Anchor · Controlled Values
Satoshium Anchor · Controlled Values
Controlled Values define the governed vocabulary Anchor uses in production
records so states, methods, outcomes, and classifications remain consistent
across human-readable and machine-readable representations.
Anchor should freeze only values that production architecture proves are
necessary. Vocabulary should not become permanent merely because it was
convenient during design.
Current Freeze Decision
Production has now proven the minimum vocabulary needed for Anchor's first
Integrity Reference candidate, SCRD-SC-CERT-2026-0001.
Lifecycle State → production-frozen
Representation Type → canonical_json
Integrity Method → cryptographic_digest
Integrity State → current
Verification Result → match
Publication State → unpublished · published
Relationship Type → references_source
These values are frozen only because the first production candidate requires
them. Other values and categories remain unfrozen until production proves a need.
Minimum Production Set Frozen
Controlled Values Principle
Define the category → prove the need → govern the values → freeze only when production requires stability
Controlled Values exist to prevent ambiguous or ad hoc language inside
production Integrity References.
Integrity Method
Identifies the method used to generate or preserve integrity evidence for a Canonical Representation. The first production value is now frozen as cryptographic_digest.
First Value Frozen
Integrity State
Describes the current integrity-related state of an Anchor Integrity Reference without replacing Verification Result, Publication State, or Lifecycle State. The first production value is now frozen as current.
First Value Frozen
Verification Result
Records the outcome of a defined Integrity Verification process. The first production value required by the initial successful Verification path is now frozen as match.
First Value Frozen
Publication State
Describes whether and how an Integrity Reference is available through Anchor's publication architecture. The first production states are now frozen as unpublished and published.
Initial Values Frozen
Lifecycle State
Describes the institutional lifecycle position of the Integrity Reference itself, separate from the Source Artifact's lifecycle. The initial production enumeration is now frozen by the Lifecycle architecture.
Production Values Frozen
Representation Type
Classifies the kind of Canonical Representation covered by the Integrity Reference. The first production value is now frozen as canonical_json for the SCRD JSON candidate.
First Value Frozen
State Separation
Anchor should never collapse distinct state dimensions into one ambiguous
status field.
Integrity State ≠ Verification Result ≠ Publication State ≠ Lifecycle State
A record may be validly published while awaiting Reverification.
It may remain historically preserved after supersession.
It may have a failed Verification Result without automatically changing
every other state dimension.
Method Status
Anchor may eventually need governed values describing whether an Integrity
Method is approved for new production, deprecated, historical-only, or prohibited.
Provisional Category
Algorithm Status
Cryptographic algorithms may require a separate governed status model so
historical records remain interpretable after algorithms are deprecated.
Provisional Category
Correction Type
Later Corrections architecture may require controlled categories for
Anchor-owned errors, but those values should be defined only after the
Correction model is complete.
Deferred
Relationship Type
Relationships architecture requires a governed Source relationship for production. The first production token is now frozen as references_source; additional relationship tokens remain unfrozen.
First Value Frozen
Integrity Method — First Production Value Frozen
The first production Integrity Reference uses a deterministic cryptographic digest over its Canonical Representation.
cryptographic_digest
This is now the first frozen Integrity Method token. Other candidate methods remain unfrozen until production requires them.
digital_signature · trusted_timestamp · merkle_commitment · transparency_commitment · bitcoin_commitment · composite_integrity_method → still unfrozen
cryptographic_digest Frozen
Representation Type — First Production Value Frozen
The first production Source Artifact is the complete machine-readable SCRD JSON document.
canonical_json
This token is now the first frozen Representation Type because it accurately describes the intended Canonical Representation for SCRD-SC-CERT-2026-0001.
Other representation candidates remain unfrozen until tested by later Integrity References.
canonical_json Frozen
Verification Result — First Production Value Frozen
The Verification architecture is complete enough to freeze the first successful comparison outcome required by IR #1.
match → comparison reached and observed integrity material agrees with expected integrity material
Other outcomes remain unfrozen until an actual production condition requires them.
mismatch · unable_to_verify · incomplete_material · method_unavailable → still unfrozen
match Frozen
Integrity State — First Production Value Frozen
The first production Integrity Reference requires a current integrity condition distinct from its Verification Result, Publication State, and Lifecycle State.
current → the Integrity Reference has no known integrity condition requiring escalation under the evidence presently available
Other conceptual states remain unfrozen until production demonstrates their need.
attention_required · compromised · historical → still unfrozen
current Frozen
Publication State — Initial Production Values Frozen
The completed Publication architecture and first production workflow require a clear distinction between a candidate that has not yet entered public Anchor authority and a Version that has.
unpublished → the Anchor Version has not entered public Anchor authority
published → the Anchor Version has entered public Anchor authority following Publication Gate approval
Publication Gate decisions remain separate:
APPROVED / NOT APPROVED ≠ Publication State
Additional states, including withdrawal behavior, remain governed by Publication architecture and should be frozen only when production requires them.
Initial Values Frozen
Lifecycle State — Initial Production Enumeration Frozen
Anchor Lifecycle describes the institutional lifecycle position of the
Integrity Reference itself and remains separate from the Source Artifact's lifecycle.
Source Lifecycle ≠ Anchor Lifecycle
The completed Lifecycle architecture has now frozen the initial production vocabulary as:
draft
active
superseded
withdrawn
archived
These values are now governed production Controlled Values for Lifecycle State.
Future changes should occur through governed deprecation, replacement, or expansion
rather than silent reinterpretation.
Production Enumeration Frozen
Relationship Type — First Production Value Frozen
The first Integrity Reference must preserve a machine-readable relationship to its Source Artifact.
references_source
For IR #1, this relationship connects the Anchor Integrity Reference to SCRD-SC-CERT-2026-0001 without transferring Certifier authority to Anchor.
Additional Relationship Type tokens remain unfrozen until later records require them.
references_source Frozen
Controlled Value Governance
Every production Controlled Value should eventually have:
stable token · human-readable label · definition · governing category · allowed usage · introduction Version · deprecation status where applicable
Machine tokens should remain stable even if explanatory prose improves later.
Adding a New Value
New production values should be added only when an existing value cannot
accurately represent a real production condition.
New production need → architectural review → value definition → governance approval → documentation / schema update
Changing a Value
A production token should not be silently renamed or redefined after use.
If meaning changes materially, Anchor should prefer deprecation and
replacement over reinterpretation.
Preserve historical meaning. Change vocabulary forward.
Unknown and Other Values
Anchor should avoid generic fallback values such as unknown,
other, or miscellaneous unless production proves
they are necessary and their semantics are clearly governed.
Ambiguous fallback values can hide incomplete architecture.
Human Labels vs. Machine Tokens
Machine Token → stable, schema-safe value
Human Label → readable presentation
Human-facing wording may evolve without changing the machine token's
underlying meaning.
Relationship to Identifiers
Identifiers answer which Integrity Reference is being discussed.
Controlled Values describe governed properties of that record.
Anchor Identifier → identity
Controlled Value → governed classification or state
Mutable state should not be encoded into the Anchor Identifier.
Relationship to Schemas
The Integrity Reference Base Schema provides the structural fields that Controlled Values populate.
Controlled Values → governed vocabulary
Schema → structural enforcement
The Base Schema already enforces Lifecycle State. The newly frozen minimum production values should now be reconciled into schema constraints before IR #1 is constructed.
representation_type → canonical_json
method_type → cryptographic_digest
integrity_state → current
verification_result → match
publication_state → unpublished · published
relationship_type → references_source
Current Freeze Decision
Production has now proven the minimum vocabulary needed for Anchor's first
Integrity Reference candidate, SCRD-SC-CERT-2026-0001.
Lifecycle State → production-frozen
Representation Type → canonical_json
Integrity Method → cryptographic_digest
Integrity State → current
Verification Result → match
Publication State → unpublished · published
Relationship Type → references_source
These values are frozen only because the first production candidate requires
them. Other values and categories remain unfrozen until production proves a need.
Minimum Production Set Frozen