WTK / TARGET-STATE FLOW
Trust boundary map
Authority, Factory, runtime, external consequence, and evidence domains require separate controls and identities.
INTENT → FACTORY → RUNTIME → CONSEQUENCE → VERIFICATION- 01Intent domainPrincipals and policy holders establish authority.
- 02Factory domainPackages, evaluators, and projections are prepared.
- 03Runtime domainAgents reason without owning consequence authority.
- 04Evidence domainReceipts cross to independent consumers.
Look for every point where intent, policy, identity, deployment, action, receipts, or verification crosses into another trust domain.
- 01
Treat every domain crossing as a control decision.
- 02
Identity is bound before runtime work begins.
- 03
External actions cross a distinct consequence boundary.
- 04
Verification remains outside the producer's trust domain.
WTK represents contracts, protected evaluation, projection, identity context, receipts, and consumer-facing evidence as separate governed artifacts.
Independent attestation, multi-operator boundaries, collusive-agent behavior, and external verifier interoperability remain open.
Delegation integrity · Evidence authenticity