Immutable identity
- Repository, branch and full commit SHA
- Language, package and binary versions
- Licence and third-party provenance
Evaluate each component at an immutable commit, run its own verification path and preserve the exact output. Qualification is scoped to the repository, platform and boundary stated by that evidence.
DON'T TRUST THE DEMO. VERIFY THE SYSTEM.Domain desks integrate beside incumbent systems through authenticated notifications, authoritative rereads, exact source bytes and cryptographic commitments. A webhook is a trigger; it is not automatically authoritative evidence or a synchronous prevention hook.
| Term | Meaning | Does not mean |
|---|---|---|
| IMPLEMENTED | Code and tests exist in the named tree. | Production operation. |
| QUALIFIED | A named matrix passed at a specific commit and environment. | Certification or universal correctness. |
| PARTIAL | An internal path exists but a named dependency remains. | End-to-end qualification. |
| PROVEN | A specific proof object verifies under its protocol. | Truth of facts the protocol never observed. |
| DIVERGED | Observed evidence differs from the committed record. | Automatic attribution of fault. |
| UNRESOLVED | Evidence cannot determine the effect. | Permission to retry a possibly started effect. |
Live credentials, customer consent, public HTTPS, production key custody, source licences, external-provider contracts, deployment topology, backup/restore, load and buyer acceptance remain separate diligence items unless proved explicitly.