Skip to main content

Tier 1 Source Intake Work Packets

Purpose

This page turns the Tier 1 promotion queue into bounded source-capture work packets.

A work packet is not a promotion. It defines what must be collected before a candidate can move from source_required to sourced_intake.

work packet != sourced intake
work packet != page candidate
work packet != benchmark mapping
work packet != endorsement
work packet != execution authority

Required Capture Fields

Every Tier 1 packet must collect:

canonical_source
source_version_or_date
published_scope
published_non_claims
artifact_type
relationship_class
benchmark_relevance
authority_boundary
evidence_posture

Tier 1 Packets

CandidateFamilyCapture focusTarget state
Open Policy Agentpolicy_as_codepolicy decision model, input/output contract, decision authority boundary, runtime integrationsourced_intake
Cedar Policypolicy_as_codeauthorization model, policy language scope, entity/action semantics, decision boundarysourced_intake
OSCALrisk_and_assurancemachine-readable controls, assessment artifacts, evidence references, control versioningsourced_intake
SPIFFE/SPIREidentity_and_authorityworkload identity, trust domains, attestation, credential lifecyclesourced_intake
W3C Verifiable Credentialsidentity_and_authoritycredential model, roles, proof/status, revocation semanticssourced_intake
in-totoprovenance_and_tracesupply-chain layout, link metadata, functionary identity, verificationsourced_intake
SLSAprovenance_and_traceprovenance levels, build integrity, source/builder identity, verificationsourced_intake
Sigstoreprovenance_and_traceartifact signing, identity binding, transparency log, verificationsourced_intake
Model Context Protocolagent_protocolstool/resource contracts, client-server roles, capability exposure, authorizationsourced_intake
Agent2Agent Protocolagent_protocolsagent identity, task delegation, artifact exchange, completion/failure semanticssourced_intake

Completion Rule

A packet is complete only when all required capture fields are present and the source is canonical enough to support independent review.

A packet with missing fields remains source_capture_required. It must not be copied into the promoted-intake registry.

Non-Claims

Packet completion does not certify the framework.
Packet completion does not prove compatibility.
Packet completion does not grant authority.
Packet completion does not establish benchmark standing.
Packet completion only permits sourced-intake review.

Standing remains a separate commit-time reconstruction question.