Signing trust and staging authority

Trust the identity. Verify the package. Separate the decision.

P003 accepts public-key evidence, never upstream private keys. A valid signature authenticates a package; it does not approve editorial content or authorise promotion.

P010/P011 sequence0
Promotion approvals0
Rollback authorisations0
Private-key storageProhibited
01

Register

Record programme, fingerprint, algorithm, public-key reference, custody, validity, and accountable registrars.

02

Activate

Require independent approval and evidence before the key can authenticate a package.

03

Verify

Check programme binding, validity, revocation, monotonic sequence, package hash, and signature.

04

Rotate

Overlap public verification safely while preventing the retired key from signing new sequences.

05

Revoke

Block immediately, quarantine affected packages, assess exposure, and preserve the audit trail.

06

Expire

End trust automatically; renewal requires a new governed ceremony.

Replay protection

Every programme advances independently.

P003 records only the last accepted sequence after a verified promotion. Repeated or lower sequences are quarantined, preventing an older validly signed package from replacing newer public truth.

P0000000Last accepted sequence
P0010000Last accepted sequence
P010/P0110000Last accepted sequence
P1000000Last accepted sequence

Separation of duties

No single identity can move content from receipt to public release.

Promotion requires distinct requester, staging approver, promotion approver, and security reviewer. Emergency rollback requires distinct requester, rollback approver, and security reviewer.

01
Intake operator

Receives and quarantines packages; cannot approve promotion.

02
Staging approver

Accepts regression evidence; cannot be the requester.

03
Promotion approver

Authorises the effective public snapshot.

04
Security reviewer

Confirms signature, trust, sequence, and exposure controls.

05
Rollback approver

Authorises restoration during a declared incident.

Compromise response

Revocation closes trust, not history.

  1. 01Revoke the affected key immediately.
  2. 02Quarantine unpromoted packages signed by it.
  3. 03Identify accepted sequences and snapshots.
  4. 04Declare incident and assess public exposure.
  5. 05Rollback only with separated authority.
  6. 06Register replacement through a new ceremony.
P010/P011 export pack →Intake architecture →Recovery architecture →Security architecture →