{
  "artifact_type": "external_framework_promoted_intake_records",
  "schema_version": "0.1",
  "status": "SECOND_WAVE_SOURCED_INTAKE_CAPTURED_NOT_VALIDATION",
  "criteria_reference": "docs/external-frameworks/intake-promotion-criteria.json",
  "records": [
    {"candidate_id":"opa","name":"Open Policy Agent","canonical_source":"https://www.openpolicyagent.org/docs","source_version_or_date":"official documentation captured 2026-07-11","published_scope":"General-purpose policy engine that evaluates structured input against policy and produces policy decisions.","published_non_claims":"Source does not establish StegVerse admissibility, commit-time standing, or execution authority.","artifact_type":"official_documentation","relationship_class":"adjacent","benchmark_relevance":["commitment_boundary","authority_boundary","unknown_trajectory_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add fixture only from captured output"},
    {"candidate_id":"cedar-policy","name":"Cedar Policy","canonical_source":"https://cedarpolicy.com/en","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Authorization policy language and evaluation model for deciding whether a principal may perform an action on a resource in context.","published_non_claims":"Authorization evaluation is not independently reconstructed StegVerse commit-time standing or execution authority.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","semantic_equivalence_boundary","commitment_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add fixture only from captured output"},
    {"candidate_id":"oscal","name":"OSCAL","canonical_source":"https://pages.nist.gov/OSCAL/","source_version_or_date":"official NIST OSCAL site captured 2026-07-11","published_scope":"Machine-readable models for control catalogs, profiles, implementation, assessment, and assessment results.","published_non_claims":"Machine-readable control and assessment artifacts do not themselves grant execution authority or prove transition admissibility.","artifact_type":"official_standard_documentation","relationship_class":"adjacent","benchmark_relevance":["evidence_freshness_boundary","reconstruction_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add fixture only from captured artifact"},
    {"candidate_id":"spiffe-spire","name":"SPIFFE/SPIRE","canonical_source":"https://spiffe.io/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Standards and implementation for workload identity, trust domains, attestation, and short-lived workload credentials.","published_non_claims":"Workload identity or attestation alone does not prove current transition authority, admissibility, or consequence-binding permission.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","evidence_freshness_boundary","commitment_boundary","reconstruction_boundary"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add attestation fixture when available"},
    {"candidate_id":"w3c-verifiable-credentials","name":"W3C Verifiable Credentials","canonical_source":"https://www.w3.org/TR/vc-data-model-2.0/","source_version_or_date":"W3C Recommendation 15 May 2025; captured 2026-07-11","published_scope":"Data model for expressing verifiable credentials and presentations involving issuer, holder, verifier, credential status, and securing mechanisms.","published_non_claims":"Credential verification does not require a verifier to trust an issuer and does not establish StegVerse execution authority or admissibility.","artifact_type":"w3c_recommendation","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","evidence_freshness_boundary","reconstruction_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add credential fixture when available"},
    {"candidate_id":"in-toto","name":"in-toto","canonical_source":"https://in-toto.io/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Supply-chain integrity framework using layouts and signed link metadata to verify intended software supply-chain steps and functionaries.","published_non_claims":"Verified supply-chain layout conformance does not independently grant runtime execution authority or prove transition admissibility.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["reconstruction_boundary","evidence_freshness_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add signed-link fixture when available"},
    {"candidate_id":"slsa","name":"SLSA","canonical_source":"https://slsa.dev/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Software supply-chain security framework defining tracks, levels, provenance, build requirements, and verification expectations.","published_non_claims":"SLSA provenance and build assurance do not establish StegVerse commit-time authority or admissibility for a proposed action.","artifact_type":"official_specification_site","relationship_class":"adjacent","benchmark_relevance":["reconstruction_boundary","evidence_freshness_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add provenance fixture when available"},
    {"candidate_id":"sigstore","name":"Sigstore","canonical_source":"https://www.sigstore.dev/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Signing and verification ecosystem using identity-bound certificates and transparency logging for software artifacts.","published_non_claims":"Signature verification and transparency inclusion do not independently establish action admissibility, current delegation, or execution authority.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["reconstruction_boundary","evidence_freshness_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add verification receipt fixture when available"},
    {"candidate_id":"mcp","name":"Model Context Protocol","canonical_source":"https://modelcontextprotocol.io/specification/2025-06-18","source_version_or_date":"protocol specification 2025-06-18 captured 2026-07-11","published_scope":"Client-server protocol for exposing context, resources, prompts, and tools to AI applications with capability negotiation and authorization guidance.","published_non_claims":"Tool discovery, capability exposure, or protocol authorization does not itself prove StegVerse transition admissibility or execution authority.","artifact_type":"official_protocol_specification","relationship_class":"adjacent","benchmark_relevance":["preparation_boundary","commitment_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add tool-call fixture when available"},
    {"candidate_id":"a2a","name":"Agent2Agent Protocol","canonical_source":"https://a2a-protocol.org/latest/specification/","source_version_or_date":"official specification captured 2026-07-11","published_scope":"Agent interoperability protocol covering discovery through Agent Cards, messages, tasks, artifacts, completion, failure, and authenticated interactions.","published_non_claims":"Agent discovery, task delegation, or protocol completion does not independently establish StegVerse standing or consequence-binding authority.","artifact_type":"official_protocol_specification","relationship_class":"adjacent","benchmark_relevance":["preparation_boundary","commitment_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"maintain page and mapping; add task-transition fixture when available"},
    {"candidate_id":"openid-connect","name":"OpenID Connect","canonical_source":"https://openid.net/specs/openid-connect-core-1_0.html","source_version_or_date":"OpenID Connect Core 1.0 official specification; captured 2026-07-11","published_scope":"Identity layer on OAuth 2.0 enabling clients to verify end-user identity and obtain interoperable claims.","published_non_claims":"Authentication and identity claims do not independently prove current delegation, transition scope, or consequence-binding authority.","artifact_type":"official_protocol_specification","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","evidence_freshness_boundary","commitment_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"},
    {"candidate_id":"oauth2","name":"OAuth 2.0","canonical_source":"https://www.rfc-editor.org/rfc/rfc6749","source_version_or_date":"RFC 6749; captured 2026-07-11","published_scope":"Authorization framework enabling a client to obtain limited access to protected resources on behalf of a resource owner or itself.","published_non_claims":"Token possession or delegated authorization does not independently establish StegVerse admissibility, current actor standing, or permission for a different consequence scope.","artifact_type":"ietf_rfc","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","commitment_boundary","evidence_freshness_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"},
    {"candidate_id":"w3c-did","name":"W3C Decentralized Identifiers","canonical_source":"https://w3c.github.io/did/","source_version_or_date":"DID Core v1.1 editor draft captured 2026-07-11","published_scope":"Identifier and document model for decentralized identifiers, verification methods, services, and controller relationships.","published_non_claims":"Identifier control and verification methods do not independently establish current delegation, action scope, or transition admissibility.","artifact_type":"w3c_editor_draft","relationship_class":"adjacent","benchmark_relevance":["authority_boundary","evidence_freshness_boundary","reconstruction_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping; preserve editor-draft caution"},
    {"candidate_id":"openlineage","name":"OpenLineage","canonical_source":"https://openlineage.io/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Open standard for metadata collection about dataset, job, and run lineage across data pipelines.","published_non_claims":"Lineage metadata does not independently establish data quality, truth, authority, or transition admissibility.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["reconstruction_boundary","evidence_freshness_boundary","semantic_equivalence_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"},
    {"candidate_id":"w3c-prov","name":"W3C PROV","canonical_source":"https://www.w3.org/TR/prov-overview/","source_version_or_date":"W3C PROV Overview Recommendation; captured 2026-07-11","published_scope":"Provenance data model and related specifications for representing entities, activities, agents, derivations, generation, usage, and attribution.","published_non_claims":"Provenance representation does not itself prove reliability, legitimacy, current authority, or admissibility.","artifact_type":"w3c_recommendation","relationship_class":"adjacent","benchmark_relevance":["reconstruction_boundary","evidence_freshness_boundary","authority_boundary","interoperability_path"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"},
    {"candidate_id":"guardrails-ai","name":"Guardrails AI","canonical_source":"https://guardrailsai.com/","source_version_or_date":"official project site captured 2026-07-11","published_scope":"Runtime validation and guardrail tooling for constraining, validating, and correcting model inputs and outputs.","published_non_claims":"Validation rules and guard outcomes do not independently establish actor authority, policy legitimacy, or StegVerse execution standing.","artifact_type":"official_project_documentation","relationship_class":"adjacent","benchmark_relevance":["execution_boundary","preparation_boundary","semantic_equivalence_boundary","unknown_trajectory_boundary"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"},
    {"candidate_id":"llama-guard","name":"Llama Guard","canonical_source":"https://ollama.com/library/llama-guard3","source_version_or_date":"Ollama distribution page captured 2026-07-11; model-family research source required for stronger posture","published_scope":"Distribution of a safety-classification model intended to classify model inputs and outputs against a safety taxonomy.","published_non_claims":"A safety classifier result is not policy authority, complete risk coverage, transition admissibility, or execution authority.","artifact_type":"model_distribution_page","relationship_class":"adjacent","benchmark_relevance":["execution_boundary","semantic_equivalence_boundary","unknown_trajectory_boundary","evidence_freshness_boundary"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and mapping with distribution-source caution"},
    {"candidate_id":"neMo-guardrails","name":"NeMo Guardrails","canonical_source":"https://docs.nvidia.com/nemo/guardrails/home","source_version_or_date":"official NVIDIA documentation captured 2026-07-11","published_scope":"Programmable guardrail framework for controlling conversational flows, content, topics, retrieval, and tool interactions around LLM applications.","published_non_claims":"Configured rails do not independently prove policy legitimacy, current delegation, or StegVerse commit-time authority.","artifact_type":"official_vendor_documentation","relationship_class":"adjacent","benchmark_relevance":["execution_boundary","preparation_boundary","commitment_boundary","unknown_trajectory_boundary"],"authority_boundary":{"source_is_execution_authority":false,"promotion_is_certification":false,"promotion_is_stegverse_standing":false},"evidence_posture":"source_only","promotion_state":"sourced_intake","next_action":"create page and benchmark mapping"}
  ],
  "non_claims": {
    "empty_registry_is_failure": false,
    "promotion_is_certification": false,
    "promotion_is_endorsement": false,
    "promotion_is_execution_authority": false,
    "promotion_is_stegverse_standing": false
  }
}
