SOVEREIGN\PROVENANCE
An Interoperable Lineage Protocol — Non-Tokenized, Rights-Aware, Trace-Priced
Modern Ancients LLC
Version 2.2 — 2026
Abstract
SOVEREIGN\PROVENANCE is an interoperable lineage protocol. It preserves inheritance, contribution, transformation, and stewardship as artifacts move between people, machines, organizations, and systems—without blockchain tokens or proof-of-work consensus.
Category. Interoperable lineage protocol. Function. Continuity through change: every artifact can carry a biography that other protocols can evidence and none of them currently own. Philosophy. Contribution can remain visible without requiring creation to become possession.
The protocol does not replace the internet’s existing primitives. Identity, authenticity, storage, federation, credentials, and ledgers already answer their own questions. SOVEREIGN\PROVENANCE sits among them and owns the missing semantic layer: lineage. Native engines—Identity, Seal, Passport, Accord, Ledger, Guardian—are adapters and anchors, not replacements. A deployment may mint a sovereign identity or bind a DID; merkle-anchor events natively or commit hashes to an external timestamping service. The protocol owns the lineage graph either way.
Provenance is stacked: runtime events record what happened at operational volume; critical checkpoints and authorizations fail closed; publication exports a curated proof bundle; public proof commits hashes without exposing protected content. Accords authorize rights and consent. Policy Packs evaluate records against readiness criteria and never mutate source data.
The same four protocol functions—RECORD, AUTHORIZE, CONSTRAIN, VERIFY—compose a six-layer system (material, protocol, experience, participation, institutional, economic) specified in Part II. Applied to organizational decisions they constitute decision accounting: the provenance protocol that powers a Responsible Intelligence Operating System. That category message is for buyers; this document is the constitution of the protocol underneath it.
This document establishes the conceptual, mathematical, and architectural foundations that define SOVEREIGN\PROVENANCE as a system. Implementation detail—API endpoints, SDK signatures, product tiers, and operational runbooks—lives in linked specification documents (see Appendix A.6). Market sizing, GTM, and financial scenarios live in the investor memo and data room.
The alloy protects. The core remembers.
I. Thesis
The Genesis Era
Humanity has crossed an inflection point: synthetic content now exceeds human-originated volume at industrial scale. A scientist reads forty papers; a model traverses forty million. A designer prompts a system trained on billions of artifacts; a team modifies the output; another model incorporates the result; a company commercializes it; another community adapts it. Dataset provenance is existential. Trust in digital authorship, consent, and cultural integrity is eroding under opacity.
The structural failures are not incidental—they are architectural. Most artifacts still have no cryptographic proof of creation. Consent breaks at scale with no machine-readable enforcement. Identity is fragmented. Transformation chains are not verifiable. Rights declarations are static. Synthetic outputs omit model and dataset lineage. The internet remembers events better than it remembers inheritance.
Those failures share a single missing layer.
What Provenance Is Not
Identity is not provenance. Authenticity is not provenance. Ownership is not provenance. Custody is not provenance. Transaction history is not provenance. Attribution is not provenance. Provenance is not merely history.
A file can have a hash. A person can have an identity. A claim can have a credential. A photograph can have authenticity metadata. A product can have a supply-chain history. A post can move between federated networks. A transaction can be immutably recorded. And we can still lose the story of becoming.
Provenance is continuity through change. The question is not only what happened? It is what became of what came before?
The Missing Layer
Other protocols establish facts. SOVEREIGN\PROVENANCE preserves becoming.
It records relationships among states as artifacts move:
Origin → Inheritance → Contribution → Transformation → Transmission → Derivation → Consequence
Creation no longer has a single author. “Who made what?” is no longer a sufficient question. The better questions are: What was inherited? What was contributed? What transformed? What persisted? What deserves recognition? What obligations remain? What should travel forward?
Protocol Landscape
SOVEREIGN\PROVENANCE does not sit above the internet. It sits among the protocols that already make it work, and makes them legible to one another through lineage.
| Family | Question it answers | Question it does not own |
|---|---|---|
| DID / VC | Who are you? What can you prove? | What was your relationship to what became? |
| ToIP | Why should this claim or relationship be trusted? | What lineage should persist through the trusted relationship? |
| ATProto / ActivityPub | How does information move across a federated network? | What survives as it moves? |
| W3C PROV | What entities, agents, and activities produced something? | How does inheritance persist through subsequent transformation? |
| C2PA | Is this media authentic, and what happened to it? | What larger lineage does the artifact belong to? |
| GS1 / EPCIS | Where did a product go and what happened to it? | What ecological, material, and human inheritance moved through it? |
| Solid | Who controls and accesses data? | What happened through its use and transformation? |
| IPFS / hashes | What exact object is this? | What is its biography? |
| Ledgers | What events were recorded and in what order? | What do those events mean within a lineage? |
A protocol should own as little as necessary. SOVEREIGN\PROVENANCE does not need its own identity system, blockchain, storage network, social network, credential system, or media-authenticity standard. It consumes those primitives. It is network-agnostic, storage-agnostic, ledger-agnostic, and identity-agnostic. The protocol owns the lineage.
SOVEREIGN\PROVENANCE is not another internet. It is a way for lineage to survive across the internet we already have.
When the Protocol Applies
The protocol is warranted when five conditions hold:
- Did something inherit from something else?
- Did multiple actors contribute?
- Did it transform?
- Will it move between systems?
- Does its lineage matter after it moves?
If those conditions are present—in science, culture, civic records, supply chains, creative work, models, or organizational decisions—facts about the object are not enough. The biography must travel with it.
Object Biography
Consider a photograph. IPFS can say which object it is. A DID can say who signed it. C2PA can say whether it is authentic and what edits occurred. ToIP can say whether its assertions can be trusted. ATProto can say how it circulates.
None of those answers, stacked, yields: what it inherited; who contributed to what it became; what transformations occurred; what it subsequently influenced; what obligations traveled forward; what descended from it.
The other protocols help establish facts about the artifact. SOVEREIGN\PROVENANCE preserves the artifact’s relationship to what came before and what comes after. Sequence is not inheritance. A Passport can resolve an artifact into lineage and reference evidence from other protocols rather than manufacturing all evidence itself.
From Output-Priced to Trace-Priced Economies
For centuries, markets priced outputs because they could not observe origins. Tokens attempt to represent creative value as fungible units detached from lineage, context, and intent—producing speculative distortion, environmental cost, and misaligned incentives.
Markets already record ownership → transaction → price. Innovation actually happens through inheritance → contribution → transformation → adoption → downstream value. The market frequently sees only the final monetizable artifact.
Because lineage can be made machine-readable, economies can shift: from output-priced to trace-priced. A trace is a cryptographically provable, temporally anchored record:
where i is sovereign identity (native or bound), t₀ is origin timestamp, and L is the lineage DAG of descendants. Traces capture identity, origin, intent, rights, transformations, cultural protocols, and synthetic disclosures in one verifiable structure. A trace cannot be forged; it grows in relational value as lineage expands.
The protocol records relationships. It should be capable of establishing that an artifact inherited X from a contribution, with evidence, transformation history, and subsequent lineage. It should not say Alice deserves 7%. Markets determine value. Once provenance is legible, participants can build royalties, licenses, reputation, procurement preference, grants, or simply recognition. The protocol preserves the optionality.
The Genesis Era made this shift existential. The missing layer makes it possible.
Markets saw only the event. Reality runs on the trace.
II. Ontology
SOVEREIGN\PROVENANCE is one system expressed through six layers. Each layer composes on those below; none replaces upstream semantics.

Material Layer
The material canon is a metaphor for protocol properties, not a product surface. It is how the system remembers origin while remaining tamper-evident under transmission.
| Layer | Meaning | Protocol mapping |
|---|---|---|
| Tourmaline Core | Intrinsic origin, authorship, lineage-memory | Identity adapter, Seal, temporal anchor |
| Alloy Shell | Tamper-evident integrity, rights, consent, proof without exposure | Passport, Accord, ledger anchoring |
| Transmission Field | Visible knowledge proofs, resonance, accountability under pressure | Guardian, Proof cards, Fractal overlays, ambient seals |
Artifacts emit visible knowledge proofs—signal types (positive, negative, neutral charge) and contextual overlays tied to events, usage, and chain-of-custody—without revealing protected essence.
Protocol Layer — Anchor
Anchor engines construct, bind, and query lineage. Where a named engine overlaps an existing internet primitive, the engine is an adapter or anchor, not a replacement of that primitive.
| Engine | Function | Restraint |
|---|---|---|
| SP Identity | Sovereign cryptographic identity across contexts and jurisdictions | Adapter: mint native keys or bind DID / VC |
| SP Seal | Atomic fragment hashing; derivative detection (Rust/WASM) | Complements content-addressed hashes; does not replace IPFS |
| SP Passport | Lineage biography binding identity, seal, rights, nine lineage fields, ledger | The object the protocol owns |
| SP Accord | Machine-readable, executable rights and consent | Authorizes; does not evaluate readiness |
| SP Ledger | Append-only, merkle-anchored event log | Anchor: native chain or external timestamping / ledger commit |
| SP Guardian Node | Regional enforcement, mirroring, integrity alerts | Not a social network or storage network |
| SP Synthetic | AI output registration with model/dataset lineage disclosure | Consumes model and dataset evidence; does not govern the model |
| SP Lineage | Lineage DAG construction and query | Semantic layer over facts established elsewhere |
| TVE | Read-only trace valuation over verified lineage | Never mutates provenance; never assigns a market share |
| Mission Provenance | Autonomous work: runtime events, critical checkpoints, publication export; optional Venture Cell host | Record, authorize, constrain, and verify remain separable |
Passport lineage fields
Every Passport can resolve an artifact into a biography. Fields reference evidence; they do not invent it.
| Field | Question |
|---|---|
| Origin | Where does this begin? |
| Inheritance | What came into it? |
| Contribution | Who or what added something? |
| Transformation | What changed? |
| Evidence | How do we know? |
| Stewardship | Who carried responsibility? |
| Transmission | Where did it travel? |
| Derivation | What emerged from it? |
| Consequence | What happened afterward? |
Parent and derivative identifiers remain a graph convenience. They are not a substitute for these fields.
The protocol owns four separable functions. RECORD answers what happened and never implies authorization. AUTHORIZE answers who had authority and never implies scientific truth. CONSTRAIN answers whether action was permitted and never implies correctness. VERIFY answers whether an outcome can be reconstructed and never returns truth=true.
Experience Layer
- Mirror — Operational console: workflows, lineage dashboards, Proof cards, Auditor bundles, economic telemetry, organization and API key management, and Repository Stewardship capsules. Mirror Watch is specified as reuse detection across the web and model indexes; scan coverage is a deployment capability, not a global network claim.
- Fractal — Context-intelligence layer: epistemic confidence, validation traces, metadata completeness, risk classification, and valuation overlays. Proprietary scoring remains server-side. Fractal add-ons compose on this layer; they do not substitute for protocol proofs.
- Provenance Bar — Ambient sealing at the point of creation. Origin is bound in the tool where work happens, then issued as public proof without exposing protected content.
- Repository Stewardship — Evolving context around an artifact (capsule, claims, evidence, stewardship authority). Git hosting is an evidence source and execution environment, not the provenance product. Stewardship is not the HCP Steward Workbench.
Participation Layer — Human-Centered Provenance (HCP)
HCP extends the protocol for bounded human collaboration. People participate naturally. The Cell remembers responsibly. Humans confirm only what matters. Value is calculated only when something consequential occurs.
Venture Cells are collaboration containers organized around a Purpose Covenant, with scoped RoleGrants. Before contribution, each participant completes an Opening Position—a versioned statement of inheritance, background assets, protected boundaries, opportunity cost, and reciprocity preferences.
Domain chain (ordered; no layer may skip upstream semantics):

Five experience surfaces: Personal Mirror, Collective Mirror, Steward Workbench, Adjudication Workbench, Network Mirror. Interaction follows: presence → confirm meaning → confirm consequence.
Missions may optionally attach to a Venture Cell (host_cell_id). Mission charter authority remains independent of Cell RBAC. Mission provenance establishes causal evidence; HCP allocation may consume it and must not collapse provenance into finance.
Institutional Layer
- SP Market — Innovation claims, append-only proofs, settlement events, and governance instruments (provisional licenses, risk co-signs, formal challenges). Connects provenance to outcome settlement without tradable tokens. The institutional form is a clearinghouse of claims and evidence, not a speculative venue.
- Obligation Passports — Passport specialization for debt/obligation provenance with deterministic Accord evaluation and append-only lifecycle events.
- Policy Packs — Versioned rule sets that evaluate provenance records against readiness criteria. They never modify source records, never issue certifications, and are not Accords. Accords authorize rights; Policy Packs score explainability and control completeness.
- Preservation-to-Discovery — Knowledge stewardship: preserved material is not automatically computationally legible. Atlas locates opportunity, Network makes it reachable, Journey sequences responsible next action, and SOVEREIGN\PROVENANCE is why each assertion can be trusted.
- Decision Accounting — The same protocol applied to AI-mediated organizational decisions. RECORD becomes a reasoning ledger (claims, assumptions, limits). AUTHORIZE and CONSTRAIN become a decision journal and Policy Pack readiness evaluation. VERIFY becomes a consequence register, drift detection, and outcome reconciliation. Learning compounds across artifacts. We do not govern AI systems; we govern decisions influenced by AI. SOVEREIGN\PROVENANCE is the provenance protocol that powers that operating system. Enterprise module names and buyer messaging live in GTM documents; they do not replace the protocol functions named here.
Economic Layer — Two Connected Systems
| System | Question it answers | Mutability |
|---|---|---|
| TVE | What is trace value given verified lineage and signals? | Read-only |
| HCP value | What value was created, verified, and distributable—and who authorized allocation? | Append-only; human-governed |
TVE outputs may inform allocation proposals; they never substitute for human Allocation Decisions. They never assign a percentage share.
Commercial offerings (Creator Shield, Platform Integrity, Dataset Passport, Lab Provenance, Guardian Node, Sovereign Vault, Venture Cell, and others) compose these layers for specific personas. See Product Catalog and Developer Documentation.
III. Invariants
Protocol Principles
- Sovereign Identity — Cryptographically verifiable, persistent, rights-aware; native or bound to interoperable identity standards
- Atomic Provenance — Fragment-level hashing and derivative detection
- Rights-Aware by Default — Executable, non-strippable, survives replication
- Cultural Sovereignty — Cultural protocols as first-class enforceable rights
- Tamper-Evident Records — Append-only, merkle-anchored ledger (native or externally committed)
- Non-Tokenized Architecture — Traces, not tokens; no speculative layer
- Governance-Friendly Evolution — Transparent proposals, backward compatibility
- Runtime ≠ Publication — Operational events are not public proofs; Git is never the runtime ledger
- Lineage Interoperability — Inherit existing primitives; own only the missing semantic layer
- Contribution without Possession — Visibility of contribution does not require exclusive ownership
System Ethos
- Origin cannot be severed · Lineage is memory · Integrity is structural
- Protection without extraction · Visibility without exposure · Verification without surrender
- Sovereignty as a material condition
- Stewardship with provenance · The freer ideas become, the more important provenance becomes
HCP Foundational Rule
Sovereignty precedes attribution. Attribution precedes valuation. Valuation precedes allocation. Allocation never defines human worth.
What the Protocol Never Does
- Infer or mutate provenance for valuation purposes
- Treat projected value as realized value
- Recompute historical snapshots with new economic parameters
- Expose protected content in public projections
- Allow self-adjudication on conflicted high-risk actions
- Conflate model inference permission with model training permission (default deny on protected sources)
- Create tradable tokens or speculative instruments
- Conflate runtime telemetry with publication proof
- Let Policy Packs mutate source records or issue certifications
- Collapse mission provenance into financial allocation
- Replace DID, C2PA, W3C PROV, GS1, ToIP, or other fact-establishing protocols
- Assign percentage shares, royalties, or market value as protocol truth
- Require a native identity, ledger, storage network, or social graph in order to record lineage
IV. Architecture
Interoperability Stack
Applications (science, AI, culture, civic systems, supply chains, creative work, knowledge systems) sit above a lineage layer. That layer—inheritance, contribution, transformation, stewardship, derivation, consequence—is what SOVEREIGN\PROVENANCE owns. Beneath it: interoperability with W3C PROV, C2PA, ToIP, DID / VC, and GS1 / EPCIS; network and data with ATProto, ActivityPub, Solid, IPFS, and the Web; verification and compute with cryptography, ledgers, databases, and cloud or edge.
Inherit existing primitives. Own only the missing semantic layer.
Layered Stack

The stack diagram names deployment engines. It does not require every engine to be the system of record for the primitive it touches. Identity may be bound. Ledger events may be anchored externally. Guardian Nodes enforce and mirror; they do not constitute a new public internet.
Rights and AI Authorization
Accord rules are machine-readable and non-strippable. They are enforced at protocol boundaries—upload, API, and Guardian—and are designed to survive transformation. Universal enforcement across every third-party platform is an adoption condition, not a completed network fact. Model inference (ephemeral processing) and model training (weight updates, fine-tuning corpora) remain distinct permission purposes, both requiring explicit consent with default deny for protected sources. Redaction occurs at projection boundaries before prompt assembly.
Public Proof vs Protected Content
Public projections carry hash-linked proofs and disclosure-mode-appropriate metadata only. Protected source content remains behind permission boundaries. Withdrawal and tombstone records block future re-ingestion.
Runtime vs Publication Provenance
Artifact publication and autonomous mission execution have different volume, latency, and disclosure requirements. They share one protocol and must not share one store.
RUNTIME PROVENANCE → high-volume mission events
CRITICAL PROVENANCE → signed checkpoints, authorization decisions
PUBLICATION PROVENANCE → curated manifest and proof bundle
PUBLIC PROOF → hash commitments without exposing protected content
Authorization and integrity-critical events fail closed. Informational telemetry may batch asynchronously. Git and external timestamping remain publication-only; they are never the runtime ledger. Every publication artifact retains mission_id and source_event_ids linking back to runtime records.
Sovereign Zones
Provenance truth is anchored per jurisdiction. Artifacts carry sovereignZoneId, jurisdiction, and proofPolicyId. Zones define residency, replication allowlists, and Guardian assignment. Cross-zone operations require explicit authorization.
HCP and Mission Implementation
HCP logic lives in packages/cell-core/ (types, state machines, invariants) with Cell-scoped APIs and deny-by-default row-level security. Consequential records are append-only or versioned via supersede semantics. Idempotency keys govern retried writes; outbox events handle side effects.
Mission Provenance lives in packages/mission-core/, composing on provenance-core and policy-engine. Missions are org-scoped and domain-independent. Scientific missions may optionally host in a Venture Cell; they are not a Cell subtype.
Full API, schema, and SDK reference: see Appendix A.6.
V. Economics
Markets Determine Value
The protocol’s economic claim is restraint first, then formalism.
SOVEREIGN\PROVENANCE records relationships. It does not adjudicate desert. Participants may later construct royalties, licenses, reputation, procurement preference, grants, or recognition on top of machine-readable lineage. Those constructions are markets, contracts, and governance—not protocol truth.
Legible provenance produces a flywheel: more legible provenance → greater trust → lower diligence cost → safer sharing → more contribution → more recombination → more innovation → more economic value → greater reason to preserve provenance. Compliance may be a beachhead. The larger proposition is increased economic velocity without collapsing contribution into possession.
Stewardship with provenance. The more confidently people can contribute without disappearing from the lineage, the more confidently knowledge can circulate.
Trace Formalism
Let artifacts be nodes in lineage DAG G = (𝒜, E). Let R(a) be direct payoff of artifact a, and Desc(a) its verified descendants.
where α weights direct vs inherited value and wₐ,ᵦ ∈ [0,1] attributes downstream value to ancestor a. Only verified lineage counts; provenance is never mutated by valuation. T(a) and wₐ,ᵦ are read-only signals available to human allocation; they are not an assigned share.
R-Function and Signals
Weights β and attribution rules w are governance parameters under the Economic Parameters Charter: Protocol Council approval, versioning, immutability of past snapshots. Default weights and proprietary tuning remain governance-controlled, not hard-coded in client surfaces.
Attribution strategies include fragment-proportional, lineage-depth discount:
Accord-constrained, and contract-defined overrides.
Optional economic.snapshot ledger events record point-in-time trace value without altering provenance.
HCP Value States
Consequential value progresses: projected → committed → realized → verified → distributed, with revised and reversed via superseding Correction records.
Economic pool invariant: sum(approved_allocations) + sum(reserves) = authorized_pool
Network consolidation eliminates internal double-counting across Cells.
Value Dimensions
Beyond scalar trace price, SOVEREIGN\PROVENANCE recognizes lineage value, rights-awareness value, origin protection value, contextual interaction value, cultural integrity value, misuse-prevention savings, and compliance/risk-reduction value. Organizations quantify cost-avoidance from theft, misattribution, legal exposure, dataset contamination, and unauthorized training.
Cooperative Allocation
The protocol supports Shapley-compatible allocation approximations through lineage depth, rights constraints, and derivative attribution—structural support for fair origin compensation, not a token market, and not a protocol-assigned split.
Value originates at origins, not endpoints.
VI. Governance and Sovereignty
Protocol Governance
Protocol proposals are transparent with impact analysis and migration paths. Backward compatibility preserves existing records across upgrades. Guardian Nodes are specified as participants in proposal review; a live multi-region Guardian electorate is a governance capability, not a deployed global vote.
Economic Parameters Charter governs TVE: who may set β and w, per sovereign zone or deployment. Past snapshots are never recomputed.
Accord and Policy Pack are distinct. Accords bind executable rights and consent to artifacts. Policy Packs evaluate records against versioned readiness criteria and never mutate those records. Readiness scores are operational signals—not audit opinions, attestations, or certifications.
HCP and Mission governance is codified in sixteen accepted Architecture Decision Records (Appendix A.5): module boundaries, cell isolation, disclosure modes, two-layer permission evaluation, public/protected separation, append-only versioning, evidence integrity, idempotency, human review boundaries, allocation conservation, retention/tombstones, AI-purpose authorization, runtime versus publication provenance, mission event-store architecture, event criticality, and the mission–Venture Cell relationship.
Allocation policies are versioned and pinned at decision time. Conflicted actors cannot self-approve. Policy changes never rewrite history.
Cultural Protocols
Sacred content, geographic restrictions, usage conditions, attribution customs, and community governance are first-class Accord capabilities—not edge cases. Cultural module packs extend those rights by community and jurisdiction; enforcement depth follows deployment. SOVEREIGN\PROVENANCE treats cultural sovereignty as core infrastructure.
VII. Vision
Lineage will survive across the internet we already have. Every artifact that moves between people, machines, organizations, and systems will be able to carry a biography: origin, inheritance, contribution, transformation, evidence, stewardship, transmission, derivation, and consequence—sealed in creative tools through Provenance Bar, bound at publication, evidenced by C2PA, DID, PROV, GS1, and hashes where those protocols already speak, verified without exposing protected content.
In Venture Cells, Opening Positions will preserve contributor sovereignty, mirror cycles will make attribution visible and contestable, and value return will follow verified consequence under human authority—not speculation, and not a protocol-assigned share.
Creators will be valued for contribution and ecosystem enablement without being forced into possession. AI systems will respect consent by design. Cultural protocols will have enforcement infrastructure as real as commercial licenses. Civic truth will remain verifiable as synthetic media proliferates. Organizations will account for AI-mediated decisions on the same fabric that accounts for artifacts.
This is the economic and cultural shape of digital civilization when aligned to reality: relational, lineage-based, origin-priced, and interoperable.
The freer ideas become, the more important provenance becomes.
VIII. Conclusion
SOVEREIGN\PROVENANCE is the provenance protocol that preserves becoming. It binds origin, intent, lineage, rights, synthetic disclosure, cultural sovereignty, human-centered collaboration, autonomous mission provenance, and governed value return into a single fabric—without replacing the protocols that already establish facts, and without becoming a token market or an arbiter of desert.
It restores what digital civilization lost: truth in authorship, clarity in lineage, accountability in use, respect for culture, and economic recognition of origin—extended through Venture Cells to responsible human participation, and through decision accounting to AI-influenced institutional action.
It is non-tokenized, rights-aware, governance-friendly, identity-agnostic where it should be, and built to endure.
The alloy protects. The core remembers.
As AI accelerates into the Genesis Era, provenance becomes existential. SOVEREIGN\PROVENANCE provides the missing layer upon which a truthful digital civilization can stand.
Appendices
A.1 Artifact Formats
Illustrative. Authoritative schemas live in protocol specification documents (Appendix A.6).
Manifest
{
"id": "urn:sp:manifest:...",
"artifactType": "text|image|audio|video|code|dataset",
"createdAt": "2026-09-17T10:30:00Z",
"identityId": "urn:sp:identity:...",
"seal": {
"algorithm": "sha256-frag-v1",
"hash": "abc123...",
"fragments": []
},
"metadata": {
"title": "Artifact Title",
"description": "Description",
"tags": ["tag1", "tag2"]
}
}
Passport
{
"id": "urn:sp:passport:...",
"identityId": "urn:sp:identity:...",
"sealId": "urn:sp:seal:...",
"accordId": "urn:sp:accord:...",
"metadata": {},
"lineage": {
"origin": { "statement": "...", "evidence": [] },
"inheritance": [{ "from": "urn:sp:passport:...", "relation": "inherited_from" }],
"contribution": [{ "actor": "urn:sp:identity:...", "relation": "contributed_by" }],
"transformation": [{ "through": "urn:sp:passport:...", "relation": "transformed_through" }],
"evidence": [
{ "protocol": "c2pa", "ref": "..." },
{ "protocol": "did", "ref": "..." },
{ "protocol": "ipfs", "ref": "sha256:..." }
],
"stewardship": [{ "actor": "urn:sp:identity:...", "relation": "stewarded_by" }],
"transmission": [{ "to": "urn:sp:passport:...", "relation": "transmitted_to" }],
"derivation": [{ "id": "urn:sp:passport:...", "relation": "derived_from" }],
"consequence": [{ "id": "urn:sp:passport:...", "relation": "resulted_in" }],
"parentIds": ["urn:sp:passport:..."],
"derivativeIds": ["urn:sp:passport:..."]
},
"ledgerAnchor": {
"merkleRoot": "...",
"blockHeight": 12345,
"timestamp": "2026-09-17T10:30:00Z",
"externalCommit": null
}
}
parentIds and derivativeIds index the graph. The nine fields carry meaning. evidence entries reference foreign protocols; they do not duplicate those protocols’ payloads.
Seal
{
"id": "urn:sp:seal:...",
"algorithm": "sha256-frag-v1",
"contentHash": "sha256:...",
"fragments": [
{ "offset": 0, "length": 1024, "hash": "sha256:..." }
],
"createdAt": "2026-09-17T10:30:00Z"
}
A.2 Cryptographic Specifications
| Domain | Specification |
|---|---|
| Primary hash | SHA-256 |
| Fragment hashing | SHA-256, configurable fragment size (default 1 KB) |
| Merkle trees | SHA-256 binary tree; path proofs leaf-to-root |
| Signatures | Ed25519 (recommended); secp256k1 (compatibility) |
| Key derivation | Ed25519 keypair with versioning for rotation |
| External proofs | OpenTimestamps, IPFS, or other commits where required; native ledger optional |
Proprietary scoring heuristics (Fractal drift detection, hazard signals, allocation weights beyond structure) are server-side trade secrets—not specified in this document.
A.3 Ledger Event Types
Protocol events: identity.created · identity.bound · seal.generated · passport.issued · passport.derived · accord.bound · lineage.linked · guardian.alert · synthetic.registered
Obligation events: obligation.created · obligation.terms.updated · obligation.payment.recorded · obligation.renegotiated · obligation.default.triggered · obligation.closed
Economic events: economic.snapshot
HCP events: cell.created · membership.invited · opening_position.confirmed · contribution.receipt.confirmed · value.event.recorded · allocation.decided · settlement.receipt.recorded
Mission events: mission.created · charter.created · mission.authorized · permission.granted · permission.denied · checkpoint.created · claim.asserted · human.decision.recorded
lineage.linked carries relation type (inherited_from, contributed_by, transformed_through, stewarded_by, transmitted_to, derived_from, resulted_in). identity.bound records a DID / VC or other foreign identity binding. All events are append-only with merkle chaining. Event payload schemas: see Protocol Specification (Appendix A.6).
A.4 Glossary
Accord
Machine-readable, executable rights declaration: attribution, derivatives, AI training, commercial use, cultural protocols, geographic restrictions. Accords authorize. Policy Packs evaluate.
Allocation Decision
Human-authorized approval or rejection of an allocation proposal. Automation proposes; humans confirm. The protocol never assigns a percentage share as truth.
Auditor
Compliance bundle export (EU AI Act, ISO 42001, NIH/NSF/DARPA-style) on demand via Mirror and API.
Capsule
Stewardship context around an artifact: claims, evidence, rights, and authority over time. The artifact is not the capsule.
Contribution Receipt
Record of participant contribution under specific permissions, with confirm/contest/withhold states.
Decision Accounting
Institutional application of RECORD / AUTHORIZE / CONSTRAIN / VERIFY to AI-mediated decisions: reasoning ledger, decision journal, consequence register, learning graph. Category positioning for strategy, risk, and policy buyers; not a second protocol.
Dependency Claim
Reviewed assertion linking artifact or decision to upstream sources. Dependency ≠ causality.
Demand Credential
Evidence that demand is mature enough to authorize value events.
Economic Parameters Charter
Governance charter for TVE: who sets β and w; versioning; immutability of past snapshots.
Economic Pool
Authorized allocatable amount within a Cell. Conservation: allocations + reserves = pool.
economic.snapshot
Point-in-time trace value record; does not alter provenance.
Economic Signal
Structured input for R(a): directRevenue, usageScore, complianceValue, contractValue, customValue.
Guardian Node
Regional node: rights enforcement, violation detection, integrity alerts, ledger mirroring. Not a social or storage network.
Innovation Docket
Structured innovation claim with evidence and demand maturity; feeds SP Market.
Interoperable Lineage Protocol
Category of SOVEREIGN\PROVENANCE: preserves inheritance, contribution, transformation, and stewardship across systems that already establish facts.
Lineage DAG
Directed acyclic graph of passport nodes and typed derivation edges (inheritance, contribution, transformation, stewardship, transmission, derivation, consequence).
Lineage Fields
Nine Passport biography fields: origin, inheritance, contribution, transformation, evidence, stewardship, transmission, derivation, consequence.
Manifest
Structured metadata describing artifact type, creator, seal, and metadata.
Mirror Cycle
Published Cell activity summary (draft → proposed → published).
Mirror Watch
Specified reuse detection across the web and model indexes. Operational scan coverage is deployment-dependent.
Mission Provenance
Domain-independent provenance for autonomous work. Record, authorize, constrain, and verify are separable. Optional Venture Cell host; never a Cell subtype.
Net Value Statement
Reconciled benefits, costs, externalities, liabilities for an intervention.
Obligation Passport
Passport specialization for debt/obligation provenance with deterministic evaluation.
Opening Position
Versioned pre-engagement statement: inheritance, assets, boundaries, cost, reciprocity.
Passport
Cryptographic certificate binding identity, seal, metadata, rights, nine lineage fields, and a ledger or external anchor. The object the protocol owns.
Policy Pack
Versioned rule set that evaluates provenance records against readiness criteria. Never mutates source records. Not an Accord, not a certification.
Preservation-to-Discovery
Knowledge-stewardship path: Atlas (where opportunity exists), Network (how it becomes reachable), Journey (responsible next action), provenance (why an assertion can be trusted). Preserved material is not automatically computationally legible.
Proof Card
Shareable, jurisdiction-tagged proof-of-origin card via Mirror.
Provenance Bar
Ambient sealing at the point of creation. Origin is bound in the working tool; public proof does not expose protected content.
Purpose Covenant
Versioned statement of why a VentureCell exists.
Regenerative Capacity
Portable individual, Cell, or network capacity after authorized allocation.
Repository Stewardship
Evolving context (capsule) around an artifact: origin, authorship, claims, evidence, and stewardship authority. Git hosting is evidence, not the product. Distinct from the HCP Steward Workbench.
RoleGrant
Scoped Cell authorization (participant through system_service roles).
Seal
Cryptographic hash of artifact fragments via atomic fragment hashing.
Settlement Receipt
Append-only record of what actually occurred on the ledger.
Sovereign Alloy / Tourmaline Core / Transmission Field
Material metaphor layers: protection shell, origin soul, interaction/resonance field. Metaphor for protocol properties, not a product SKU.
Sovereign Identity
Cryptographically verifiable identity with public keys and jurisdictional context. May be minted natively or bound to DID / VC.
Sovereign Zone
Jurisdiction and data residency anchor with replication allowlists.
SP Synthetic
AI output registration with model and dataset lineage disclosure.
Trace
Fundamental economic unit:
Identity, origin timestamp, and lineage DAG.
Trace Valuation Engine (TVE)
Read-only lineage valuation; never mutates provenance; never assigns a market share.
Trace Value
Direct utility plus weighted downstream value from verified descendants:
Value Event
Consequential outcome (financial, social, cultural, ecological, capacity) in HCP layer.
VentureCell
Bounded collaboration container with Purpose Covenant and tenant isolation.
A.5 Architecture Decision Records
| ADR | Title | Core decision |
|---|---|---|
| 0001 | Bounded contexts | cell-core package; apps compose; DB is source of truth |
| 0002 | Cell tenant isolation | VentureCell wraps org; deny-by-default RLS |
| 0003 | Disclosure modes | Six modes; preserved in derived records |
| 0004 | Permission runtime | Legal consent + Accord purpose evaluation |
| 0005 | Public vs protected | Hash-linked proofs; no secrets in projections |
| 0006 | Append-only records | Supersede, never erase |
| 0007 | Evidence integrity | SHA-256 content hash; proofs ≠ truth |
| 0008 | Idempotency | Idempotency keys; outbox for side effects |
| 0009 | Human review | Automation proposes; no self-adjudication |
| 0010 | Allocation invariants | Conservation pools; network elimination |
| 0011 | Retention/tombstones | Withdrawal blocks re-ingestion |
| 0012 | AI-purpose auth | Inference ≠ training; default deny protected |
| 0013 | Runtime vs publication | Mission events ≠ publication proofs; Git is publication-only |
| 0014 | Mission event store | Hybrid PostgreSQL; branch-scoped chains; no dedicated graph DB |
| 0015 | Event criticality | Informational async; authorization and integrity fail closed |
| 0016 | Mission and HCP | Missions are org-scoped; optional host_cell_id; provenance ≠ finance |
Full text: docs/adr/ in the SOVEREIGN\PROVENANCE repository.
A.6 Reference Documentation
| Document | Location | Contents |
|---|---|---|
| Protocol Positioning | /protocol | Public thesis: landscape, restraint, passport fields |
| Protocol Overview | docs/protocol/overview.md | Component details, data flow |
| Protocol Specification | /protocol/specification | Engines, Accords, commercial offerings |
| API Reference | /docs/developer/api | Endpoints, authentication, examples |
| SDK Documentation | /docs | JavaScript, Python, Go integrations |
| Product Catalog | /docs/protocol/product-catalog | Commercial offerings by persona |
| Narrative Alignment | docs/business/narrative-alignment.md | Protocol vs category (decision accounting) |
| Investor Memo | /investors/docs/investor-memo | TAM/SAM/SOM, GTM, risks |
| HCP Architecture | docs/hcp/architecture-foundation.md | VentureCell, domain chain, surfaces |
| HCP Domain Glossary | docs/hcp/domain-glossary.md | Full HCP vocabulary |
| Mission Provenance | docs/mission-provenance/ | Runtime/publication stack, protocol spec |
| Policy Packs | docs/governance/product/ | Readiness evaluation; not certification |
| Repository Stewardship | docs/repository-stewardship/ | Capsules, claims, evidence, authority |
| Preservation-to-Discovery | docs/preservation-to-discovery/ | Atlas, Network, Journey, evidence |
| Provenance Bar | docs/developer/provenance-bar.md | Ambient sealing at creation |
| Economic Parameters Charter | docs/governance/economic-parameters-charter.md | TVE governance |
| Sovereign Zones | docs/governance/sovereign-zones.md | Jurisdiction and residency |
| Obligation Passports | docs/obligation-passports/ | Schema and lifecycle |
| SP Market Architecture | docs/sp-market-architecture.md | Clearinghouse domain model |
Version History
Version 2.2 (2026-09-17) — Lineage protocol thesis
- Re-anchored category as interoperable lineage protocol; Genesis Era retained as historical condition
- Added protocol landscape, restraint architecture, nine Passport lineage fields, object biography, and standard test
- Distinguished adapters/anchors (Identity, Ledger, Guardian) from the lineage layer the protocol owns
- Placed Decision Accounting once under the institutional layer; market material remains in the investor memo
- Stated economic restraint before TVE formalism: markets determine value; the protocol does not assign shares
- Updated invariants, A.1 Passport schema, A.3 lineage relation types, glossary, and A.6 (
/protocolis positioning, not the overview spec)
Version 2.1 (2026-09-05) — Ontology refresh
- Named Mission Provenance in the protocol layer: runtime, critical, publication, and public proof
- Distinguished Accord (rights) from Policy Packs (readiness evaluation)
- Indexed Repository Stewardship, Preservation-to-Discovery, and Provenance Bar
- Extended ADR appendix through 0016; refreshed A.6
- Clarified architectural versus operational language for Fractal, Mirror Watch, and Guardian proposal review
Version 2.0 (2026-08-03) — Structural rewrite
- Consolidated six-layer ontology (material → protocol → experience → participation → institutional → economic)
- Single canonical architecture; eliminated redundant sections (duplicate math, overlapping product/use-case narratives)
- IP boundary discipline: artifact formats and crypto in appendices; API/SDK/types moved to reference docs
- Unified glossary (A.4); ADR summary (A.5); reference index (A.6)
- ~50% reduction in body length; thesis-driven structure (Parts I–VIII)
Version 1.4 (2026-08-03)
- Human-Centered Provenance, system ethos, Sovereign Zones, TVE/HCP distinction, ADR appendix
Version 1.2 (2026-02-21)
- Trace Valuation Engine, Economic Telemetry, Economic Parameters Charter
Version 1.1 (2026-02-21)
- Sovereign Stack, Obligation Passports, commercial offerings expansion
Version 1.0 (2025-01-15)
- Initial publication