EvidenceBound · DataHub Gate
PUBLIC JUDGE JOURNEY
Fail-closed governance for data agents

Read current context. Verify deterministically. Preserve proof. Keep approval human.

This editorial explorer visualizes retained evidence, including repository-published Ed25519 release seals. It does not impersonate the DataHub UI, execute production actions, authorize promotion, or create new acceptance evidence.

DataHub MCPidentity · schema · bounded lineage
Context bindingobserved digests and required fields
Restricted ASTunsupported constructs rejected
Bounded interpreterdeterministic execution without exec
Proof PackSHA-256 binding · Ed25519 release seal
Human reviewpromotion remains false
DataHub MCP readPASS
Current contextVERIFIED
Stale schemaBLOCKED
Retained sealsEd25519
VERIFIED
CONTROLLED REPRODUCTION
context binding matched; bounded interpreter completed
Dataset
ORDER_ENTRY_DB.analytics.order_history
Runtime result
present
Proof Pack root
2509becc6b3b21ad642c3779516cec76399264730f1195f3bcaec1c1279db616
Retained signature
Ed25519 · SIGNATURE_VALID
fdf31b458136d39b…81f0680d
Human approval
REQUIRED
Promotion authorized
false

Current context

  • schema digest matches
  • lineage evidence present
  • claims bind to evidence refs

Stale contract

  • expected digest changed
  • runtime remains null
  • SCHEMA_MISMATCH recorded

Evidence chain

01
Observed DataHub contextExact URN, schema fields, one-hop lineage.
02
Deterministic gate receiptVERIFIED or BLOCKED with explicit reasons.
03
Content-addressed Proof PackCanonical JSON, SHA-256 bindings, tamper rejection.
04
Retained detached Ed25519 sealsKey ID evidencebound-datahub-hackathon-2026; both controlled packs verify against the published public key.
05
Mandatory Human ReviewNo automatic deployment or promotion.

Cryptographic trust model

SHA-256 content bindingDetects changed artifacts and binds the evidence root.
Ed25519 detached sealSigns the verified manifest subject with an owner-controlled private key.
Repository-key verificationBoth retained controlled packs return SIGNATURE_VALID.
Independent identity trustRequires fingerprint comparison through a separately trusted channel.
Published release key fingerprint
fdf31b458136d39b3c22fe041e9ae7c986365c40275383d09e8a38ae81f0680d

The repository publishes the public key and two detached seals. This proves possession of the matching private key when verification succeeds; it does not independently establish the signer identity or authorize production use.

Bounded DataHub integration

Discovery
search
Entity identity
get_entities
Schema
list_schema_fields
Lineage
get_lineage · one hop · max five
Native receipt
update_description
Claim boundary
No badge, transaction block, certification, or automatic promotion.