Chain of Custody Overview
This is a living index, not a spec of its own: reading Holder Claim Integrity, Cross-Custodian Convergence, and Verifier Provenance Disclosure independently doesn’t, by itself, show they’re one continuous pipeline. This page is the map: a document enters the network through one custodian, and by the time a verifier checks it, every party who ever touched it — honestly or not — has been accounted for.
If you’re arriving fresh: read this page first, then Custodian Onboarding, then the claim → convergence → disclosure arc in order. Each of those documents is self-contained and cites the others; this page is the map, not a fifth destination.
The pipeline
What each link solves — and what it deliberately doesn’t
| Link | Problem closed | Explicitly not its job |
|---|---|---|
| Custodian Onboarding | A custodian can attest a document without being (or claiming to be) the original issuer — a labeled, signed Tier-2 record. | Proving the claiming holder is the real subject. |
| Holder Claim Integrity | The claim step is upgraded from “controls an inbox” to “controls the inbox and holds the document” (or is a freshly-verified new identity) — closes the one true zero-click hole (fuzzy name auto-bind) entirely. | Anything about a second custodian or the real issuer showing up later — that’s the network effect, not the claim itself. |
| Cross-Custodian Convergence | When the same record crosses a second custodian, or the real issuer, the network resolves it — automatically where unambiguous, a human only on genuine ambiguity. | Telling a verifier any of this happened — convergence is internal bookkeeping until disclosure exists. |
| Verifier Provenance Disclosure | The verifier — the actual end customer of the whole network — finds out. | Changing what “valid” means; supersession is advisory, the signature was always the real proof. |
Guardrail prefixes across the arc
Each document in this arc owns a distinct letter prefix for its guardrails, so a citation like “per C3” is never ambiguous across the tree:
| Document | Prefix | Owns |
|---|---|---|
| Custodian Compliance | G1–G10 | Compliance/expiry/re-performance guardrails |
| Custodian Workforce Compliance | (inherits Compliance’s G1–G10) | Workforce compliance, same guardrail set |
| Holder Claim Integrity | C1–C8 | Claim-integrity guardrails |
| Cross-Custodian Convergence | H1–H7 | Cross-custodian visibility/convergence guardrails |
| Verifier Provenance Disclosure | V1–V5 | Verifier-disclosure guardrails |
A citation of a bare letter+number outside its own document should always name the document too — the letter alone isn’t globally unique across the documentation tree.
Is this arc finished?
Two things are true at once:
- Verifier disclosure closes the safety-critical gap. Once it’s live, the one scenario that actually risks someone relying on stale information (a verifier trusting a superseded credential with no warning) is closed.
- A natural fifth link is already visible and deliberately not yet specified: what happens when the authoritative (Tier-1) credential is later revoked — misconduct, an accreditation lapsing, an error by the issuer. Does a previously-superseded Tier-2 attestation’s disclosure need to change? Nothing answers this yet; it’s flagged here so it isn’t mistaken for an oversight later.
Launch-blocking assessment
Per the roadmap’s target production launch, this arc splits cleanly:
- Holder claim integrity is launch-blocking. A real institutional issuer’s first live credentials will be claimed by real holders on day one — the fuzzy-name auto-bind alone is a zero-click misdelivery path that must not exist before any real holder claims a real credential.
- Cross-custodian convergence and verifier provenance disclosure are not launch-blocking for a first marquee issuer. Both only matter once multiple custodians and a converging original issuer are simultaneously active for the same holder population — a real scenario, but not the day-one one. Both are, as of this review, already implemented ahead of that requirement.
This assessment is a recommendation for whoever owns the roadmap to confirm or override, not a binding fact on its own.