Local authority
Sovereign + Ledger
The loopback mediator, capability ledger, approvals, model connections, files, effect execution, and signed receipt production.
System state, without theater
Rig exposes what the machine can prove, what only a human can decide, and which parts of the path are local, cloud-hosted, or external.
The three surfaces
A cloud deployment does not move Sovereign into the cloud. It makes the coordination and evidence surfaces reachable while work remains on the owner's machine.
Local authority
The loopback mediator, capability ledger, approvals, model connections, files, effect execution, and signed receipt production.
Cloudflare edge
Passwordless account access, pairing metadata, entitlement, revocation, public commitments, and checkpoint intake—never session content.
Portable proof
A folder the owner can keep, hand to an auditor, render locally, and verify offline against an explicit trust root.
What blocks release
These are intentionally outside the builder's authority. The platform names them instead of converting missing evidence into a passing badge.
Founding-contract signature, role owners, source and SDK rulings, license decisions, compatibility rulings, and the remaining pinned evidence.
capsule.created and capsule.create conflict. Neither is selected or silently aliased.
Uncoached UI use, a witnessed live-model note, paired devices, deed/export/restore, real riff users, external review, and signed acceptance.
The five owner exclusions make the strict predecessor chain unclosable as written until the owner rescopes or recuts that fence.
This site being reachable proves that Cloudflare served these bytes and that its health dependencies answered. It does not prove a local effect happened, an owner ratified a record, or a publicly witnessed checkpoint exists.
loading pinned status…