ATLAS/TRUST MODEL/LIFECYCLE/THE CONTRIBUTOR JOURNEY SHEET L / 07

The Contributor Journey

From registration to steward — how you join, verify your identity, publish your first blueprint, and grow.

CONTRIBUTOR JOURNEY — FROM REGISTRATION TO STEWARD
SHEET L / 07 CONTRIBUTOR JOURNEY — FROM REGISTRATION TO STEWARD YOU applicant METAFACTORY registry / web UI VERIFIER trusted member SPONSOR assigned reviewer CLEAN ROOM automated pipeline STEWARD governance register account (email + password) enable MFA (TOTP or WebAuthn) link GitHub identity ○ NEW — you can browse and install verify applicant identity (GitHub history + real name) sponsor assigned promote to ◐ IDENTIFIED ◐ IDENTIFIED — you can submit blueprints arc bundle → submit first blueprint validate report + checklist approve published! after 3+ published → eligible for ● PROVEN sponsor nominates for ● PROVEN approve ● PROVEN (7-day objection window) ● PROVEN — you can peer-review others' updates endorse ◆ TRUSTED (14-day comment period) ◆ TRUSTED — you can sponsor new contributors and approve blueprints nominate ★ STEWARD (community vote, 30-day consideration) ★ STEWARD — governance decisions, tier promotions, incident response COMMUNITY REVIEWER — contribute through review, no publication rights needed Vouched by ◆ Trusted or ★ Steward. Security pros, domain experts, adjacent-ecosystem developers. Review attestations visible to sponsors. FIVE TIERS: ○ NEW → ◐ IDENTIFIED → ● PROVEN → ◆ TRUSTED → ★ STEWARD Each tier expands what you can do. Trust is earned through sustained contribution, peer endorsement, and community consensus. Community Reviewers contribute through review alongside any tier.
REGISTER

Register and secure your account

Create an account on metafactory with email and password.

Enable MFA immediately — this is a hard gate. TOTP (authenticator app) at minimum, hardware key (WebAuthn/FIDO2) preferred. SMS is not accepted (SIM swap risk).

Link your GitHub account — this establishes your public identity and lets verifiers check your contribution history.

At this point you’re ○ NEW: you can browse the atlas, install blueprints, and explore — but you can’t publish yet.

VERIFY

Identity verification and sponsor assignment

A ◆ Trusted or ★ Steward member verifies your identity: they check your GitHub profile has meaningful activity (not newly created), and that your real name is verifiable (LinkedIn, personal site, conference talks, open-source presence).

If you’re not personally known to any existing member, two independent verifications are required (dual-control).

You’re assigned a sponsor — a ◆ Trusted or ★ Steward member who agrees to review your first submissions.

Your namespace is reserved (@your-name/) and you sign the publisher agreement.

A ★ Steward promotes you to ◐ IDENTIFIED — you can now submit blueprints.

Target: 48 hours from application to ◐ IDENTIFIED for clear-cut cases.

PUBLISH

Submit your first blueprint

Run arc bundle ./my-blueprint — arc creates a signed tarball (Sigstore keyless, tied to your OIDC login) and submits it.

The clean room runs four automated checks: attribute gate, deterministic analysis, content scan, quarantine sandbox.

Your sponsor reviews the automated report and your code: do the capabilities make sense? Is the README clear?

If they request changes, fix and resubmit. If they approve, metafactory signs and publishes.

Your blueprint appears in the atlas — consumers can arc install @your-name/blueprint.

GROW

Trust tier progression

FROMTOCRITERIAPROCESS
◐ IDENTIFIED● PROVEN3+ published blueprints, sustained contributions, sponsor endorsementSponsor nominates, 7-day objection window, steward approves
● PROVEN◆ TRUSTED5+ maintained blueprints, security awareness, community consensus14-day public comment period, steward endorsement required
◆ TRUSTED★ STEWARDGovernance judgment, community trust, long-term commitmentSteward nomination, community vote, 30-day consideration

Each promotion expands what you can do: ● PROVEN can peer-review others’ updates. ◆ TRUSTED can sponsor new contributors and approve new blueprints. ★ Steward can promote tiers, make governance decisions, and coordinate incident response.

Demotion is possible for policy violations or security incidents — trust is earned and maintained, not permanent.

COMMUNITY REVIEWER

Contributing without publishing

Not everyone who contributes needs to publish code. The Community Reviewer role recognizes people who contribute through review.

Security professionals, domain experts, experienced developers from adjacent ecosystems (MCP, Homebrew, Debian) — anyone who can evaluate whether a blueprint does what it claims.

Vouched for by a ◆ Trusted or ★ Steward member, same identity verification as onboarding. No publication rights needed.

Community Reviewers can provide review attestations visible to sponsors and consumers, flag security concerns, and participate in review discussions.

← Back to Lifecycle Trust Model →