation lapses, the offer cannot ride the next release and is withdrawn until renewed. A declaration is checkable against the public event log and the signer registry, offline, like every other fact in a release.
Declaring, claiming, and correcting are free. No payment creates, ranks, or retains a declared offer.
revision sha256:49ab0a80de3c362a3bb3b9ac031feaef624af9ec3f95bbefe2c8dfb50e72fc08 · published in release sha256:fbebb3b52183…