CONTINUUM · PROVIDER-ORIGIN OUTCOME AUTHORITY
S3 HEAD+GET · short-lived signed handle · participant CockroachDB

The action worker cannot mint its own success.

Only a fresh provider re-read can issue the proposal-bound promotion handle. CockroachDB consumes the handle digest, outcome, and canonical memory atomically; invalid authority produces zero outcome rows.

VERIFYING STATIC RECEIPTS
Outcome rows
Canonical promotions
Journal rows
Scope-visible rows
S3 receipt lookups
Blocked authority paths

Proposal-scoped reconciliation journal

Deployment artifact SHA-256
Journal chain tip
Accepted S3 receipt commitment
Conflicting S3 receipt commitment
Consumed handle digest
Atomic attestation/outcome/memory joins

Bounded claim: one retained proposal and six negative controls on the participant cluster, not a population estimate. The signing key and raw handle never enter the artifact, database, or repository; only opaque SHA-256 commitments remain.