approvedcompleteApache-2.0
Born-with certificate + agentic posture binding (LI-2)
012-born-with-provenance
Every stamped app is born with a provenance certificate that states, at the moment of stamping, what it was stamped from and what agentic posture it was born under. The template owns the certificate's schema and its validator; the factory (statecraft) owns emission. This lands the reserved [provenance] contract table from spec 009 §3.3 and is absorption line item LI-2 of spec 010. Lineage: the born-with cert + agenticPostureBinding flow proven in the template-encore era; the design facts an implementer needs are inlined here, no external archive required.
- Depends on
- Establishes
- .statecraft/born-with.schema.json
- scripts/verify-born-with.mjs
- scripts/verify-born-with.test.ts
- scripts/fixtures/born-with.example.json
- Sections
- 012: Born-with certificate + agentic posture
- 1. Purpose
- 2. Territory
- 3. Certificate shape (v1)
- 4. Canonical form and hash
- 5. template.toml [provenance] (contract 0.3.0)
- 6. Acceptance
- 7. Out of scope
- Source
- specs/012-born-with-provenance/spec.md @ dc4c9237e12aas of 2026-07-21 · shard fdbeec652afb