Skip to Content
ConceptsChain of CustodyOverview

Chain of Custody Overview

This is a living index, not a spec of its own: reading Holder Claim Integrity, Cross-Custodian Convergence, and Verifier Provenance Disclosure independently doesn’t, by itself, show they’re one continuous pipeline. This page is the map: a document enters the network through one custodian, and by the time a verifier checks it, every party who ever touched it — honestly or not — has been accounted for.

If you’re arriving fresh: read this page first, then Custodian Onboarding, then the claim → convergence → disclosure arc in order. Each of those documents is self-contained and cites the others; this page is the map, not a fifth destination.

The pipeline

LinkProblem closedExplicitly not its job
Custodian OnboardingA custodian can attest a document without being (or claiming to be) the original issuer — a labeled, signed Tier-2 record.Proving the claiming holder is the real subject.
Holder Claim IntegrityThe claim step is upgraded from “controls an inbox” to “controls the inbox and holds the document” (or is a freshly-verified new identity) — closes the one true zero-click hole (fuzzy name auto-bind) entirely.Anything about a second custodian or the real issuer showing up later — that’s the network effect, not the claim itself.
Cross-Custodian ConvergenceWhen the same record crosses a second custodian, or the real issuer, the network resolves it — automatically where unambiguous, a human only on genuine ambiguity.Telling a verifier any of this happened — convergence is internal bookkeeping until disclosure exists.
Verifier Provenance DisclosureThe verifier — the actual end customer of the whole network — finds out.Changing what “valid” means; supersession is advisory, the signature was always the real proof.

Guardrail prefixes across the arc

Each document in this arc owns a distinct letter prefix for its guardrails, so a citation like “per C3” is never ambiguous across the tree:

DocumentPrefixOwns
Custodian ComplianceG1–G10Compliance/expiry/re-performance guardrails
Custodian Workforce Compliance(inherits Compliance’s G1–G10)Workforce compliance, same guardrail set
Holder Claim IntegrityC1–C8Claim-integrity guardrails
Cross-Custodian ConvergenceH1–H7Cross-custodian visibility/convergence guardrails
Verifier Provenance DisclosureV1–V5Verifier-disclosure guardrails

A citation of a bare letter+number outside its own document should always name the document too — the letter alone isn’t globally unique across the documentation tree.

Is this arc finished?

Two things are true at once:

  1. Verifier disclosure closes the safety-critical gap. Once it’s live, the one scenario that actually risks someone relying on stale information (a verifier trusting a superseded credential with no warning) is closed.
  2. A natural fifth link is already visible and deliberately not yet specified: what happens when the authoritative (Tier-1) credential is later revoked — misconduct, an accreditation lapsing, an error by the issuer. Does a previously-superseded Tier-2 attestation’s disclosure need to change? Nothing answers this yet; it’s flagged here so it isn’t mistaken for an oversight later.

Launch-blocking assessment

Per the roadmap’s target production launch, this arc splits cleanly:

  • Holder claim integrity is launch-blocking. A real institutional issuer’s first live credentials will be claimed by real holders on day one — the fuzzy-name auto-bind alone is a zero-click misdelivery path that must not exist before any real holder claims a real credential.
  • Cross-custodian convergence and verifier provenance disclosure are not launch-blocking for a first marquee issuer. Both only matter once multiple custodians and a converging original issuer are simultaneously active for the same holder population — a real scenario, but not the day-one one. Both are, as of this review, already implemented ahead of that requirement.

This assessment is a recommendation for whoever owns the roadmap to confirm or override, not a binding fact on its own.