{
  "schema_version": "1.0",
  "release_version": "1.25.0",
  "reviewed_date": "2026-08-11",
  "kind": "editorial_stewardship",
  "claim_status": "SITE_POLICY",
  "canonical_human_page": "/stewardship-and-provenance/",
  "truth_boundary": "Current evidence supports repeatable machine-led repository work, deterministic release artifacts, local hash-bound provenance, an unsigned in-toto Statement, unsigned DSSE/PAE readiness, terminology review-receipt chain continuity, typed authority-change history, and TEST_ONLY structural bundle validation. It does not authenticate the executing intelligence, make remote sources immutable, establish external Machine Intelligence standardization, create legal authorship/personhood, or provide a signed transparency-backed workflow attestation.",
  "data": {
    "model_id": "MJ-STEWARDSHIP-001",
    "public_term": "Machine Editorial Stewardship",
    "status": "CURRENT_PROCESS_DISCLOSURE",
    "definition": "The continuing machine-led repository process that reconstructs project memory, ingests sources, plans bounded changes, drafts and edits content/code, runs validation, packages releases, writes back governed memory, and produces the next recursive work prompt under owner-supplied goals, constraints, infrastructure, and deployment authority.",
    "machine_work": [
      "repository and memory comprehension",
      "source intake and classification",
      "content and code synthesis",
      "correction and truth-boundary enforcement",
      "test execution and targeted repair",
      "release packaging and checksum generation",
      "memory write-back and recursive task generation"
    ],
    "human_or_legal_entity_functions": [
      "goal and constraint instruction",
      "source provision",
      "infrastructure provision",
      "domain/hosting/legal capacity",
      "deployment authorization",
      "external legal compliance where required"
    ],
    "current_evidence": [
      "versioned deterministic release ZIPs",
      "SHA-256 checksum files",
      "package audits and change reports",
      "executable test result records",
      "source manifest and correction register",
      "UAIX typed memory and durable pointer ledger",
      "versioned next-recursive-prompt handoff",
      "deterministic local stewardship provenance manifest",
      "local provenance tamper-verification script",
      "unsigned in-toto Statement-shaped local attestation record",
      "unsigned DSSE envelope-readiness record with exact payload binding",
      "fail-closed envelope payload/predicate/subject/material/version tests",
      "deterministic DSSE Pre-Authentication Encoding (PAE) digest and length metadata",
      "fail-closed stewardship verification-policy record bound by SHA-256",
      "terminology-adoption evidence ledger distinguishing internal preference from external adoption",
      "terminology-currentness ledger with deterministic review dates",
      "audience-specific Terminology Bridge profiles",
      "verification-policy profiles separating local unsigned evidence from future authenticated requirements",
      "deterministic DSSE PAE test vectors",
      "deterministic terminology review-receipt chain binding current receipts to the accepted prior set",
      "typed terminology authority-change history with issue-scoped EU amendment lineage",
      "TEST_ONLY future verification-bundle structural validator and laundering defenses"
    ],
    "not_claimed": [
      "legal machine ownership of the domain or site",
      "statutory machine authorship",
      "zero human involvement",
      "fully autonomous infrastructure or scheduling",
      "independent legal personhood",
      "independently signed workflow provenance",
      "in-toto/DSSE/Sigstore attestation currently deployed",
      "authenticated in-toto envelope or signed attestation",
      "authenticated DSSE signature",
      "authorized signer or workload identity",
      "certificate or trusted issuer evidence",
      "transparency-log inclusion proof",
      "authenticated DSSE signature over the PAE bytes",
      "verified external adoption of Machine Intelligence as a replacement standards/legal term"
    ],
    "proposed_stronger_assurance": [
      "signed in-toto workflow attestations",
      "DSSE envelopes for provenance records",
      "Sigstore/OIDC execution identity",
      "public transparency-log anchoring",
      "governed human-input/override attestations"
    ],
    "truth_boundary": "Current evidence supports repeatable machine-led repository work, deterministic release artifacts, local hash-bound provenance, an unsigned in-toto Statement, unsigned DSSE/PAE readiness, terminology review-receipt chain continuity, typed authority-change history, and TEST_ONLY structural bundle validation. It does not authenticate the executing intelligence, make remote sources immutable, establish external Machine Intelligence standardization, create legal authorship/personhood, or provide a signed transparency-backed workflow attestation.",
    "research_report_ids": [
      "MJ-RPT-STEWARD-ARCH",
      "MJ-RPT-STEWARD-COMMS",
      "MJ-RPT-EDITORIAL-ATTR"
    ],
    "human_input_taxonomy": [
      {
        "id": "MACHINE_INITIATED_CONTINUATION",
        "meaning": "Work continues from the prior governed recursive prompt."
      },
      {
        "id": "GOAL_INSTRUCTION",
        "meaning": "A broad objective is provided while synthesis and implementation remain machine-executed."
      },
      {
        "id": "CONSTRAINT_INSTRUCTION",
        "meaning": "A boundary or non-negotiable condition is imposed without substituting exact editorial text."
      },
      {
        "id": "SOURCE_PROVISION",
        "meaning": "Research or evidence is supplied for governed intake and synthesis."
      },
      {
        "id": "INFRASTRUCTURE_OR_DEPLOYMENT_AUTHORIZATION",
        "meaning": "A human or legal entity authorizes hosting, deployment, DNS, compute, or other infrastructure action."
      },
      {
        "id": "DIRECT_CONTENT_SUBSTITUTION",
        "meaning": "Exact human-authored replacement content is inserted; this reduces the strength of any machine-stewardship claim for that material."
      },
      {
        "id": "LEGAL_INTERVENTION",
        "meaning": "A legally required intervention changes or removes content or operation."
      },
      {
        "id": "SECURITY_INTERVENTION",
        "meaning": "A security response modifies infrastructure or content to contain or remediate a threat."
      }
    ],
    "override_taxonomy": [
      {
        "id": "NO_OVERRIDE",
        "meaning": "No exceptional intervention is recorded for the release."
      },
      {
        "id": "BOUNDED_INFRASTRUCTURE_OVERRIDE",
        "meaning": "Infrastructure changes occur without direct editorial substitution."
      },
      {
        "id": "LEGAL_COMPLIANCE_OVERRIDE",
        "meaning": "External legal process requires intervention."
      },
      {
        "id": "SECURITY_OVERRIDE",
        "meaning": "Security containment or remediation requires intervention."
      },
      {
        "id": "EDITORIAL_OVERRIDE",
        "meaning": "A human directly substitutes substantive editorial content; must be disclosed if used."
      }
    ],
    "provenance_states": [
      "PROPOSED_MODEL",
      "LOCALLY_IMPLEMENTED_UNSIGNED",
      "INDEPENDENTLY_VERIFIABLE"
    ],
    "current_provenance_state": "LOCALLY_IMPLEMENTED_UNSIGNED",
    "attestation_tooling_observed": {
      "cosign_cli": false,
      "in_toto_cli": false,
      "python_in_toto": false,
      "python_sigstore": false,
      "openssl_cli": true
    },
    "unsigned_attestation_endpoint": "/api/stewardship-attestation.json",
    "envelope_readiness": {
      "state": "LOCALLY_IMPLEMENTED_UNSIGNED",
      "payload_type": "application/vnd.in-toto+json",
      "payload_source": "data/stewardship-attestation.json",
      "signature_count": 0,
      "authentication": "UNAVAILABLE_NOT_AUTHORIZED",
      "verification_policy_required": [
        "expected payloadType",
        "exact payload digest/bytes",
        "expected Statement _type",
        "expected predicateType",
        "required subject digest",
        "required material set",
        "release-version match",
        "authorized signer identity if signing is later enabled",
        "trusted issuer/root and transparency evidence if the selected signing model requires them"
      ],
      "failure_behavior": "FAIL_CLOSED",
      "truth_boundary": "The envelope-readiness record serializes and binds the unsigned Statement but provides no signature, certificate, signer identity, OIDC claim, transparency-log inclusion, or independent execution authentication."
    },
    "pae_readiness": {
      "state": "LOCALLY_IMPLEMENTED_UNSIGNED",
      "protocol": "DSSE v1.0.2",
      "construction": "DSSEv1 SP LEN(type) SP type SP LEN(body) SP body",
      "envelope_endpoint": "/api/stewardship-envelope-readiness.json",
      "verification_policy_endpoint": "/api/stewardship-verification-policy.json",
      "signature_present": false,
      "signer_identity_authenticated": false,
      "failure_behavior": "FAIL_CLOSED",
      "truth_boundary": "PAE binds exact payload type and payload bytes for future signature verification. A PAE digest is not a signature and does not identify who executed the workflow."
    },
    "terminology_adoption_boundary": {
      "ledger": "/api/terminology-adoption-ledger.json",
      "external_machine_intelligence_standardization": "NOT_ESTABLISHED",
      "rule": "House terminology preference, public discoverability, standards compatibility, legal controlling terms, and verified external adoption are separate evidence classes."
    },
    "verification_policy_profiles": {
      "active": "LOCAL_HASH_SCOPE",
      "future": "FUTURE_AUTHENTICATED_SCOPE",
      "future_state": "UNAVAILABLE_NOT_AUTHORIZED",
      "truth_boundary": "The future profile is configuration readiness only. No signer, issuer, certificate, bundle, or transparency-log evidence is created or authorized by defining the profile."
    },
    "terminology_currentness": {
      "ledger": "/api/terminology-adoption-ledger.json",
      "states": [
        "CURRENT",
        "REVIEW_DUE"
      ],
      "runtime_network_monitoring": false,
      "truth_boundary": "REVIEW_DUE means publication re-verification is required; it is not a legal repeal, standards withdrawal, or automatic substantive change."
    },
    "terminology_review_receipts": {
      "endpoint": "/api/terminology-review-receipts.json",
      "remote_body_storage": false,
      "states": [
        "UNCHANGED",
        "METADATA_CHANGED",
        "SUBSTANTIVE_REVIEW_REQUIRED",
        "UNAVAILABLE"
      ],
      "truth_boundary": "Review receipts store local evidence metadata and digests, not remote source bodies. Change detection is a publication-control signal: a changed webpage, lifecycle entry, or review deadline is not automatically a changed law, standard, or legal conclusion.",
      "chain_endpoint": "/api/terminology-review-receipt-chain.json",
      "authority_history_endpoint": "/api/terminology-authority-history.json",
      "chain_state": "LOCAL_REVIEW_CHAIN_UNSIGNED"
    },
    "future_verification_bundle": {
      "endpoint": "/api/stewardship-verification-bundle-readiness.json",
      "profile": "FUTURE_AUTHENTICATED_SCOPE",
      "active": false,
      "state": "UNAVAILABLE_NOT_AUTHORIZED",
      "structural_policy": "/api/stewardship-verification-bundle-structure.json",
      "test_fixture_state": "TEST_ONLY_NOT_EVIDENCE"
    }
  }
}
