| ProvisioningRecord | Provisioning → identity/admission | Observed outcome, posture, readiness claims and authoritative evidence | Specified |
| DeviceBinding | Inventory → relying services/admission | Exact canonical identity/instance/credential binding and lifecycle snapshot | Specified |
| WorkloadBinding | Membership registry → SPIFFE relying services | Canonical workload identity, active enrollment instance and per-request permission; unadopted additive 0.5 draft | Specified |
| DNSWorkloadAuthorization | Fleet registry → DNS controller | Transient response binding one authorization query to current workload membership and assigned DNS name; not a durable record or bearer grant | Specified |
| PilotAdoptionRecord | Provisioning → pilot admission | Existing-device observations and separately retained qualification gaps | Specified |
| PilotPolicy | Policy authority → pilot admission/relying services | Exact two-target cohort, issuer, audience, permissions and validity | Specified |
| PilotAdmissionDecision | Policy authority → pilot admission | Exact adoption/policy approval or denial and accepted gaps | Specified |
| PilotDeviceBinding | Inventory → pilot relying services | Restricted pilot tuple and lifecycle, without full qualification | Specified |
| FleetTarget | Admission → resolver/controller | Tenant, instance, platform and capability references, policy decision, freshness and restrictions | Deferred |
| ComponentContract | Component owner → editor/resolver/adapter | Versioned schema, typed ports, compatibility, permissions, resolution semantics and health requirements | Deferred |
| ConfigurationRevision | Authoring → resolver | Immutable graph, pinned components, secret references and authoring provenance | Deferred |
| DeploymentPlan | Resolver → reviewer/publication/execution | Exact instances, effective input digests, value provenance, conflicts, exclusions, expected revisions and rollout policy | Deferred |
| PublishRequest | User client → publication authority | Exact plan and expected desired-state versions, with a retry identity | Specified |
| Publication | Publication authority → execution/UI | Durable acceptance of exact intent, actor and authorization decision | Specified |
| BuildResult | Builder → release authorization | Exact input-to-artifact mapping, compiler/lockfile/source versions and provenance | Deferred |
| AuthorizedRelease | Release authority → assignment/verifier | Approved artifact digests, platform, delegation, epoch, validity and recovery class | Deferred |
| DesiredAssignment | Controller → device | Instance, desired version, release digest, expected base, attempt and lease | Deferred |
| DeviceObservation | Device → controller/appraisal | Sequenced boot/attempt/release observations and separate health dimensions | Deferred |
| PolicyDecision | Appraisal → controller/verifier | Evidence binding, policy version, freshness, result and reasons | Deferred |
| ExecutionResult | Controller → UI/audit | Attempt-correlated result supported by observations and policy decisions | Deferred |
|---|