Operator manual
Install Global Profiles
Profiles are versioned interpretation/constraint material. Install them as controlled configuration, not as editable policy snippets.
- Pin the ENTITY release/profile source.
- Verify the profile registry/package hashes/signatures where provided.
- Install the exact profile versions required by the deployment.
- Set organization-specific configuration outside immutable sealed payloads where required.
- Run valid/invalid fixtures.
- Record installed profile IDs/versions in deployment evidence.
Upgrades
Installing a new profile version must not silently change the interpretation of historical signed passports. Keep older profile versions available for verification.
Authority boundary
A profile cannot grant authority that the Entity/rights state does not already authorize.