Human guide / 09-lifecycle-security-alerts.json
Source-qualified discovery inventory
Lifecycle security alerts
Status, rotation, suspension, quarantine, freeze, revocation, compromise response, clamps, and alerts.
Document context
How to read this page Every value below mirrors the JSON document. Friendly labels and explanations add context without replacing the exact field name or recorded value. Follow any “raw record” link to inspect or edit the same data.
Schema versionschema_version Version of the discovery-inventory document shape.
0.1.0
Catalogue statuscatalogue_status Maturity of this catalogue data, not implementation status.
discovery_inventory
Authorityauthority How this document may be used and what it must not be mistaken for.
Evidence-derived inventory; not a final implementation-governing SSOT. Preserve source modality and consult conflicts.json.
Categorycategory Stable subject area used to organize the inventory.
lifecycle_security_alerts
Descriptiondescription Human-language explanation preserved by the inventory.
Status, rotation, suspension, quarantine, freeze, revocation, compromise response, clamps, and alerts.
On this page Items6
Preventive authorization, replay, freshness, scope, status, enrollment, and history controls.
What this represents This entry is recorded as Security controls in the Items section.
Statement status: Source description This records how the historical source describes the system.
IdidStable catalogue identity. Ordinary edits should preserve it. security.auto_clamps
NamenameRecorded inventory field; its exact name and structure are preserved. Automatic clamps
KindkindStructural role of this entry within the catalogue. security_controls
DescriptiondescriptionHuman-language explanation preserved by the inventory. Preventive authorization, replay, freshness, scope, status, enrollment, and history controls.
ModalitymodalityStrength or status of the source statement. source_description ControlscontrolsRecorded inventory field; its exact name and structure are preserved. Nonce replay rejection Tight timestamp windows Per-Key and per-action rate limits Maximum active children/depth/lifetime Resource/namespace and audience restrictions Required signature combinations Ancestor status checks and descendant propagation One-time expiring claims Component status Deny precedence Immutable policy versions and historical signatures Alert candidates for anomalous requests, minting, policy/lifecycle changes, exports, spikes, inactivity, location concurrency, and forbidden endpoints.
What this represents This entry is recorded as Security controls in the Items section.
Statement status: Source description This records how the historical source describes the system.
IdidStable catalogue identity. Ordinary edits should preserve it. security.detection
NamenameRecorded inventory field; its exact name and structure are preserved. Detection and alerts
KindkindStructural role of this entry within the catalogue. security_controls
DescriptiondescriptionHuman-language explanation preserved by the inventory. Alert candidates for anomalous requests, minting, policy/lifecycle changes, exports, spikes, inactivity, location concurrency, and forbidden endpoints.
ModalitymodalityStrength or status of the source statement. source_description Owner controls over components, Keys, children/subtrees, permissions/ceilings, minting, rotation, tenant freeze, and sessions.
What this represents This entry is recorded as Security controls in the Items section.
Statement status: Source description This records how the historical source describes the system.
IdidStable catalogue identity. Ordinary edits should preserve it. security.manual_clamps
NamenameRecorded inventory field; its exact name and structure are preserved. Owner manual clamps
KindkindStructural role of this entry within the catalogue. security_controls
DescriptiondescriptionHuman-language explanation preserved by the inventory. Owner controls over components, Keys, children/subtrees, permissions/ceilings, minting, rotation, tenant freeze, and sessions.
ModalitymodalityStrength or status of the source statement. source_description Component-specific versioning and retained old public keys preserve historical verification; rotation overlap details remain unsettled.
What this represents This entry is recorded as Lifecycle behavior in the Items section.
Statement status: Mvp inclusion The source places this concern inside the first functional MVP.
IdidStable catalogue identity. Ordinary edits should preserve it. lifecycle.rotation
NamenameRecorded inventory field; its exact name and structure are preserved. Component rotation
KindkindStructural role of this entry within the catalogue. lifecycle_behavior
DescriptiondescriptionHuman-language explanation preserved by the inventory. Component-specific versioning and retained old public keys preserve historical verification; rotation overlap details remain unsettled.
ModalitymodalityStrength or status of the source statement. mvp_inclusion Dedicated narrowly scoped compromise-report challenge is proposed; compromised Key must never resume itself.
What this represents This entry is recorded as Lifecycle behavior in the Items section.
Statement status: Firm statement The source states this firmly, rather than as a suggestion.
IdidStable catalogue identity. Ordinary edits should preserve it. lifecycle.compromise
NamenameRecorded inventory field; its exact name and structure are preserved. Compromise reporting
KindkindStructural role of this entry within the catalogue. lifecycle_behavior
DescriptiondescriptionHuman-language explanation preserved by the inventory. Dedicated narrowly scoped compromise-report challenge is proposed; compromised Key must never resume itself.
ModalitymodalityStrength or status of the source statement. firm_statement Suspension temporarily suspends descendants; revocation prevents new descendant actions immediately without rewriting provenance.
What this represents This entry is recorded as Lifecycle behavior in the Items section.
Statement status: Explicit immutable The source explicitly presents this as immutable or non-configurable.
IdidStable catalogue identity. Ordinary edits should preserve it. lifecycle.ancestor_effects
NamenameRecorded inventory field; its exact name and structure are preserved. Ancestor lifecycle propagation
KindkindStructural role of this entry within the catalogue. lifecycle_behavior
DescriptiondescriptionHuman-language explanation preserved by the inventory. Suspension temporarily suspends descendants; revocation prevents new descendant actions immediately without rewriting provenance.
ModalitymodalityStrength or status of the source statement. explicit_immutable