Evidence ceiling E3Proof boundary

FIRST INSTITUTION ACTIVATION

The software path is complete. The next evidence must come from the institution.

Use one institution, one tenant and one workflow lineage to bind contact delivery, identity, institution-owned keys, authoritative state, telemetry, E4, E5 and production E6.

Current state

FIRST_INSTITUTION_EXECUTION_PATH_COMPLETE

Every template validates and begins in HOLD. No seller-authored configuration, admin toggle or signed seller record can promote customer-live.

KIT VERSION
1.0.0
TEMPLATES
8
TEMPLATE VALIDATION
PASS · ALL HOLD
PORTABLE HASH ENTRIES
17
EXTERNAL EVIDENCE
0 / 8
CUSTOMER LIVE
NO
E4 / E5 / E6
HOLD / HOLD / NOT_PERFORMED
MANUAL OVERRIDE
NONE

Activation sequence

Eight outside-controlled proofs. One lineage.

Each step must carry attributable, current evidence. Missing, stale, mismatched, seller-controlled or invalidly signed inputs remain HOLD or STOP.

01

01

CONTACT

02

02

IDENTITY

03

03

KEY CUSTODY

04

04

AUTHORITATIVE SOURCE

05

05

TELEMETRY

06

06

E4

07

07

E5

08

08

E6

Promotion contract

A real customer becomes live only after the complete evidence set verifies.

Contact requires provider acceptance plus a controlled-mailbox receipt. Identity requires an authorized institutional challenge. Key custody requires institution-controlled signing. Source and telemetry require customer-side receipts. E4, E5 and E6 remain externally controlled.

01

CONTACT

Provider receipt + controlled mailbox receipt

02

IDENTITY

OIDC or SAML challenge + server-resolved authority

03

KEY CUSTODY

KMS/HSM challenge-response; private key never enters Finality

04

AUTHORITATIVE SOURCE

Frozen source contract + live authenticated observation

05

TELEMETRY

Institution SIEM/OTLP acceptance + customer acknowledgement

06

E4

Buyer-controlled hidden cases + institution signature

07

E5

Independent implementation/evaluator + external signature

08

E6

Real production execution + institution-signed activation envelope

Package integrity

Original package provenance preserved; verification made portable.

The supplied ZIP remains bound by its original SHA-256. Its internal absolute build paths and self-hash entry are excluded from the canonical portable manifest so every listed entry can be independently verified in any environment.

SOURCE ZIP SHA-256
sha256:e05bfc1337b14e8f97c1e80e8ac07e092338b34a49cd348b6ce95b3a4f3a4290
AGENT COMMAND SHA-256
sha256:4d2d35706a98c6ae36e564a9102e5b192851114a5738ec1bb0fe570173292193
MANIFEST NORMALIZATION
ABSOLUTE_BUILD_PATHS_REMOVED; SELF_HASH_ENTRY_EXCLUDED

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.