Atomic D1 outcome
- Record
- published
- Current version
- accepted + frozen
- Editorial
- unreviewed
- Discoverability
- listed
Record workflow rehearsal
This studio is a browser-only model of the museum-record command path. It helps a first contributor understand drafts, corrections, independent statuses and the DOI outbox before public intake opens. It does not create an account, upload a file, write D1 data, sign a record, or register a DOI.
Illustrative command result
This is a browser-generated representation of the success path, not an acceptance decision. A real command cannot succeed until an authenticated account, owner-DID control proof, signed canonical record, personal Veritas append, institutional receipt, promoted media, accepted terms and safety processing have been verified at their respective boundaries.
“Published” and “reviewed” are not the same state. In the intended path a complete, valid record may be published as unreviewed. Later curator review can add findings or temporarily hide it from discovery; it cannot silently alter this frozen version. A correction is another signed version of the same record, and updates the existing concept DOI metadata rather than minting a second concept DOI.
Command boundary
The browser will never decide publication on its own. It will hand an authenticated command to the museum service, which verifies the trust references and all database facts before making one transactional D1 write.
Build the canonical version payload, attach the owner’s signature and personal Veritas reference, and collect declared record fields. No private key is sent to Clio.
Verify ownership, account and policy state, media promotion, terms, canonical commitment, signature and trust references. Rejections return reasons, not partial records.
On success, D1 writes the record, frozen version, evidence links, publication state, DOI job and doi.register outbox entry together. Provider registration happens later.