Operator manual
Global Passport Operations
Issue passports from verified identity/authority/rights/evidence state, not from untrusted UI fields.
Issue
- Load/verify issuing Entity.
- Resolve rights/evidence/provenance inputs.
- Select exact profile stack and mapping versions.
- Construct canonical passport payload.
- Sign under the authorized key.
- Store the resulting passport and issuance event.
Verify
Use the layered procedure in Verify a Passport. Record precise outcomes for signature, authority, rights, evidence, profile and domain conformance.
Supersede
If state changes, issue a new passport/derivation. Historical signed passports remain immutable verification targets.
Domain packages
Configure organization-specific facts before deployment and run the package verifier/conformance fixtures. Placeholder facts are non-production.