← policies

Policy of record

Provenance tiers

Every published revision carries a tier derived from evidence, never assigned by hand and never influenced by payment. A tier applies to an exact revision.

A provenance tier is derived, not granted. It attaches to one exact content-addressed revision: change a fact and the new revision earns its own standing, inheriting no attestation and no verification.

observed
Supporting evidence covers every material path of the revision. The vendor's own published source was captured, and each fact is bound to the exact bytes that support it.
signed
A principal holding current claim authority for the vendor attested to this exact revision. Signed means that and only that: no scanner, operator, or release signer can create it.
verified
A passing verification run covered the required paths for this exact revision, with the run recorded as a public event.

The highest applicable tier renders, and every underlying event and coverage basis remains public. Expired verification falls back to signed while a valid attestation covers the same revision, otherwise to observed. A revoked or lapsed claim authority remains in history but no longer grants a current signed tier.

An offer may exist on a current declaration alone. When a vendor holding current claim authority attests an exact offer revision, the attestation itself is the evidence: no public page is required, and every material path is covered by the signature rather than an observation. Declared coverage ages on its own freshness budget and must be re-affirmed; if the claim authority or attestation lapses, the offer cannot ride the next release and is withdrawn until renewed. A declaration is checkable against the public event log and the signer registry, offline, like every other fact in a release.

Declaring, claiming, and correcting are free. No payment creates, ranks, or retains a declared offer.

revision sha256:49ab0a80de3c362a3bb3b9ac031feaef624af9ec3f95bbefe2c8dfb50e72fc08 · published in release sha256:fbebb3b52183…