01
CONTACT
FIRST INSTITUTION ACTIVATION
Use one institution, one tenant and one workflow lineage to bind contact delivery, identity, institution-owned keys, authoritative state, telemetry, E4, E5 and production E6.
Current state
Every template validates and begins in HOLD. No seller-authored configuration, admin toggle or signed seller record can promote customer-live.
Activation sequence
Each step must carry attributable, current evidence. Missing, stale, mismatched, seller-controlled or invalidly signed inputs remain HOLD or STOP.
CONTACT
IDENTITY
KEY CUSTODY
AUTHORITATIVE SOURCE
TELEMETRY
E4
E5
E6
Promotion contract
Contact requires provider acceptance plus a controlled-mailbox receipt. Identity requires an authorized institutional challenge. Key custody requires institution-controlled signing. Source and telemetry require customer-side receipts. E4, E5 and E6 remain externally controlled.
Provider receipt + controlled mailbox receipt
OIDC or SAML challenge + server-resolved authority
KMS/HSM challenge-response; private key never enters Finality
Frozen source contract + live authenticated observation
Institution SIEM/OTLP acceptance + customer acknowledgement
Buyer-controlled hidden cases + institution signature
Independent implementation/evaluator + external signature
Real production execution + institution-signed activation envelope
Package integrity
The supplied ZIP remains bound by its original SHA-256. Its internal absolute build paths and self-hash entry are excluded from the canonical portable manifest so every listed entry can be independently verified in any environment.