V0.1
Lifecycle and privacy
This v0.1 draft describes lifecycle only where it affects identity relationships, binding, or resolution. The canonical lifecycle contract contains additional workflows outside this operation’s public scope.
IP-LC-01 — One current membership. A committed Subordinate membership change leaves exactly one authoritative Passport for an active Subordinate; conflicting work cannot create dual ownership or an active orphan. [ADRs 8C, 8H; lifecycle reliability invariants.]
IP-LC-02 — Binding is not a grant. A consumer mapping identifies one candidate Subordinate; it is not a Passport authorization record. Revoking or replacing the mapping affects the local binding, not Passport grants. [ADRs 7D, 8B, 8C; resolver contract, Consumer references and local bindings.]
IP-LC-03 — Privacy-minimized output. A one-target resolve operation returns only the opaque consumer reference. It does not disclose Root continuity, siblings, Passport IDs, grant paths, unrelated Accounts, or private binding history. [ADRs 7P, 8D–8E, 8G, 8R-A; resolver contract, Contract and Denial and failure privacy.]
IP-LC-04 — Privacy across failures. After consumer authentication, hidden target existence and authority relationships are not disclosed by denial, lookup, retry exhaustion, or operational failure. Telemetry and restricted diagnostics must not include identity keys. [ADR 8G; resolver contract, Denial and failure privacy.]
IP-LC-05 — Retirement and deletion are distinct. Voluntary retirement and privacy-first deletion are separate lifecycle actions. Their full disposition, retention, and external reconciliation rules are defined by [ADRs 7A–7C, 8H, and 9B-A–9E-A; canonical lifecycle contract]. this resolve-focused draft does not restate those workflows.