Revocation Layer
Publish and verify revocation state for identities, credentials, authorities, records, relations and devices while preserving the historical chain.
One function. Explicit trust boundaries.
Revocation changes present validity without erasing the historical existence of the revoked object or relationship.
Every material state transition should remain attributable to an authenticated actor, an authority context, a timestamp and the evidence required to reconstruct what happened.
Revocations functions.
The domain is separated into explicit functions so status, authority, evidence and lifecycle transitions can be inspected independently.
Identity
Inspect or publish revocation state for identity while preserving the prior evidentiary and lifecycle history.
Explore →02Credentials
Inspect or publish revocation state for credentials while preserving the prior evidentiary and lifecycle history.
Explore →03Authority
Inspect or publish revocation state for authority while preserving the prior evidentiary and lifecycle history.
Explore →04Records
Inspect or publish revocation state for records while preserving the prior evidentiary and lifecycle history.
Explore →05Relations
Inspect or publish revocation state for relations while preserving the prior evidentiary and lifecycle history.
Explore →06Devices
Inspect or publish revocation state for devices while preserving the prior evidentiary and lifecycle history.
Explore →Revocations lifecycle.
Identify revocable object
Verify revoking authority
Capture reason & evidence
Set revocation state
Preserve prior history
Minimum verification context.
The exact schema can vary by object class and policy version, but the verification layer should be able to resolve these core dimensions.
- Revocation ID
- Object
- Revoking authority
- Effective time
- Reason class
- Evidence
- Replacement / successor
- History
Designed for progressive activation.
Production status must always be sourced from the deployed service and published through System Status; this static package does not claim backend activation.