K10 · bounded transition and assurance evidence
Workload identity continuity
Direct answer
Workload identity continuity derives a DEGRADED root because one or more mandatory shared dependencies are degraded, stale, or unavailable.
Authority, operation, and disclosure boundary. K10 publishes static tools, deterministic synthetic fixtures, review queues, offline observation records, migration and merge reports, abstract dependency analysis, reference transition plans, audit trails, signed offline receipts, redaction records, and a release-time dashboard. It does not perform live monitoring, deployment, procurement award, facility certification, network reconnaissance, protected-system operation, legal authorization, or factual adjudication.
Derived root state
DEGRADED because mandatory shared evidence is not fully satisfied.
| ID | Type | Name | State | Mandatory |
|---|---|---|---|---|
| CCT-K10-IDENTITY-ROOT | claim | Workload identity continuity | DEGRADED | True |
| CCT-K10-IDENTITY-CONTROL | control | Bounded workload identity continuity control | SATISFIED | True |
| CCT-K10-IDENTITY-TEST | test | Synthetic workload identity continuity test | SATISFIED | True |
| CCT-K10-IDENTITY-EVIDENCE | evidence | Reference workload identity continuity evidence | SATISFIED | True |
| CCT-K10-IDENTITY-RECEIPT | receipt | Reference workload identity continuity receipt | SATISFIED | True |
| CCD-K10-TIME | shared-dependency | Trusted time evidence | DEGRADED | True |
| CCD-K10-SIGNING | shared-dependency | Evidence signing and verification | SATISFIED | True |
| CCD-K10-IDENTITY | shared-dependency | Workload identity evidence | SATISFIED | True |
Typed edges
| ID | From | Relation | To | Mandatory |
|---|---|---|---|---|
| CCT-K10-IDENTITY-E1 | CCT-K10-IDENTITY-ROOT | REQUIRES | CCT-K10-IDENTITY-CONTROL | True |
| CCT-K10-IDENTITY-E2 | CCT-K10-IDENTITY-CONTROL | VERIFIED_BY | CCT-K10-IDENTITY-TEST | True |
| CCT-K10-IDENTITY-E3 | CCT-K10-IDENTITY-TEST | PRODUCES | CCT-K10-IDENTITY-EVIDENCE | True |
| CCT-K10-IDENTITY-E4 | CCT-K10-IDENTITY-EVIDENCE | ATTESTED_BY | CCT-K10-IDENTITY-RECEIPT | True |
| CCT-K10-IDENTITY-S1 | CCT-K10-IDENTITY-CONTROL | DEPENDS_ON | CCD-K10-TIME | True |
| CCT-K10-IDENTITY-S2 | CCT-K10-IDENTITY-EVIDENCE | DEPENDS_ON | CCD-K10-SIGNING | True |
| CCT-K10-IDENTITY-S3 | CCT-K10-IDENTITY-CONTROL | DEPENDS_ON | CCD-K10-IDENTITY | True |
Boundary
Protected configuration included: No. The record is a synthetic dependency model, not an incident, facility finding, or attack path.