Publishing workflow
Typical publisher sequence
- Establish namespace authority.
- Define the registry and schema.
- Validate the record payload.
- Sign or otherwise bind the record to the published trust model.
- Publish through the management API.
- Confirm the record is retrievable through public read paths.
- Publish update, revocation, or retirement events as needed.
Mutation guidance
- Treat key history and revocation history as append-first unless there is a strong reason not to.
- Keep correction workflows distinct from revocation workflows.
- Do not delete historical material without a documented retention policy.