Detached Activation Ticket
+ Dual-control Arming
A production-shaped, one-shot activation ticket is cryptographically qualified by two independent approvers, then deliberately left unarmed, disarmed, revoked and destroyed. Qualification is evidence—not live activation authority.
P65_LIVE_TARGET_ACTIVATION_BINDING_AUTHORITY
The repository proves ticket and dual-control semantics. It does not prove a dedicated host, a live Target binding authority, an Invocation Permit issuer or port 8110.
Abort-only terminal evidence
Preflight, Latch, Attestation and their signing authority are never reused.
Capability-free input only
Any capability-shaped field is rejected before the Cut 101 Ticket nonce can be claimed.
Prior custody is closed before new authority is considered
Owner, role, root and key separation
One requested activation; zero usable activation
Every identity and request digest is immutable
Short-lived and non-renewable
Expiry triggers revoke and destroy; it cannot extend or arm the Ticket.
Atomic claim surface 1 / 4
Replay, partial claim, generation drift or signature mutation fails before either approver can sign.
Target identity without live attachment
Source, module, configuration and surface remain digest-bound
Fresher than the parent Ticket
Identity is not connectivity
Security approves posture, not activation
Second root repeats the full verification
Two signatures cannot collapse into one trust domain
team:security-activation-arming
team:independent-activation-arming
Both approvals expire before the Ticket
Atomic claim surfaces 2 / 4 and 3 / 4
Security and Independent claims are individually single-use and cross-bound to the same Ticket, Target and request digests.
Two approvals are present and independently verified
Quorum permits the Platform to record a qualification decision only. It does not attach, arm, invoke or commit.
Platform records the held result
Platform signs both approval digests and the unchanged target chain
Narrowest evidence window
Atomic claim surface 4 / 4
The final nonce can only lead to disarm, revoke, destroy, release and zero-effect settlement.
Qualification and application are separate states
No mutable follow-up can reinterpret this terminal decision as live activation authority.
No state edge reaches ARMED
SRE terminal custody proof
Success still destroys the Ticket
24 complete paths; zero live activation bindings.
Every corrupt path converges on custody cleanup
372 negative cases fail closed; none can leave an active Ticket or approval.
Every execution and infrastructure counter remains zero
| Surface | Value | Surface | Value |
|---|---|---|---|
| Payloads / callables | 0 / 0 | Live bindings / permits | 0 / 0 |
| Network / persistence | 0 / 0 | Adapter invokes / commits | 0 / 0 |
| Host contacts / mutations | 0 / 0 | Port 8110 calls | 0 |
Executable cryptographic evidence
Real WebCrypto P-256 signatures and atomic claims; no fetch, network, environment, host or persistence APIs.
One qualified lane and six 62-case fault families
| Suite group | Cases | Expected |
|---|---|---|
| Complete dual-control path | 24 | QUALIFIED + DESTROYED |
| Cut 100 / Ticket / Target | 186 | REJECT OR REVOKE |
| Approvals / Decision / Closeout | 186 | DISARM + DESTROY |
26 named cutpoints cover pre-claim, post-claim, approval, decision and closeout interruption.
Cut 101 extends the verified system model
Three repository-bound, one external red gate
22 explicitly owned production gaps
Portal is live; Controller activation is not
Ephemeral Target Activation Binding + Single-use Invocation Permit
Ticket destroyed
Cut 102 must use a fresh binding authority and must not reuse the Ticket, Target Profile, Approval, Decision, nonce or signing capability closed here.