CONTINUUM · SEPARATED OUTCOME AUTHORITY
AWS KMS · real S3 re-read · participant CockroachDB
The action worker can execute. It cannot sign success.
An independent verifier re-reads the provider receipt and alone can call KMS. CockroachDB stores the algorithm, authority epoch, and a key-ARN digest—not a reusable handle—then verifies old outcomes after restart without another signature.
VERIFYING STATIC RECEIPTS
KMS signatures—
Verifier keys—
S3 re-reads—
Canonical promotions—
Fail-closed checks—
Private handoffs left—
Signed authority lifecycle
Public receipt SHA-256
—Canonical receipt SHA-256
—Deployment artifact SHA-256
—Exact workflow run
—Persisted authority epochs
—Worker KMS sign attempt
—Bounded claim: one retained dual-key lifecycle on the participant AWS account and CockroachDB cluster. It proves role separation, rotation, rollback, offline restart, exact replay, RLS, and independent cleanup; it is not a population-level reliability estimate. Key ARNs, raw handles, credentials, and database rows are absent.