Owner selects type, label, scope, permissions, child types/ceilings, depth, child count, expiration, rate limits, approvals, and bootstrap mode; Key is inactive.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.draft
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Key draft
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Owner selects type, label, scope, permissions, child types/ceilings, depth, child count, expiration, rate limits, approvals, and bootstrap mode; Key is inactive.
- Modality
modalityStrength or status of the source statement. - recommendation
Four component slots plus public-bundle verifier, each with random claim token, expiry, single-use state, and separate confirmation code; only token hashes stored.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.slots
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Five enrollment slots
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Four component slots plus public-bundle verifier, each with random claim token, expiry, single-use state, and separate confirmation code; only token hashes stored.
- Modality
modalityStrength or status of the source statement. - recommendation
- Slots
slotsRecorded inventory field; its exact name and structure are preserved. - Authentication
- Delegation
- Authorship
- Confidentiality
- Public bundle verification
Destination receives one-time URL while dashboard separately displays confirmation code.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.claim_delivery
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Claim-link delivery
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Destination receives one-time URL while dashboard separately displays confirmation code.
- Modality
modalityStrength or status of the source statement. - recommendation
Device enters code, locally generates assigned pair, registers public key, proves possession for Ed25519, and displays/exports private component once.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: Firm statementThe source states this firmly, rather than as a suggestion.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.local_generation
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Local component generation
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Device enters code, locally generates assigned pair, registers public key, proves possession for Ed25519, and displays/exports private component once.
- Modality
modalityStrength or status of the source statement. - firm_statement
- Exports
exportsRecorded inventory field; its exact name and structure are preserved. - Copy
- QR representation
- Checksummed text
- Encrypted .cre8component file
Fifth device receives ID, four public keys/fingerprints, type, parent, policy hash, and creation time for comparison.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.public_verification
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Public bundle verification
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Fifth device receives ID, four public keys/fingerprints, type, parent, policy hash, and creation time for comparison.
- Modality
modalityStrength or status of the source statement. - recommendation
Logical Key becomes active only after confirmation.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.activation
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Owner activation
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Logical Key becomes active only after confirmation.
- Modality
modalityStrength or status of the source statement. - recommendation
Four private components imported into encrypted local nine-field payload; Argon2id-derived key and XChaCha20-Poly1305, with decrypted components only in process memory while unlocked.
What this representsThis entry is recorded as Enrollment stage in the Items section.
Statement status: RecommendationThis is recommended guidance rather than a final requirement.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.client_consolidation
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Authorized-client consolidation
- Kind
kindStructural role of this entry within the catalogue. - enrollment_stage
- Description
descriptionHuman-language explanation preserved by the inventory. - Four private components imported into encrypted local nine-field payload; Argon2id-derived key and XChaCha20-Poly1305, with decrypted components only in process memory while unlocked.
- Modality
modalityStrength or status of the source statement. - recommendation
Lower-assurance modes must not be prohibited; record mode and available client/destination/network evidence and acknowledgement without claiming IP proves device separation.
What this representsThis entry is recorded as Enrollment configuration in the Items section.
Statement status: Firm statementThe source states this firmly, rather than as a suggestion.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.assurance_modes
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Bootstrap assurance modes
- Kind
kindStructural role of this entry within the catalogue. - enrollment_configuration
- Description
descriptionHuman-language explanation preserved by the inventory. - Lower-assurance modes must not be prohibited; record mode and available client/destination/network evidence and acknowledgement without claiming IP proves device separation.
- Modality
modalityStrength or status of the source statement. - firm_statement
- Modes
modesRecorded inventory field; its exact name and structure are preserved. - split_5
- split_3
- split_2
- single
Hardware custody device is discussed for later and explicitly deferred from MVP.
What this representsThis entry is recorded as Future component in the Items section.
Statement status: Explicit deferralThe source deliberately leaves this outside the first MVP.
- Id
idStable catalogue identity. Ordinary edits should preserve it. - enroll.hardware
- Name
nameRecorded inventory field; its exact name and structure are preserved. - Hardware CRE8 device
- Kind
kindStructural role of this entry within the catalogue. - future_component
- Description
descriptionHuman-language explanation preserved by the inventory. - Hardware custody device is discussed for later and explicitly deferred from MVP.
- Modality
modalityStrength or status of the source statement. - explicit_deferral