CONTINUUM · PROVIDER-ORIGIN OUTCOME AUTHORITY
S3 HEAD+GET · short-lived signed handle · participant CockroachDB
The action worker cannot mint its own success.
Only a fresh provider re-read can issue the proposal-bound promotion handle. CockroachDB consumes the handle digest, outcome, and canonical memory atomically; invalid authority produces zero outcome rows.
VERIFYING STATIC RECEIPTS
Outcome rows—
Canonical promotions—
Journal rows—
Scope-visible rows—
S3 receipt lookups—
Blocked authority paths—
Proposal-scoped reconciliation journal
Deployment artifact SHA-256
—Journal chain tip
—Accepted S3 receipt commitment
—Conflicting S3 receipt commitment
—Consumed handle digest
—Atomic attestation/outcome/memory joins
—Bounded claim: one retained proposal and six negative controls on the participant cluster, not a population estimate. The signing key and raw handle never enter the artifact, database, or repository; only opaque SHA-256 commitments remain.