approvedcompleteApache-2.0

Born-with certificate + agentic posture binding (LI-2)

012-born-with-provenance

Every stamped app is born with a provenance certificate that states, at the moment of stamping, what it was stamped from and what agentic posture it was born under. The template owns the certificate's schema and its validator; the factory (statecraft) owns emission. This lands the reserved [provenance] contract table from spec 009 §3.3 and is absorption line item LI-2 of spec 010. Lineage: the born-with cert + agenticPostureBinding flow proven in the template-encore era; the design facts an implementer needs are inlined here, no external archive required.

Establishes
  • .statecraft/born-with.schema.json
  • scripts/verify-born-with.mjs
  • scripts/verify-born-with.test.ts
  • scripts/fixtures/born-with.example.json
Sections
  • 012: Born-with certificate + agentic posture
  • 1. Purpose
  • 2. Territory
  • 3. Certificate shape (v1)
  • 4. Canonical form and hash
  • 5. template.toml [provenance] (contract 0.3.0)
  • 6. Acceptance
  • 7. Out of scope
Source
specs/012-born-with-provenance/spec.md @ dc4c9237e12aas of 2026-07-21 · shard fdbeec652afb