01
Author
OWNER: PUBLISHER
None — before metafactory is involved.
Namespace rules, blueprint types
CONTRIBUTOR JOURNEY →
02
Bundle
OWNER: ARC
Tarball must parse as valid manifest.
Manifest schema, SHA-256 integrity (L-Sign-1)
03
Publisher sign
OWNER: SIGSTORE
OIDC token chains to allowlisted issuer.
Keyless OIDC provenance (L-Sign-3)
SIGNING LEVELS →
04
Handover
OWNER: CROSS-REPO SEAM
Sigstore verify + identity match.
Intake seam contract (frozen)
HANDOVER SEAM CONTRACT →
05
Attribute gate
OWNER: METAFACTORY
Per-type required attributes, README, namespace.
Per-type validation, gate rules
ATTRIBUTE GATE →
06
Clean room
OWNER: METAFACTORY
L1 deterministic + L2 content + L3 sandbox.
Observer model, sandbox tiers, counterfactual runs
CLEAN ROOM →
07
Sponsor review
OWNER: METAFACTORY
Reviewer checklist, dual-control approval.
Human review required, sponsor model
08
Registry sign
OWNER: METAFACTORY
Sponsor approval + dual-control signing ceremony.
Ed25519 dual-control ceremony (L-Sign-2)
SIGNING LEVELS →
09
Publish
OWNER: METAFACTORY
Mechanical — once signed.
Content-addressed storage
10
Install + enforce
OWNER: ARC
4 independent crypto checks.
Install seam contract (frozen)
INSTALL SEAM CONTRACT →