Publication Standard
The threshold between private work and public trust
Publication is a change in who may rely on a document. This standard explains the evidence, metadata, boundary checks, and lifecycle discipline required before that threshold can be crossed. It keeps a beautiful presentation from being mistaken for approval and keeps an AI reader from treating visibility as authority.
Continue to the Cryptographic Signing Standard, where a publication claim meets the narrower question of authenticated integrity.
Purpose
Defines provenance, eligibility, disclosure, supersession, and reproducibility requirements for publishing Stygian documents and proofs.
Architect-review operating model
- PROV-R148: Publication review SHALL record authority, eligibility, audience, disclosure scope, provenance, reproducibility, correction route, and expiry or supersession.
- PROV-R149: Unverified, private, unsafe, or authority-bound material SHALL remain withheld or clearly labelled according to its evidence state.
- PROV-R150: A publication SHALL preserve source identity, version, dependencies, and correction history.
- PROV-R151: This Draft SHALL NOT publish private material, activate deployment, or promote lifecycle status.
Interpretation cases: Conforming records eligibility and disclosure; Prohibited publishes private evidence; Boundary releases a bounded excerpt; Failure pauses publication; Loophole uses “preview” to bypass review; Misuse implies approval from visibility; Care-control protects affected persons and correction rights.
Normative clauses
- PROV-R020: A publication shall identify its document ID, version, status, digest, authority, dependencies, and applicable provenance limitations.
- PROV-R021: Only material eligible under its publication status and authority may enter a public release; a digest or signature cannot make ineligible material publishable.
- PROV-R022: Public proofs shall minimise disclosure and shall not expose private keys, credentials, recovery material, personal identity details, or protected evidence.
- PROV-R023: Supersession shall preserve the prior digest, effective relationship, reason, and historical attribution.
- PROV-R024: Publication verification shall fail closed on unknown, invalid, revoked, conflicting, incomplete, or stale evidence.
Examples and exclusions
A Draft may be reviewed privately while remaining ineligible for production publication. A valid digest does not promote a Draft to Canonical. This Draft does not connect a website, publish externally, or authorise deployment.
Publication record
Each release decision shall identify source revision, generated outputs, digest manifest, eligibility result, review evidence, limitations, superseded material, and rollback or withdrawal conditions. Public and protected evidence references shall be distinguishable. A failed build, stale manifest, private dependency, or unresolved status mismatch blocks release.
Review and withdrawal
Publication review shall include metadata, dependency, link, privacy, provenance, accessibility, and reproducibility checks. Withdrawal or supersession preserves the prior record and reason. Withdrawal does not erase historical attribution or make a later release authoritative by implication.
Eligibility matrix
| State | Review use | Production publication |
|---|---|---|
| Stub | Private drafting and dependency review | No |
| Draft | Substantive review and Architect feedback | No |
| Candidate | Ratification preparation after required evidence | No |
| Canonical | Authoritative release after Architect approval and provenance checks | Yes, subject to publication controls |
| Published | Approved non-normative public material | Yes, subject to disclosure and provenance checks |
| Superseded or Revoked | Historical reference only with status shown | No |
Publication decision method
Review shall compare audience, purpose, sensitivity, authority, dependency eligibility, provenance completeness, accessibility, reproducibility, and withdrawal plan. Preview, private review, and production publication remain distinct states.
Failure cases
Stale generated output, private dependency, leaked protected evidence, mismatched status, broken links, unreviewed supersession, and incomplete withdrawal evidence block publication and preserve an attributable failure record.
Status is evidence about lifecycle, not authority by itself. A file, digest, signature, or generated allowlist cannot assign Canonical or Published status without the governing approval. No subordinate publication rule may override the repository publication boundary or make Candidate material production-eligible.