01Governed Identity
Resolves the exact subject, artifact, configuration, execution, and responsible authority before action.
02Capability Envelopes
Defines what a governed configuration may do, to which resources, under which conditions, and for how long.
03Immutable Evidence
Preserves attributable, append-only safety, policy, execution, provenance, containment, and certification records.
04Certification Lifecycle
Separates evaluation success, certification state, deployment readiness, release authority, and continuous recertification.
05Containment Authority
Records suspension, quarantine, command acknowledgment, verified effects, and release prerequisites.
06Governed Datasets
Manages data contracts, validated snapshots, quality state, lineage, exports, dataset versions, and certification evidence.