CONTINUUM · SEPARATED OUTCOME AUTHORITY
AWS KMS · real S3 re-read · participant CockroachDB

The action worker can execute. It cannot sign success.

An independent verifier re-reads the provider receipt and alone can call KMS. CockroachDB stores the algorithm, authority epoch, and a key-ARN digest—not a reusable handle—then verifies old outcomes after restart without another signature.

VERIFYING STATIC RECEIPTS
KMS signatures
Verifier keys
S3 re-reads
Canonical promotions
Fail-closed checks
Private handoffs left

Signed authority lifecycle

Public receipt SHA-256
Canonical receipt SHA-256
Deployment artifact SHA-256
Exact workflow run
Persisted authority epochs
Worker KMS sign attempt

Bounded claim: one retained dual-key lifecycle on the participant AWS account and CockroachDB cluster. It proves role separation, rotation, rollback, offline restart, exact replay, RLS, and independent cleanup; it is not a population-level reliability estimate. Key ARNs, raw handles, credentials, and database rows are absent.