03 — Workflows
Summary
The pack's centre of gravity: the client is a published page. Verify needs no writes, no credentials and no state. Enrol walks the bootstrap gradient as commands — keygen, canonical statement, sign, post through the account-less lane, poll the public registry for the outcome, since the read path is the outcome channel. Operate-under-mandate is the three-session shape: issuer, subject and verifier sharing nothing but public URLs. The two not-yet-shipped dependencies (lane-address derivation; exact sign/verify flags) are marked rather than assumed.
Key concepts
- The hardest easy case — full tooling, no standing state, reads documentation literally
- The blind ack has no probe value — pending and declined look identical, by design
- Session-scoped identities — a finding to record — and I6 in the tabletop runs it as theatre
Key ideas
- Writing the workflow page is the first acceptance test — executed, not recalled, applies to command blocks.
- The verifier refusing correctly is as much the test as the happy path.
- The passphrase question is answered on the page: an encrypted vault yes, the repo and the transcript no.
Read the document
📄 Pack document · 03__workflows.md · rendered from the raw markdown (the source of truth)