Disclosure Boundary
These pages define what BlockSkunk will say in public about the shared-record stack: Stratum, Legate, and Arbiter. They answer what pattern you are buying into and how clients connect. They do not answer how products decide, score, or police internally.
Forward this page to security and legal without edits. Link it from every major section.
Purpose
Buyers and reviewers need stable vocabulary: unit of record, actor boundaries, write sequence, maturity labels, and what stays private. Integrators need the connect contract. Judgment logic, policy source, and proprietary architecture stay private.
Published
- Product identity: Stratum = scoped shared record. Legate = production MCP connection surface (envoy). Arbiter = verification-first evidence when the interface exposes seal/fingerprint (maturity labeled)
- Buyer-facing pattern: delegated agent access without exporting signing material. Agents prepare. Humans conclude
- Integration Surfaces maturity matrix (Live / by arrangement / contract-preview / contract-only)
- How to obtain a connection (wizard / deeplink / Agent Card / short-lived token) with no key export
- Transports: remote HTTPS (Streamable HTTP) and local stdio
- Auth at the interface: Bearer JWT, audience/resource binding, scopes → packs, write consent claim
- Actor boundaries: operator, agent/integrator, external signer, agent host (out of contract)
- Write path as a client sequence: simulate → prepare → external sign → submit_signed
- Synthetic record and prepare shapes for evaluation
- Verification model: what a permitted party can confirm, and what verification excludes
- Agent Card well-known path (high-level discovery)
/healthvs/readysemantics for callers- Public error categories and synthetic examples
- Stable public pack names partners are allowed to call
- Framework alignment as evidence mapping, not certification
Never published
- Guard / scoring engines, trust maps, thresholds, or interrupt models
- Policy source (allow/deny rule files) beyond “scope ⊆ granted packs”
- Mandate / approval business rules that decide when prepare is allowed
- Internal architecture: component graphs, middleware order, caches, event workers, rate-limit algorithms
- Audit / SIEM internals beyond the existence of digests for actor / tool / args / status
- Deploy-plane secrets: compose internals, VPC layout, image digests, BFF minting implementation
- Exhaustive proprietary tool catalogues and unpublished admin ops
- Real client data, tokens, JWTs, or live Agent Cards
- Invented Arbiter engagement enums or seal schemas beyond claims-safe interface language
- Competing infrastructure product brand names that are not part of the public Stratum / Legate / Arbiter vocabulary
- Mechanism-first category labels as hero language (prefer shared record / evidence integrity)
- Named external essays, funds, or strategy labels as proof
Three-line test
Before shipping any page:
- Describes the interface or authority pattern an actor interacts with, not how conclusions are reached.
- Names states and signals, not admission or blocking rules.
- Explains how to evaluate or connect, not production judgment processes.
Author rule: If a sentence explains how a product decides rather than what authority boundary exists or how the client connects, cut it.
Public vocabulary
| Prefer in public docs | Avoid in public MDX |
|---|---|
| Stratum peer / scoped shared record / record scope | Competing infrastructure product proper names; ledger partition jargon (prefer record scope) |
| Legate as envoy for agents (delegated access, humans keep the final say) | Word-origin essays, imperial or military metaphor as hero copy |
| Shared record / evidence integrity / delegated authority / external signer | Mechanism-first category labels, “trustless,” “DLT,” wallet-export framing as hero |
| Agents prepare, humans conclude | Lasting commit power inside the AI / model host as a recommended pattern |
| Illustrative record examples (evaluation only) | Published schema / frozen field-name commitments in buyer MDX |
| Signing material / connection credentials | Hot-wallet as the product metaphor |
legate.read / legate.write | Internal pack aliases not issued to partners |
| Arbiter fingerprint / seal at the interface (with maturity label) | Unqualified “cryptographically sealed” without arrangement notes |
| Ops capabilities by arrangement | Public admin API dump |
Forwardable package
For security, legal, or procurement review, send:
- This page
- Access model
- Framework Alignment
- Integration Surfaces (maturity honesty)
- Verification model
- Production Checklist when a technical champion is looping in