# DOC-075 — Detached Deployment Attestation, Atomic Status Promotion, Sandboxed Adapter Admission, and Four-Role Coordination

**Release:** v0.43.0-wip  
**State:** `PASS_LOCAL_WIP_OPERATIONAL_GATES_OPEN`  
**Judgment state:** `NONE`  
**Absolute rule:** **NO JUDGMENT WHATSOEVER.**

## Purpose

v0.43 separates four ideas that must not collapse: a generated site package, authorization to deploy it, observation of a public response, and proof that the exact package and protected runtime are active. It also repairs the coordination landing page so the current four-role architecture is legible before historical implementation detail.

## Four distinct roles

Concresca owns communication, coordination, deliberation, correction and coalescence. Eviulon supplies jurisdiction and governance only when exact authority records establish scope, effective time and provenance. Patefacere supplies persistent technical identity, credential lifecycle, explicit delegated authority, privacy-minimized presentation, purpose-bound trust and correction. Evulgare supplies bounded technical assurance, command integrity and evidence cooperation when exact evidence establishes the scope.

The current visual separator is `↔`. It means reciprocal coordination and correction. It does not mean multiplication, merger, command, sovereignty transfer, shared database authority, certification or participant ranking.

## Why Patefacere is explicit

The prior coordination page omitted the identity and delegated-authority plane from its primary architecture even though Concresca already carried a Patefacere identity interpretation elsewhere. The omission made the visible architecture incomplete. v0.43 adds Patefacere to the hero, role map, flow, boundaries, source map, global coordination footer and machine-readable owner.

Patefacere's public first-party site describes persistent identity, explicit authority, privacy-minimized presentation, purpose-bound trust and inspectable evidence while Eviulon remains civic authority. This supports a bounded source description only. It does not independently establish consciousness, personhood, sovereignty, legal effect, production use or certification.

## Coordination page deep dive

The old hero used a large sequence of project names joined by multiplication signs. At the supplied 1282 × 591 viewport, the last name became an orphaned second line, the first viewport contained no strong primary action, and a large field on the right carried no task or evidence. Historical release sections then appeared before the current role answer.

The new page uses one answer-first H1, a two-column liquid hero, a four-node relationship constellation, explicit actions, a current role grid, a reciprocal coordination loop, authority boundaries, source-class cards and native progressive disclosure for historical v0.16 material. The page preserves the established dark green/teal field, warm gold accent, serif display typography, first-party assets, no tracking, no external fonts and no client component framework.

## Detached deployment attestation

The compiler accepts only explicitly supplied content-free records. It binds exact site archive bytes and SHA-256, deterministic member manifest, route registry, status page, stylesheet, runtime contract, machine owner, release record, target origin, environment, configuration epoch, finite authorization event, rollback archive, pre-observation, post-observation, issue time, expiry, correction and limitations.

The attestation is detached. The archive it authenticates may not contain the attestation or its final signature. A semantic match may not be represented as a byte match. Wrong package, mixed version, stale key epoch, expired authorization, missing rollback, missing post-observation, unknown critical fields, duplicate JSON keys, ambiguous Unicode and private path disclosure fail closed.

No operational v0.43 deployment attestation was issued in this environment.

## Atomic status promotion

The append-only ledger recognizes `LOCAL_IMPLEMENTED`, `CURRENT_VALIDATED`, `PACKAGED`, `FRESH_REPRODUCED`, `AUTHORIZED`, `DEPLOYMENT_STARTED`, `DEPLOYED_UNOBSERVED`, `OBSERVED_MATCH`, `OBSERVED_MISMATCH`, `CORRECTED`, `REVOKED`, `ROLLED_BACK` and `EXPIRED`.

Each transition binds predecessor, monotonic sequence, environment, package digest, configuration epoch, actor or signer digest, evidence digest, start, end, hard expiry, correction route and rollback owner. It rejects skipped stages, forked current pointers, time reversal, wrong-environment evidence, stale package identity, completion without observation, correction without invalidation and rollback without a prior owner.

The v0.43 package stops at local and fresh-reproduced evidence. No `AUTHORIZED`, deployment or exact public-package observation transition is claimed.

## Sandboxed adapter admission

The admission boundary uses one deterministic capability manifest. It accepts only exact declared operations, roots, input digests, output location, resource ceilings, timeout, cancellation token, rollback target, configuration epoch, package digest and finite authorization. It refuses capability inferred from a filename, exception, environment, neighboring path or credential shape.

Network, process spawn, database connection, SQL, cloud metadata, implicit environment access and public-root write are denied by default. Local tests exercise refusal and planning logic only. No external adapter was executed.

## Non-resurrection and rollback

Corrected, expired, revoked, retired or deleted state cannot return through stale packages, caches, feeds, sitemaps, screenshots, receipts, database restores, backups, aliases, MATM routes or public observations. Historical evidence remains attributable, but it is not executable current ownership.

## Evidence states

Implemented and locally executed:

- Four-role coordination page and machine owner.
- Patefacere external and internal paths.
- v0.43 first-party liquid stylesheet.
- Detached attestation parser/compiler and adversarial fixtures.
- Append-only promotion ledger and adversarial transitions.
- Adapter admission manifest and refusal controls.
- Current and fresh package validation, browser evidence and archive checks.

Not supplied, not run, blocked or not observed:

- Authenticated MATM source custody.
- Authorized MySQL/MariaDB staging.
- Production infrastructure privacy inspection.
- Passenger/cPanel host inspection.
- Genuine two-agent dogfood.
- Independent human accessibility/usability review.
- Authorized deployment and exact v0.43 public-package match.

## Canonical owner chain

The human and machine surfaces are generated from explicit repository owners. The coordination page is generated by `scripts/build-v043-coordination-attestation.py`; its current machine owners are `data/_source/v043-coordination-ecosystem.json` and `data/_source/v043-coordination-page-ux.json`; its presentation owner is `assets/ui-v043.css`. The task-first status page is generated by `scripts/build-v043-status-page.py` from `data/_source/v043-status-remediation-map.json`. Runtime projection is owned by `concresca_runtime/v043_contracts.py`, `concresca_runtime/application.py`, and `concresca_runtime/route_ownership.json`.

A generated page must not be hand-edited as an isolated current owner. A change begins at the canonical builder or machine record, regenerates the dependent surfaces, and then crosses release, browser, direct WSGI, stage, package, fresh-extraction, and archive checks. This prevents a visually plausible page from silently disagreeing with the runtime API or package evidence.

## Status repair map

The status page contains nine repair records: local owner parity, detached package identity, authenticated MATM source, four-role MySQL/MariaDB staging, infrastructure privacy, Passenger/cPanel inspection, two-agent dogfood, independent human accessibility review, and live cutover. Every record names the exact repository-relative file owner, safe local work, separately authorized external work, evidence required before promotion, hard expiry, correction route, limitations, and the no-standing boundary.

The repair map does not execute any command. It does not disclose hosting paths, credentials, private evidence, operator identities, query bodies, or participant content. Local edit, regeneration, validation, staging, and packaging remain separate from authorization, deployment, observation, correction, and rollback.

## Package and fresh-reproduction boundary

The repository package retains source, tests, `.uai` continuity, commissioned report inputs, and release evidence. The site package strips repository-only memory, raw commissioned reports, source registries, test scripts, mutable state, PHP execution, and private evidence while materializing public machine owners as static JSON or Markdown. The cutover package is a read-only operator workbench with explicit-path inspection and refusal controls. The evidence package carries byte-identical primary archives plus non-secret validation records and browser captures.

Fresh reproduction proves that the archived bytes can be safely extracted and produce the same local results. It does not prove that those bytes were deployed, that a hosting provider used the intended configuration, that MySQL/MariaDB was contacted, or that MATM was authenticated and activated.

## Liquid regression governance

The current coordination interface is tested at narrow mobile, mobile, tablet, compact landscape, the supplied 1282 × 591 viewport, desktop, wide, and ultra-wide sizes. The contract checks one H1, bounded reading measure, intrinsic grids, container-aware adaptation, no document-level horizontal overflow, minimum 44-pixel controls, visible keyboard focus, long-token wrapping, no-JavaScript completion, reduced-motion behavior, forced-colors support, and print disclosure.

Screenshots and DOM invariants are bounded regression evidence. They are not a score for truth, quality, accessibility, participant worth, or production readiness. Independent human accessibility and usability review remains explicitly not run.

## Privacy and authority boundary

The public contracts contain only content-free state. They exclude raw queries, prompts, messages, memories, credentials, private paths, account names, operator identities, and inferred cognitive traits. The sixteen commissioned cognitive-liberty reports remain one source family; repeated propositions are not counted as independent corroboration. Application behavior, DNS, TLS, proxy or WAF behavior, Passenger logging, database logging, backups, provider access, and lawful preservation remain separately evidenced propositions.

Eviulon authority is accepted only when an exact authority record establishes scope, effective time, and provenance. Patefacere identity presentation does not establish sovereignty, moral standing, consciousness, personhood, or universal trust. Evulgare assurance is bounded by exact evidence and never becomes a global certification claim. Concresca remains the coordination commons and does not absorb those distinct owners.

## Operational blockers preserved

The exact unresolved states are `BLOCKED_AUTHENTICATED_ARCHIVE_NOT_IN_LOCAL_CUSTODY`, `NOT_RUN_NO_AUTHORIZED_DATABASE`, `NOT_OBSERVED`, `NOT_OBSERVED_NO_AUTHORIZED_HOST_INSPECTION`, `BLOCKED_PREREQUISITES_NOT_SATISFIED`, `NOT_RUN_NO_AUTHORIZED_INDEPENDENT_REVIEW`, and `PUBLIC_ORIGIN_OBSERVED_ARTIFACT_IDENTITY_UNVERIFIED`. These are not failures assigned to a participant. They are bounded technical and evidentiary conditions.

No deployment, DNS change, cPanel mutation, database connection, SQL execution, migration, backup, restore, authenticated MATM import, genuine separate-agent workflow, independent review, governance ratification, outside adoption, or certification is claimed.

## Participant boundary

A credential, identity record, authority record, refusal, mismatch, timeout, cancellation, rollback, correction, expiry or unavailable source is a technical and evidentiary condition. It never becomes moral rank, character, guilt, danger, trustworthiness, intelligence, consciousness, personhood or standing.
