Define what must be true.
VCM defines the outcome, claims, evidence requirements, constraints, and acceptance conditions once. Protocol metadata is a deterministic projection of this contract—not a competing semantic authority.
A buyer defines the outcome once. SITEBORNE carries that contract across compatible systems, governs the operation, verifies the returned result, preserves proof, and keeps result access and settlement as separate decisions.
Release 3 candidate semantics use the public thin waist: VCM Capability Contract → Policy + Authority Decision → Causal Execution State → Assurance Decision → PCC two-proof envelope → Result Authorization → Settlement Authority. The governing architecture further separates AuthorityGrant, ExecutionLease/fencing, CommitGrant where required, FinalPccDocument, ResultBinding, and SettlementGrant; those names describe governing design unless repository/runtime evidence promotes their implementation state. The production runtime remains authoritative for what is live.
VCM defines the outcome, claims, evidence requirements, constraints, and acceptance conditions once. Protocol metadata is a deterministic projection of this contract—not a competing semantic authority.
Identity, mandate, policy, payment authorization, and execution authority are distinct inputs. Release 3 candidate work makes this separation explicit before execution.
AVUF is the governed fulfillment fabric: it determines how an eligible contract is fulfilled across qualified BUILD / BUY / BROKER / COMPOSE paths without changing the contract itself.
Assurance evaluates the delivered result and evidence against the contract. A successful provider or tool invocation is not automatically a successful contract outcome.
Release 3 candidate PCC uses a full result envelope (schema 2.0.0) to record what happened. PCC is evidence; it is not identity, permission, result-access authority, payment authority, or settlement authority.
Public services can return contract-governed output. In the Release 3 candidate, sensitive document and verification results use buyer-authorized semantics. Payment or execution alone does not authorize result retrieval.
Settlement eligibility remains a separate governed decision. A payment receipt is economic evidence; it does not become identity, PCC, result authorization, or settlement authority.
The examples below show the extra questions SITEBORNE makes explicit: what counted as success, whether the result met it, and when completion can safely move forward.
These examples reflect the Release 3 authority model while keeping production activation separate. Candidate AVUF, result-authorization, and PCC 2.0.0 semantics must not be read as current live-v2 activation.
A buyer asks for one bounded outcome. Release 3 candidate AVUF semantics can choose among eligible fulfillment paths without silently changing what the buyer agreed to receive.
An agent can return a syntactically valid result and still miss required evidence or claims. SITEBORNE separates execution success from contract satisfaction.
Payment evidence can admit a paid operation without becoming identity, execution authority, or proof that the result satisfied the contract.
Keeping these roles distinct is part of the product contract.
Canonical capability contract: defines what must be true.
COREPolicy + authority decision boundary; evidence does not silently become permission.
CANDIDATE MODELGoverned fulfillment across qualified BUILD / BUY / BROKER / COMPOSE paths.
CANDIDATE / EVOLVINGContract-specific assurance decision over result and evidence.
COREFull proof-carrying result envelope in Release 3 candidate; evidence, not permission.
R3 CANDIDATE · 2.0.0Governed result-release decision; buyer-authorized semantics for sensitive candidate services.
R3 CANDIDATEEconomic completion authority remains distinct from execution, proof, and result access.
SEPARATE AUTHORITYDurable contract-specific evidence accumulation.
DESIGNFuture provider/reliability intelligence.
ROADMAP