RC Rick Collettesecurity · AI · music · people
Concept

Unsigned Artifact Policy

concept-unsigned-artifact-policy · canon/concepts/unsigned-artifact-policy.md

Unsigned Artifact Policy. The explicit rule that decides whether artifacts without acceptable signatures may enter trusted use, and under which exception path if they may.

The important architectural move is not merely refusing unsigned artifacts; it is making the exception policy visible, configured, reviewable, and auditable instead of implicit. Default refusal is the safest baseline, but even an exception path must be a governed decision.

Incoming References

Law 2
Pattern 1