Documentation preview. These pages target Registryctl v0.15.0, which is not published yet. Public download commands will not work until that release exists. For runnable released instructions, use v0.13.0.
Registry-backed evaluation
Section titled “Registry-backed evaluation”sequenceDiagram participant Consumer as Evidence consumer participant Notary as Registry Notary participant Relay as Registry Relay participant Source as Registry source Consumer->>Notary: Evaluate evidence claims for purpose Notary->>Notary: Authenticate and authorize Notary->>Relay: Execute pinned consultation Relay->>Source: Governed read Source-->>Relay: Bounded response Relay-->>Notary: Outcome, outputs, provenance Notary->>Notary: Claims, disclosure, issuance policy Notary-->>Consumer: Minimized evidence or credential Consumer->>Consumer: Use evidence under applicable policy
One consultation can support several direct and CEL evidence claims. Relay returns typed outputs, Notary owns evidence meaning and disclosure, and the evidence consumer determines how the evidence is used. The decision owner remains accountable for requirements, decisions, workflow, and actions.
Self-attested Notary-only evaluation
Section titled “Self-attested Notary-only evaluation”sequenceDiagram participant Holder as Authenticated holder participant Notary as Registry Notary Holder->>Notary: Source-free evidence request Notary->>Notary: Validate token and subject binding Notary->>Notary: Evaluate allowed self-attested evidence claim Notary-->>Holder: Allowed result or credential
This topology performs no Relay or registry-source call. The identity token authorizes subject-bound access; it does not establish consumer eligibility or another consumer-owned outcome.
Delegated evaluation
Section titled “Delegated evaluation”sequenceDiagram participant Caller as Delegated caller participant Notary as Registry Notary participant Relay as Registry Relay Caller->>Notary: Request for represented target Notary->>Notary: Validate exact authorization details Notary->>Relay: Optional pinned relationship-proof consultation Relay-->>Notary: Boolean proof outcome Notary->>Relay: Pinned evidence consultation Relay-->>Notary: Minimized evidence Notary-->>Caller: Policy-limited result
The proof consultation proves only the configured requester-target edge. It does not add scopes or grant source authority. Binding or scope failure must make zero Relay calls.
Credential issuance
Section titled “Credential issuance”Credential issuance reuses an allowed evaluation. The credential profile owns
claim membership, format, holder binding, validity, and disclosure. A direct
output claim is not issued on no_match; ambiguity or failure never issues.
Unsupported composition
Section titled “Unsupported composition”A project does not join independent registry trust domains. Cross-registry composition requires separately governed projects and explicit federation or an external workflow. Notary does not execute source adapters or general orchestration.