{
  "schema_version": "0.1.0",
  "catalogue_status": "discovery_inventory",
  "authority": "Evidence-derived inventory; not a final implementation-governing SSOT. Preserve source modality and consult conflicts.json.",
  "category": "product_domains",
  "description": "Authorship, attestations, sharing, communications, keyrings, audit, directory, integrations, and automation.",
  "items": [
    {
      "id": "domain.authorship",
      "name": "Authorship",
      "kind": "product_domain",
      "description": "Draft, sign, publish, version, amend, withdraw, co-sign, namespace, and provenance capabilities.",
      "modality": "proposal",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "197-229"
        }
      ]
    },
    {
      "id": "domain.credentials",
      "name": "Credentials and attestations",
      "kind": "product_domain",
      "description": "Credential drafting, issuing, signing, verification, presentation, lifecycle, schemas, delegation, and provenance; distinct from CRE8 Keys.",
      "modality": "proposal",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "231-262"
        }
      ]
    },
    {
      "id": "domain.sharing",
      "name": "Sharing",
      "kind": "product_domain",
      "description": "Share creation, recipients, forwarding, limits, receipts, ciphertext retrieval, and provenance; ciphertext access does not imply decryptability.",
      "modality": "proposal",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "263-284"
        }
      ]
    },
    {
      "id": "domain.communications",
      "name": "Communications",
      "kind": "product_domain",
      "description": "Messages/channels and metadata/ciphertext delivery; cryptography occurs client-side. Complex channels/group encryption deferred.",
      "modality": "proposal",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "286-311"
        },
        {
          "file": "docs/seed/MVP_Cut_Line.txt",
          "lines": "38-39"
        }
      ]
    },
    {
      "id": "domain.keyring",
      "name": "Keyring custody",
      "kind": "product_domain",
      "description": "Encrypted bundle/reference custody without permission inheritance or execution of contained Keys.",
      "modality": "firm_statement",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "313-341"
        }
      ]
    },
    {
      "id": "domain.audit",
      "name": "Audit and provenance",
      "kind": "product_domain",
      "description": "Self/descendant/tenant views and exports, hash-chain verification, annotations, and provenance. No Key can edit/delete events.",
      "modality": "firm_statement",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "343-371"
        }
      ]
    },
    {
      "id": "domain.directory",
      "name": "Public directory",
      "kind": "product_domain",
      "description": "Public keys, profiles, aliases, proofs, lineage/provenance, contact policy; Owner/private email data excluded.",
      "modality": "firm_statement",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "403-419"
        }
      ]
    },
    {
      "id": "domain.integrations",
      "name": "Integrations and automation",
      "kind": "product_domain",
      "description": "Webhook, integration, import/export, and automation namespace reserved but deferred.",
      "modality": "explicit_deferral",
      "sources": [
        {
          "file": "docs/seed/Permissions_Catalogue.txt",
          "lines": "421-443"
        }
      ]
    }
  ]
}
