Depends on: #10
Outcome
Define when authorization approval and governed-read evidence is byte-reconstructible, when it is only digest-verifiable, and which separately governed retention policy controls the underlying bytes.
Primary trust boundary
Authorization evidence retention and custody: the boundary that owns retention duration, encryption posture, deletion/redaction behavior, and key-custody requirements for human-visible approval representations and disclosed payloads.
Acceptance criteria
- Require approval evidence to bind content-addressed human-visible bytes, media type, renderer/version/digest, display-policy ref/digest, locale, timezone, and retention-policy ref/digest.
- Define governed-read proof postures at least as retained bytes versus digest-only, with no byte-reconstruction claim for digest-only evidence.
- Bind payload media type, serializer/version/digest, serialization policy, payload digest, and retention-policy identity into the receipt.
- Preserve the immutable receipt, digest, disclosure time, proof-strength posture, and historical disclosure fact after governed byte deletion or redaction.
- Define policy requirements for retention duration, encryption, deletion, redaction, and key custody without selecting or implementing a provider.
- Add hostile cases for renderer/serializer drift, unavailable display bytes, deleted retained payloads, false reconstruction claims, digest mismatch, and privacy rules that prohibit payload retention.
Non-goals
No authorization outcome changes, no domain result contract, no transport-release semantics, no storage/provider implementation, no key issuance or rotation, and no production-readiness claim.
Delivery rule
The canonical policy/contract change stays separate from later storage, encryption, and key-custody implementation PRs.
What is next: inventory existing evidence-retention and custody contracts before proposing the minimum compatible extension.
Depends on: #10
Outcome
Define when authorization approval and governed-read evidence is byte-reconstructible, when it is only digest-verifiable, and which separately governed retention policy controls the underlying bytes.
Primary trust boundary
Authorization evidence retention and custody: the boundary that owns retention duration, encryption posture, deletion/redaction behavior, and key-custody requirements for human-visible approval representations and disclosed payloads.
Acceptance criteria
Non-goals
No authorization outcome changes, no domain result contract, no transport-release semantics, no storage/provider implementation, no key issuance or rotation, and no production-readiness claim.
Delivery rule
The canonical policy/contract change stays separate from later storage, encryption, and key-custody implementation PRs.
What is next: inventory existing evidence-retention and custody contracts before proposing the minimum compatible extension.