C8Human Guide

Source-qualified discovery inventory

Enrollment activation client custody

Drafting, claim delivery, local generation, verification, activation, assurance, and local encrypted storage.

Open raw data editor05-enrollment-activation-client-custody.json

Document context

How to read this page

Every value below mirrors the JSON document. Friendly labels and explanations add context without replacing the exact field name or recorded value. Follow any “raw record” link to inspect or edit the same data.

Schema versionschema_version

Version of the discovery-inventory document shape.

0.1.0
Catalogue statuscatalogue_status

Maturity of this catalogue data, not implementation status.

discovery_inventory
Authorityauthority

How this document may be used and what it must not be mistaken for.

Evidence-derived inventory; not a final implementation-governing SSOT. Preserve source modality and consult conflicts.json.
Categorycategory

Stable subject area used to organize the inventory.

enrollment_activation_client_custody
Descriptiondescription

Human-language explanation preserved by the inventory.

Drafting, claim delivery, local generation, verification, activation, assurance, and local encrypted storage.

Structured collection

Items

9 top-level entries. Nested values are expanded inside each entry.

Open this raw section →

Enrollment stage

Key draft

Open editable raw record →

Owner selects type, label, scope, permissions, child types/ceilings, depth, child count, expiration, rate limits, approvals, and bootstrap mode; Key is inactive.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.draft
NamenameRecorded inventory field; its exact name and structure are preserved.
Key draft
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Owner selects type, label, scope, permissions, child types/ceilings, depth, child count, expiration, rate limits, approvals, and bootstrap mode; Key is inactive.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 3-20 · open exact evidence

Enrollment stage

Five enrollment slots

Open editable raw record →

Four component slots plus public-bundle verifier, each with random claim token, expiry, single-use state, and separate confirmation code; only token hashes stored.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.slots
NamenameRecorded inventory field; its exact name and structure are preserved.
Five enrollment slots
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Four component slots plus public-bundle verifier, each with random claim token, expiry, single-use state, and separate confirmation code; only token hashes stored.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 22-36 · open exact evidence
SlotsslotsRecorded inventory field; its exact name and structure are preserved.
  1. Authentication
  2. Delegation
  3. Authorship
  4. Confidentiality
  5. Public bundle verification

Enrollment stage

Claim-link delivery

Open editable raw record →

Destination receives one-time URL while dashboard separately displays confirmation code.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.claim_delivery
NamenameRecorded inventory field; its exact name and structure are preserved.
Claim-link delivery
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Destination receives one-time URL while dashboard separately displays confirmation code.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 38-42 · open exact evidence

Enrollment stage

Local component generation

Open editable raw record →

Device enters code, locally generates assigned pair, registers public key, proves possession for Ed25519, and displays/exports private component once.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Firm statement

The source states this firmly, rather than as a suggestion.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.local_generation
NamenameRecorded inventory field; its exact name and structure are preserved.
Local component generation
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Device enters code, locally generates assigned pair, registers public key, proves possession for Ed25519, and displays/exports private component once.
ModalitymodalityStrength or status of the source statement.
firm_statement
ExportsexportsRecorded inventory field; its exact name and structure are preserved.
  1. Copy
  2. QR representation
  3. Checksummed text
  4. Encrypted .cre8component file

Enrollment stage

Public bundle verification

Open editable raw record →

Fifth device receives ID, four public keys/fingerprints, type, parent, policy hash, and creation time for comparison.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.public_verification
NamenameRecorded inventory field; its exact name and structure are preserved.
Public bundle verification
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Fifth device receives ID, four public keys/fingerprints, type, parent, policy hash, and creation time for comparison.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 62-75 · open exact evidence

Enrollment stage

Owner activation

Open editable raw record →

Logical Key becomes active only after confirmation.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.activation
NamenameRecorded inventory field; its exact name and structure are preserved.
Owner activation
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Logical Key becomes active only after confirmation.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 76-78 · open exact evidence

Enrollment stage

Authorized-client consolidation

Open editable raw record →

Four private components imported into encrypted local nine-field payload; Argon2id-derived key and XChaCha20-Poly1305, with decrypted components only in process memory while unlocked.

What this represents

This entry is recorded as Enrollment stage in the Items section.

Statement status: Recommendation

This is recommended guidance rather than a final requirement.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.client_consolidation
NamenameRecorded inventory field; its exact name and structure are preserved.
Authorized-client consolidation
KindkindStructural role of this entry within the catalogue.
enrollment_stage
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Four private components imported into encrypted local nine-field payload; Argon2id-derived key and XChaCha20-Poly1305, with decrypted components only in process memory while unlocked.
ModalitymodalityStrength or status of the source statement.
recommendation
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 80-90 · open exact evidence

Enrollment configuration

Bootstrap assurance modes

Open editable raw record →

Lower-assurance modes must not be prohibited; record mode and available client/destination/network evidence and acknowledgement without claiming IP proves device separation.

What this represents

This entry is recorded as Enrollment configuration in the Items section.

Statement status: Firm statement

The source states this firmly, rather than as a suggestion.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.assurance_modes
NamenameRecorded inventory field; its exact name and structure are preserved.
Bootstrap assurance modes
KindkindStructural role of this entry within the catalogue.
enrollment_configuration
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Lower-assurance modes must not be prohibited; record mode and available client/destination/network evidence and acknowledgement without claiming IP proves device separation.
ModalitymodalityStrength or status of the source statement.
firm_statement
SourcessourcesHistorical evidence supporting this inventory entry.
  1. docs/seed/Five_Device_Instantiation.txtlines 92-109 · open exact evidence
ModesmodesRecorded inventory field; its exact name and structure are preserved.
  1. split_5
  2. split_3
  3. split_2
  4. single

Future component

Hardware CRE8 device

Open editable raw record →

Hardware custody device is discussed for later and explicitly deferred from MVP.

What this represents

This entry is recorded as Future component in the Items section.

Statement status: Explicit deferral

The source deliberately leaves this outside the first MVP.

IdidStable catalogue identity. Ordinary edits should preserve it.
enroll.hardware
NamenameRecorded inventory field; its exact name and structure are preserved.
Hardware CRE8 device
KindkindStructural role of this entry within the catalogue.
future_component
DescriptiondescriptionHuman-language explanation preserved by the inventory.
Hardware custody device is discussed for later and explicitly deferred from MVP.
ModalitymodalityStrength or status of the source statement.
explicit_deferral