{
  "schema_version": "0.1.0",
  "catalogue_status": "discovery_inventory",
  "authority": "Evidence-derived scope and verification inventory; criteria retain source strength and are not expanded with invented pass conditions.",
  "category": "mvp_scope_verification",
  "mvp_inclusions": [
    {
      "name": "Owner signup/email verification/password login/secure sessions",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "System Admin gift-account creation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Tenant and Owner separation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Primary Author creation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Four local keypair claims",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Fifth public-bundle verification claim",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "One-, three-, five-device bootstrap modes",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Public-key/component-version storage",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Signed Author API requests",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Authentication plus purpose signatures",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Parent-child hierarchy",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Immutable policy versions",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Child subset validation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "All four Key types",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Authored-object signing/verification",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Immediate suspension/revocation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Component rotation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Historical public-key retention",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Owner lineage/activity/permission views",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Append-only events",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Basic alerts",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Encrypted local client key file",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "Reference PHP CLI",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    },
    {
      "name": "PostgreSQL backup/restoration procedure",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "2-27"
      }
    }
  ],
  "explicit_deferrals": [
    {
      "name": "Real payments",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Hardware CRE8 device",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Threshold signatures",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Shamir secret sharing",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Multi-parent delegation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Distributed offline authorization",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Blockchain anchoring",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Public transparency log",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Multi-region deployment",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Webhooks",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Complex channels/group encryption",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Mobile applications",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Third-party identity federation",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "OPA-like policy engines",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Redis/distributed nonce caching",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    },
    {
      "name": "Microservices",
      "source": {
        "file": "docs/seed/MVP_Cut_Line.txt",
        "lines": "28-44"
      }
    }
  ],
  "critical_acceptance_tests": [
    {
      "id": "acceptance.01",
      "statement": "Stealing only the Authentication private key cannot mint a child.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "5"
      }
    },
    {
      "id": "acceptance.02",
      "statement": "Stealing only the Delegation private key cannot perform an ordinary API operation.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "6"
      }
    },
    {
      "id": "acceptance.03",
      "statement": "Stealing only the Authorship private key cannot publish through the API.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "7"
      }
    },
    {
      "id": "acceptance.04",
      "statement": "Stealing only the Box private key cannot authenticate, mint, or publish.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "8"
      }
    },
    {
      "id": "acceptance.05",
      "statement": "The Credential ID and all four public keys grant no access.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "9"
      }
    },
    {
      "id": "acceptance.06",
      "statement": "A child cannot receive an action absent from its parent’s delegation ceiling.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "10"
      }
    },
    {
      "id": "acceptance.07",
      "statement": "A child cannot widen its resource scope.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "11"
      }
    },
    {
      "id": "acceptance.08",
      "statement": "A child cannot create a longer-lived descendant than permitted.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "12"
      }
    },
    {
      "id": "acceptance.09",
      "statement": "Revoking a parent immediately blocks every descendant.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "13"
      }
    },
    {
      "id": "acceptance.10",
      "statement": "Suspending one component does not unnecessarily destroy unrelated historical verification.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "14"
      }
    },
    {
      "id": "acceptance.11",
      "statement": "Rotating a component does not invalidate historical signatures.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "15"
      }
    },
    {
      "id": "acceptance.12",
      "statement": "The Owner can inspect every Key and event without possessing Author private keys.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "16"
      }
    },
    {
      "id": "acceptance.13",
      "statement": "The System Admin Owner cannot cryptographically impersonate an Author.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "17"
      }
    },
    {
      "id": "acceptance.14",
      "statement": "A claim token cannot be used twice.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "18"
      }
    },
    {
      "id": "acceptance.15",
      "statement": "A request nonce cannot be used twice.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "19"
      }
    },
    {
      "id": "acceptance.16",
      "statement": "A modified body fails signature verification.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "20"
      }
    },
    {
      "id": "acceptance.17",
      "statement": "A modified permission policy changes its policy hash.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "21"
      }
    },
    {
      "id": "acceptance.18",
      "statement": "Paid and gift accounts produce identical authorization decisions.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "22"
      }
    },
    {
      "id": "acceptance.19",
      "statement": "No private Author component appears in the database, application logs, error reports, analytics, email, or backups.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "23"
      }
    },
    {
      "id": "acceptance.20",
      "statement": "An alert is produced for every permission expansion, Primary Author mint, delegation rotation, and subtree revocation.",
      "source": {
        "file": "docs/seed/Critial_Acceptance_Tests.txt",
        "lines": "24"
      }
    }
  ],
  "open_operational_concerns": [
    {
      "name": "Schema and migration",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Owner/parent-authorized enrollment",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Client Ed25519 generation",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Non-exportable private persistence",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Public JWK registration",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Single-use challenges",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Server signature verification",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Proof-bound sessions/requests",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Replay protection",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Rotation and overlap",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Extension UI",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    },
    {
      "name": "Tests and documentation",
      "source": {
        "file": "docs/seed/Considerations.txt",
        "lines": "1-23"
      }
    }
  ]
}
